Private Link Virtual Network for Secure Multi-Tenant Outbound Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud data platforms face security risks when connecting multi-tenant systems to external networks using public connections, exposing sensitive customer data.

Innovation Solution

Implementing a dedicated private link virtual network for multi-tenant systems, peered with a core virtual network, allowing secure private endpoint connections to external systems without exposing data to the public internet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public network connections are used to connect multi-tenant data systems to external networks, then connectivity and accessibility are improved, but security risks and exposure of sensitive customer data increase

Engineering Contradiction:
ImproveconnectivityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network connectivity by creating separate private endpoints for each tenant within the multi-tenant data system. Each tenant receives dedicated private link connectivity to external networks through isolated endpoints, preventing public exposure while maintaining connectivity. This segmentation allows each tenant to have secure, private access without sharing public network paths with other tenants.

Inventive Principle:
Principle #1Segmentation

2Reliability

If private link connections are implemented for each tenant, then security is improved, but system complexity and infrastructure requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal private link infrastructure that serves multiple tenants simultaneously. The system creates a shared private network backbone that can accommodate numerous tenant endpoints, where the core infrastructure provides multi-tenant isolation and security policies. This universal approach allows the system to deliver secure private connectivity to many tenants without proportionally increasing complexity, as the isolation mechanisms and security policies are implemented at the infrastructure level rather than requiring separate physical networks for each tenant.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250383900A1Outbound private link framework
Publication Date: 2025.12.18 SNOWFLAKE INC
  • US20250383900A1 patent drawing
  • US20250383900A1 patent drawing
  • US20250383900A1 patent drawing

AI summary

To provide outbound private link support for a multi-tenant data system with tenant isolation, a separate, dedicated virtual network is provided, referred to as private link (PL) virtual network. The PL virtual network may host a plurality of host interface endpoints and resource endpoints. A core virtual network and the PL virtual network may be peered together to work in conjunction. The private endpoints in the PL virtual network may then be connected to external systems using a private link without exposure to the public internet.