Multi-tenant Routing Verification for Cloud Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing systems, tenants face challenges in configuring routing information without interfering with other tenants' network traffic, as existing methods lack automated verification and distribution mechanisms, leading to potential disruptions and the need for infrastructure personnel involvement.

Innovation Solution

A system where tenants can submit routing updates, which are automatically verified by trusted computer systems through multiple tests, ensuring correctness and authenticity before distribution to underlying infrastructure components, using protocols like BGP, OSPF, and key-based authentication to prevent interference and ensure real-time updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If tenants manually configure routing information in cloud computing systems, then routing updates can be implemented, but network traffic from different tenants may interfere with each other and infrastructure personnel involvement is required

Engineering Contradiction:
Improverouting configurationVSAvoidnetwork isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary verification system that sits between tenants and the routing infrastructure. This system automatically verifies routing updates against tenant isolation policies, preventing direct tenant access to infrastructure configuration while maintaining network isolation. The intermediary validates routing information before propagation, eliminating the need for infrastructure personnel involvement while preserving tenant isolation guarantees.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables tenants to independently configure and update their own routing information through automated verification mechanisms. The system allows tenants to submit routing updates that are automatically validated against isolation policies, eliminating the need for infrastructure personnel involvement. This self-service approach maintains reliability by ensuring tenant isolation through automated policy enforcement.

Inventive Principle:
Principle #25Self-service

2Reliability

If automated verification mechanisms are implemented for routing updates, then tenant isolation and network integrity are maintained, but system complexity increases

Engineering Contradiction:
Improvenetwork integrityVSAvoidverification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary verification of routing updates before they are propagated to the network infrastructure. The verification system checks routing information against tenant isolation policies in advance, preventing incorrect or interfering routes from being installed. This preliminary action maintains network integrity while keeping the verification logic centralized and manageable, rather than distributing complexity throughout the network infrastructure.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual verification of routing information is performed, then network integrity can be maintained, but time consumption and operational overhead increase

Engineering Contradiction:
Improverouting correctnessVSAvoidrouting update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements automated self-verification of routing updates through policy-based validation. The verification system automatically checks routing information against predefined tenant isolation policies without requiring manual intervention. This automated approach maintains routing correctness while dramatically reducing the time required for verification compared to manual processes, enabling rapid routing updates while preserving network integrity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10757015B2Multi-tenant routing management
Publication Date: 2020.08.25 SALESFORCE INC
  • US10757015B2 patent drawing
  • US10757015B2 patent drawing
  • US10757015B2 patent drawing

AI summary

Techniques are disclosed relating to establishing routes to access services executing on host computer systems. In some embodiments, a computing system receives a request to distribute routing data for a first service to switches of a plurality of host computer systems. The first service is one of a plurality of services belonging to a plurality of tenants supported by the plurality of host computer systems. The computing system analyzes the routing data to determine whether distribution of the routing data is in accordance with a set of criteria established for a first tenant associated with the first service. Based on the analyzing, the computing system permits communication of the routing data via one or more border gateway protocol (BGP) update messages to the switches.