MPLS Label Cloud Network Manager for Tenant Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing solutions for virtual private network (VPN) isolation in cloud computing face limitations such as VLAN tag restrictions, congestion due to single path routing, and increased complexity and cost with IP and MAC encapsulation methods, which hinder efficient multi-tenancy and scalability.

Innovation Solution

Implementing a cloud network manager (CNM) that manages multi-protocol label switching (MPLS) flow entries to isolate tenant-specific data by using MPLS labels, allowing for flexible routing and reducing the need for IP routing, thereby simplifying network management and reducing costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VLAN tags are used for tenant isolation, then tenant data segregation is achieved, but the number of tenants is limited to 4096 due to tag restrictions

Engineering Contradiction:
Improvetenant data isolationVSAvoidnumber of supported tenants
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from 2-layer (VLAN tag) isolation to 3-layer isolation by introducing MPLS labels. The MPLS label stack includes: (1) outer MPLS label for routing, (2) inner MPLS label for tenant identification, and (3) original Ethernet frame. This dimensional expansion allows unlimited tenants while maintaining isolation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the isolation parameter from 12-bit VLAN tags (limiting to 4096 tenants) to 20-bit MPLS labels (supporting over a million tenants). This parameter change in the identification field enables scalable multi-tenancy without sacrificing isolation reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If IP encapsulation is used for VPN isolation, then tenant security is improved, but network complexity and cost increase

Engineering Contradiction:
Improvetenant securityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the tenant identification function from the IP header by using MPLS labels. Instead of requiring full IP routing and encapsulation, the solution uses MPLS labels to carry tenant IDs, separating the security/isolation function from the routing function and simplifying network configuration.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces MPLS labels as an intermediary between the Ethernet layer and IP layer. The MPLS label stack acts as a mediator that provides tenant isolation without requiring complex IP encapsulation, reducing network complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If MAC encapsulation is used for tenant isolation, then VPN functionality is achieved, but implementation complexity and cost increase

Engineering Contradiction:
Improvetenant isolationVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses MPLS labels to create a simplified copy of the tenant identification mechanism. Instead of implementing complex MAC encapsulation protocols, the solution uses lightweight MPLS labels that replicate the tenant isolation functionality at lower implementation cost and complexity.

Inventive Principle:
Principle #26Copying

4Ease of operation

If single path routing is used in VLAN networks, then routing simplicity is maintained, but network congestion occurs

Engineering Contradiction:
Improverouting simplicityVSAvoidnetwork throughput
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent introduces dynamic path selection by using MPLS label switching. The MPLS label stack enables flexible routing where packets can be directed along different paths based on label matching, allowing the network to dynamically adapt to load conditions while maintaining routing simplicity through pre-configured label switching paths.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9250941B2Apparatus and method for segregating tenant specific data when using MPLS in openflow-enabled cloud computing
Publication Date: 2016.02.02 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9250941B2 patent drawing
  • US9250941B2 patent drawing
  • US9250941B2 patent drawing

AI summary

A tenant database is used to add tenant ID information to the cloud network manager (CNM) address mapping table to isolate tenant specific data to a tenant ID to the CNM. The CNM maintains a mapping among a plurality of items in a plurality of databases or tables. The plurality of databases or tables include a tenant database (DB), a tenant identifier to tenant label (TITL) table, a top of rack server label to virtual switch link label (TLVLL) table, a label mapping table (SMVL), and a CNM address mapping table. The CNM uses the plurality of databases to generate tenant specific labels that are added to packets sent between tenant virtual machines (VMs).