Multi-Tenant Firewall Virtualization for Data Center Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Internet data centers face challenges in managing and configuring separate firewalls for each customer, leading to complex networks, high costs, and increased downtime due to the need for redundant equipment.

Innovation Solution

A centralized Internet security system utilizing a firewall engine, authentication engine, and virtual private networks (VPNs) that apply policies to data packets, allowing for dynamic resource allocation and management of multiple customers' security needs through a single device, reducing the complexity and cost of network infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate firewall device is deployed for each customer, then security management for each customer is ensured, but device complexity and network complexity increase

Engineering Contradiction:
Improvesecurity managementVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple customer firewalls into a single shared firewall device. The firewall is divided into multiple virtual domains, each handling security for a specific customer. This merging approach reduces the total number of physical firewall devices while maintaining separate security management for each customer through virtualization.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single firewall device is designed to serve multiple customers simultaneously by implementing virtual domain technology. Each virtual domain within the firewall can independently manage security policies for different customers, making the firewall universal in its ability to handle multiple customer security requirements with one device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If redundant firewall boxes are provided to reduce downtime, then reliability improves, but cost and space requirements increase

Engineering Contradiction:
Improvedowntime reductionVSAvoidequipment quantity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements virtual domain technology that allows a single firewall device to function as multiple firewalls simultaneously. This eliminates the need for redundant physical firewall boxes while maintaining high availability through software-based virtualization and failover mechanisms within the single device.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate firewall devices are used for each customer, then security isolation is maintained, but rack space and physical infrastructure requirements increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidrack space
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent merges multiple customer firewalls into one physical device using virtual domain technology. This consolidation dramatically reduces rack space requirements while maintaining security isolation through virtual boundaries that separate each customer's traffic and policies within the shared hardware infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If multiple separate firewall devices are deployed, then customer security needs are met, but wiring and switching infrastructure complexity increases

Engineering Contradiction:
Improvesecurity provisionVSAvoidwiring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent consolidates multiple firewall functions into a single device, which simplifies the network wiring and switching infrastructure. Instead of requiring separate network paths and switching configurations for each firewall, the single multi-tenant firewall reduces the overall wiring complexity while still providing dedicated security processing for each customer through virtualization.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9185075B2Internet security system
Publication Date: 2015.11.10 JUNIPER NETWORKS INC
  • US9185075B2 patent drawing
  • US9185075B2 patent drawing
  • US9185075B2 patent drawing

AI summary

Methods and apparatus, including computer program products, implementing and using techniques for processing a data packet in a packet forwarding device. A data packet is received. A virtual local area network destination is determined for the received data packet, and a set of rules associated with the virtual local area network destination is identified. The rules are applied to the data packet. If a virtual local area network destination has been determined for the received data packet, the data packet is output to the destination, using the result from the application of the rules. If no destination has been determined, the data packet is dropped. A security system for partitioning security system resources into a plurality of separate security domains that are configurable to enforce one or more policies and to allocate security system resources to the one or more security domains, is also described.