Multi-tenant Network Device Resource Isolation via Capability Databases

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network devices lack efficient resource management and isolation mechanisms, leading to potential security breaches and information leakage due to shared access rights among tenants.

Innovation Solution

A configuration manager system that virtually divides network device resources into isolated capabilities, allowing tenants to access, configure, and assign resources while maintaining clear authority separation and revocation rights, ensuring secure and isolated data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network device resources are shared among multiple tenants, then resource utilization and productivity are improved, but security and information isolation are compromised

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides network device resources into separate capability databases for each tenant, creating isolated access control structures. Each tenant has their own capability database that stores only their authorized resources and permissions, preventing cross-tenant access while maintaining efficient resource utilization through centralized management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a resource capability assignment mechanism that acts as an intermediary between tenants and network resources. This assignment system manages resource allocation, access rights, and revocation centrally, enabling secure multi-tenant resource sharing without direct tenant-to-tenant exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access rights are shared among tenants for resource management, then ease of operation is improved, but security risks and information leakage increase

Engineering Contradiction:
Improveresource management accessibilityVSAvoidsecurity breaches
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments access rights by creating tenant-specific capability databases that store isolated access control information. Each tenant can manage their own resources through their dedicated capability database, maintaining ease of operation while preventing unauthorized access to other tenants' resources through structural isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by giving each tenant customized access rights and capabilities tailored to their specific needs. Each tenant's capability database contains only the resources and permissions relevant to that tenant, enabling localized resource management with appropriate security boundaries.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If multiple tenants access the same network device, then adaptability and versatility are improved, but device complexity increases

Engineering Contradiction:
Improvemulti-tenant supportVSAvoidmanagement system structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal capability database structure that serves all tenants through a common framework. The same capability database mechanism, assignment process, and revocation procedures are used across all tenants, enabling multi-tenant support without proportionally increasing complexity through standardized reusable components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11979821B2Multitenant network device management
Publication Date: 2024.05.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11979821B2 patent drawing
  • US11979821B2 patent drawing
  • US11979821B2 patent drawing

AI summary

Example implementations relate to managing a resource of a network device. A resource of a network device may be assigned from a first tenant to a second tenant of the network device. Resources of the network device may include an assignment right, an access right, and a configuration right, By assigning the resource to the second tenant, the second tenant may be granted an access right to the assigned resource. Responsive to the assignment of the resource, an access right to the assigned resource may be removed from the first tenant such that the first tenant is isolated from the resource.