Overlay Network Host Subset Exposure via Selective Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer network technologies face challenges in selectively exposing a subset of hosts on an overlay network to external components while keeping another subset hidden, which is crucial for maintaining network security and tenant isolation in multi-tenant cloud computing environments.
Innovation Solution
Implementing a component within the overlay network that distributes mappings between hosts and substrate addresses to expose specific hosts to external components while keeping others hidden, and using external components to manage routing information and policies to control access, ensuring that only authorized hosts are accessible through the substrate network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If all hosts on an overlay network are exposed to external components, then external components can access any host, but network security and tenant isolation are compromised
Solution Approach 1:
The patent segments the overlay network hosts into multiple subsets, where each subset is selectively exposed to external components through separate mappings. This allows granular control over which hosts are accessible, preventing universal access while maintaining security for hidden hosts.
Solution Approach 2:
Different hosts within the overlay network are assigned different exposure qualities - some hosts are exposed to specific external components while others remain hidden. This local differentiation of accessibility properties enables selective exposure based on security requirements.
2Adaptability or versatility
If a component distributes mappings between all hosts and substrate addresses, then complete host accessibility is achieved, but security isolation between tenants is lost
Solution Approach 1:
The mapping distribution is segmented so that only specific mappings between certain hosts and substrate addresses are distributed to external components. This selective mapping distribution maintains security isolation while enabling necessary accessibility for authorized hosts.
Solution Approach 2:
The patent introduces an intermediary component that manages and distributes mappings selectively. This intermediary controls which host-substrate mappings are exposed to external components, acting as a security gatekeeper that prevents direct access to all hosts.
3Reliability
If selective exposure of hosts is implemented, then network security is improved, but device complexity increases due to mapping management
Solution Approach 1:
The mapping distribution component is designed with multi-functionality, handling both security enforcement and mapping management in a single system. This universal component reduces overall complexity by consolidating multiple functions rather than requiring separate mechanisms for each.
Data Source
AI summary
Techniques for exposing a subset of hosts on an overlay network, without exposing another subset of hosts on the overlay network, are disclosed. A component associated with an overlay network exposes a subset of hosts on the overlay network to components external to the overlay network. The component exposes the subset of hosts by distributing a mapping between (a) the hosts to-be-exposed and (b) the substrate addresses associated with the hosts. Alternatively, a component external to an overlay network exposes a subset of hosts on the overlay network to additional components external to the overlay network. The component exposes the subset of hosts by distributing a mapping between (a) the hosts to-be-exposed and (b) a substrate address associated with the particular component. In either embodiment, a mapping for hosts to-be-hidden is not distributed.


