Multi-tenant Network Stack with Isolated Routing Compartments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional networking stacks are unable to handle overlapping IP addresses from multiple virtual networks and lack functionality to isolate one virtual network's traffic from another, leading to inefficient and inadequate management of dedicated virtual machines for multiple tenants.
Innovation Solution
A multi-tenant network stack is implemented, where a single virtual machine is configured to serve multiple tenants and virtual networks by using a framing layer to obtain topology configuration data from a virtual switch, constructing isolated routing compartments, and providing mechanisms for network input/output processing specific to each tenant or virtual network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated virtual machine instance is configured for each tenant and virtual network, then network service functionality is provided to each tenant, but capital expenditure and operating costs increase as more tenants migrate to the virtualization service
Solution Approach 1:
The patent combines multiple virtual network functionalities into a single virtual machine instance through a multi-tenant network stack. The network stack includes a framing layer that handles multiple virtual networks simultaneously, allowing one virtual machine to serve multiple tenants instead of requiring dedicated virtual machines for each tenant.
Solution Approach 2:
The virtual machine is designed with universal functionality to serve multiple tenants through the multi-tenant network stack. The network stack provides generic routing encapsulation and virtual LAN capabilities that can accommodate different virtual networks with overlapping IP addresses, making the single virtual machine versatile enough to replace multiple dedicated instances.
2Ease of operation
If traditional networking stacks are used, then each virtual machine can be configured for a single tenant, but the stacks are unable to handle overlapping IP addresses from multiple virtual networks and lack functionality to isolate traffic
Solution Approach 1:
The network stack is segmented into distinct layers including a framing layer that handles virtual network encapsulation and a routing layer that manages IP addressing. This segmentation allows the system to handle overlapping IP addresses by maintaining separate routing tables and forwarding rules for different virtual networks while preserving ease of configuration.
Solution Approach 2:
The framing layer acts as an intermediary between the physical network and multiple virtual networks. It encapsulates and decapsulates packets, adding virtual network identifiers that enable the routing layer to distinguish between different virtual networks with overlapping IP addresses, thereby providing traffic isolation without complicating the configuration.
3Quantity of substance
If a single virtual machine serves multiple tenants, then capital expenditure and operating costs are reduced, but traditional networking stacks lack the functionality to isolate traffic from different virtual networks
Solution Approach 1:
The network stack implements nested virtualization where virtual networks are nested within a single virtual machine instance. The framing layer creates virtual network contexts that are nested within the host operating system, allowing traffic from different virtual networks to be isolated through nested routing tables and forwarding rules while maintaining cost efficiency.
Data Source
AI summary
Multi-tenant network stack techniques are described. In an implementation, a host instantiates an instance of virtual machine that is configured to serve networks service to multiple tenants and corresponding virtual networks. To do so, a framing layer of the virtual machine may be configured to obtain configuration data indicative of topology for a multi-tenant virtual networking environment from a virtual switch of a host device. The framing layer uses the configuration data to construct routing compartments and interfaces as abstractions of each virtual network in accordance with the topology. The routing compartments are isolated from each other and provide a mechanism for applications to process network input/output (I/O) in the context of a specific tenant or virtual network. The single virtual machine is able to provide services and applications to serve multiple tenants that are independent of the underlying virtualization technology.


