Packet Processor Tenant Isolation Multi-Tenant Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems lack effective mechanisms to securely transmit sensitive data across networks, risking interception by third parties due to uncontrolled data paths.
Innovation Solution
A data storage device with egress ports and a packet processor that uses tenant-specific routing policies to select secure transmission paths, ensuring data is sent through network resources controlled by the data owner, thereby minimizing interception risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is transmitted through shared network resources, then network resource utilization is improved, but data security deteriorates due to increased interception risk
Solution Approach 1:
The patent segments the network transmission path into tenant-specific isolated paths. Each tenant is assigned dedicated egress ports and routing paths, physically separating data transmission channels. This segmentation ensures that even though multiple tenants share the same storage system, their data travels through distinct network routes, eliminating interception risks while maintaining secure isolation.
Solution Approach 2:
The patent introduces a packet processor as an intermediary component between the storage system and network. This packet processor examines data packets, identifies tenant identifiers, and redirects packets to appropriate tenant-specific egress ports based on routing policies. The intermediary ensures that data is routed through controlled paths while maintaining security isolation between tenants.
2Reliability
If tenant-specific routing policies are implemented, then data security is improved, but network resource utilization deteriorates due to isolated transmission paths
Solution Approach 1:
The patent implements dynamic routing policies where egress port assignments can be adjusted based on tenant requirements, data sensitivity levels, and network conditions. The system can dynamically select optimal paths while maintaining security isolation, allowing flexible resource allocation that balances security with efficient network utilization rather than fixed rigid paths.
Solution Approach 2:
The patent changes network routing parameters dynamically based on tenant identifiers and routing policies. By modifying egress port selections and path parameters according to tenant-specific rules, the system achieves secure isolation while optimizing resource usage. Parameters such as path selection, port assignment, and routing decisions are adjusted to balance security requirements with network efficiency.
3Reliability
If physical data packet isolation is implemented for different tenants, then data security is improved, but device complexity increases due to additional routing mechanisms
Solution Approach 1:
The packet processor is designed as a multi-functional component that handles multiple tasks: it examines packet headers, extracts tenant identifiers, applies routing policies, selects egress ports, and redirects packets. By consolidating these functions into a single universal processor, the system achieves physical packet isolation without proportionally increasing overall system complexity.
Solution Approach 2:
The routing policy mechanism operates autonomously by automatically examining tenant identifiers in packets and applying pre-configured routing rules without requiring manual intervention. The system self-manages packet routing decisions, selecting appropriate egress ports based on tenant requirements and network conditions, which simplifies operation despite the added complexity of isolation mechanisms.
Data Source
AI summary
A data storage device includes egress ports, a logical data storage, and a packet processor. The local data storage includes resources allocated to multiple tenants. The packet processor obtains packets that include data stored in the resources of the logical data storage. The obtained packets are addressed to a packet destination. The packet processor selects an egress port of the egress ports based on mappings between the data and the multiple tenants. The packet processor sends the packets via the selected egress port.


