MPLS Label Cloud Network Manager for Tenant Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud computing solutions for virtual private network (VPN) isolation in cloud computing face limitations such as VLAN tag restrictions, congestion due to single path routing, and increased complexity and cost with IP and MAC encapsulation methods, which hinder efficient multi-tenancy and scalability.
Innovation Solution
Implementing a cloud network manager (CNM) that manages multi-protocol label switching (MPLS) flow entries to isolate tenant-specific data by using MPLS labels, allowing for flexible routing and reducing the need for IP routing, thereby simplifying network management and reducing costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VLAN tags are used for tenant isolation, then tenant data segregation is achieved, but the number of tenants is limited to 4096 due to tag restrictions
Solution Approach 1:
The patent transitions from 2-layer (VLAN tag) isolation to 3-layer isolation by introducing MPLS labels. The MPLS label stack includes: (1) outer MPLS label for routing, (2) inner MPLS label for tenant identification, and (3) original Ethernet frame. This dimensional expansion allows unlimited tenants while maintaining isolation.
Solution Approach 2:
The patent changes the isolation parameter from 12-bit VLAN tags (limiting to 4096 tenants) to 20-bit MPLS labels (supporting over a million tenants). This parameter change in the identification field enables scalable multi-tenancy without sacrificing isolation reliability.
2Reliability
If IP encapsulation is used for VPN isolation, then tenant security is improved, but network complexity and cost increase
Solution Approach 1:
The patent extracts the tenant identification function from the IP header by using MPLS labels. Instead of requiring full IP routing and encapsulation, the solution uses MPLS labels to carry tenant IDs, separating the security/isolation function from the routing function and simplifying network configuration.
Solution Approach 2:
The patent introduces MPLS labels as an intermediary between the Ethernet layer and IP layer. The MPLS label stack acts as a mediator that provides tenant isolation without requiring complex IP encapsulation, reducing network complexity while maintaining security.
3Reliability
If MAC encapsulation is used for tenant isolation, then VPN functionality is achieved, but implementation complexity and cost increase
Solution Approach 1:
The patent uses MPLS labels to create a simplified copy of the tenant identification mechanism. Instead of implementing complex MAC encapsulation protocols, the solution uses lightweight MPLS labels that replicate the tenant isolation functionality at lower implementation cost and complexity.
4Ease of operation
If single path routing is used in VLAN networks, then routing simplicity is maintained, but network congestion occurs
Solution Approach 1:
The patent introduces dynamic path selection by using MPLS label switching. The MPLS label stack enables flexible routing where packets can be directed along different paths based on label matching, allowing the network to dynamically adapt to load conditions while maintaining routing simplicity through pre-configured label switching paths.
Data Source
AI summary
A tenant database is used to add tenant ID information to the cloud network manager (CNM) address mapping table to isolate tenant specific data to a tenant ID to the CNM. The CNM maintains a mapping among a plurality of items in a plurality of databases or tables. The plurality of databases or tables include a tenant database (DB), a tenant identifier to tenant label (TITL) table, a top of rack server label to virtual switch link label (TLVLL) table, a label mapping table (SMVL), and a CNM address mapping table. The CNM uses the plurality of databases to generate tenant specific labels that are added to packets sent between tenant virtual machines (VMs).


