Overlay Network Host Subset Exposure via Selective Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network technologies face challenges in selectively exposing a subset of hosts on an overlay network to external components while keeping another subset hidden, which is crucial for maintaining network security and tenant isolation in multi-tenant cloud computing environments.

Innovation Solution

Implementing a component within the overlay network that distributes mappings between hosts and substrate addresses to expose specific hosts to external components while keeping others hidden, and using external components to manage routing information and policies to control access, ensuring that only authorized hosts are accessible through the substrate network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If all hosts on an overlay network are exposed to external components, then external components can access any host, but network security and tenant isolation are compromised

Engineering Contradiction:
Improveaccessibility of hostsVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the overlay network hosts into multiple subsets, where each subset is selectively exposed to external components through separate mappings. This allows granular control over which hosts are accessible, preventing universal access while maintaining security for hidden hosts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different hosts within the overlay network are assigned different exposure qualities - some hosts are exposed to specific external components while others remain hidden. This local differentiation of accessibility properties enables selective exposure based on security requirements.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If a component distributes mappings between all hosts and substrate addresses, then complete host accessibility is achieved, but security isolation between tenants is lost

Engineering Contradiction:
Improvehost accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The mapping distribution is segmented so that only specific mappings between certain hosts and substrate addresses are distributed to external components. This selective mapping distribution maintains security isolation while enabling necessary accessibility for authorized hosts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component that manages and distributes mappings selectively. This intermediary controls which host-substrate mappings are exposed to external components, acting as a security gatekeeper that prevents direct access to all hosts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If selective exposure of hosts is implemented, then network security is improved, but device complexity increases due to mapping management

Engineering Contradiction:
Improvenetwork securityVSAvoidmapping distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mapping distribution component is designed with multi-functionality, handling both security enforcement and mapping management in a single system. This universal component reduces overall complexity by consolidating multiple functions rather than requiring separate mechanisms for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11240152B2Exposing a subset of hosts on an overlay network to components external to the overlay network without exposing another subset of hosts on the overlay network
Publication Date: 2022.02.01 ORACLE INT CORP
  • US11240152B2 patent drawing
  • US11240152B2 patent drawing
  • US11240152B2 patent drawing

AI summary

Techniques for exposing a subset of hosts on an overlay network, without exposing another subset of hosts on the overlay network, are disclosed. A component associated with an overlay network exposes a subset of hosts on the overlay network to components external to the overlay network. The component exposes the subset of hosts by distributing a mapping between (a) the hosts to-be-exposed and (b) the substrate addresses associated with the hosts. Alternatively, a component external to an overlay network exposes a subset of hosts on the overlay network to additional components external to the overlay network. The component exposes the subset of hosts by distributing a mapping between (a) the hosts to-be-exposed and (b) a substrate address associated with the particular component. In either embodiment, a mapping for hosts to-be-hidden is not distributed.