Per-User Routing Tables for Multi-Tenant Network Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing platforms face challenges in efficiently isolating network traffic of multiple users, leading to increased complexity, cost, and decreased efficiency, particularly when scaling up to manage network traffic and ensure data security across a multi-tenant environment.

Innovation Solution

Implementing a system with separate routing tables for each user on networking devices, using unique user identification numbers to isolate network routes, eliminating the need for firewalls and access control lists, and ensuring data security through layer 3 isolation and VLAN-based layer 2 isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewalls and access control lists are used to isolate network traffic, then data security is maintained, but device complexity and management difficulty increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by creating separate routing tables for each user, dividing the network traffic management into isolated segments. Each routing table contains only the routes relevant to its associated user, eliminating the need for complex firewall rules and access control lists. This segmentation approach maintains data security by ensuring users can only access resources within their designated routing table while significantly reducing configuration complexity.

Inventive Principle:
Principle #1Segmentation

2Productivity

If separate routing tables are implemented for each user, then network traffic isolation efficiency improves, but device complexity increases due to multiple routing tables

Engineering Contradiction:
Improvenetwork traffic isolation efficiencyVSAvoidrouting table management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service by automatically associating each data packet with a specific user and routing it through the appropriate routing table without manual intervention. The system autonomously manages the multiple routing tables by identifying users based on received data and selecting the corresponding routing table, eliminating the need for manual configuration and management of each routing table while maintaining high isolation efficiency.

Inventive Principle:
Principle #25Self-service

3Reliability

If extensive network configurations are used to isolate traffic across multiple customers, then data security is ensured, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidnetwork management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses segmentation to divide network traffic into isolated user-specific streams, each handled by its own routing table. This eliminates the need for complex firewall configurations and access control lists, making network management straightforward while ensuring data security through automatic traffic isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system automatically identifies users and selects appropriate routing tables without requiring manual configuration or management intervention. This self-service mechanism simplifies network management operations while maintaining robust data security through automated traffic isolation.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If the number of customers increases, then platform versatility improves, but device complexity and management difficulty increase

Engineering Contradiction:
Improvemulti-tenant capabilityVSAvoidnetwork isolation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by creating separate routing tables for each user, allowing the system to scale to accommodate multiple customers without increasing overall complexity. Each new customer simply receives their own routing table, enabling linear scaling while maintaining network isolation and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal routing table structure that can accommodate any number of users through a standardized identification and association mechanism. This multi-functional approach allows the same routing infrastructure to serve diverse customer needs, enhancing platform versatility while keeping management complexity constant through automated user identification and routing table selection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12587411B2Systems and methods for isolating network traffic of multiple users across networks of computing platforms
Publication Date: 2026.03.24 PALANTIR TECHNOLOGIES INC
  • US12587411B2 patent drawing
  • US12587411B2 patent drawing
  • US12587411B2 patent drawing

AI summary

System and method for isolating network traffic of multiple users across a network of a computing platform. For example, a method includes receiving data at a networking device of a computing platform. The networking device includes a plurality of routing tables. Each routing table of the plurality of routing tables is associated with a different user of multiple users of the computing platform. A user of the multiple users is identified based at least in part on the received data. In response to identifying the user of the multiple users based at least in part on the received data, a routing table of the plurality of routing tables is identified based at least in part on the identified user. A route from the identified routing table is determined based at least in part on the received data. The received data is sent across a network of the computing platform according to the determined route. The method is performed using one or more processors.