Multi-tenant Router Virtual Network Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-tenant routers face challenges in securely delegating configuration control to customers, leading to increased operational costs and security risks due to coarse access-control parameters, which hinder agile and efficient configuration changes.

Innovation Solution

A framework that enables customers to configure their network devices through a customer portal, creating a virtual network and detecting configuration attempts, allowing authorized customers to perform configuration operations while preventing unauthorized modifications, thereby ensuring security and reducing the need for human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If service provider manually manages configuration changes for each customer, then configuration control is secure and centralized, but operational costs increase and configuration agility decreases

Engineering Contradiction:
Improveconfiguration agilityVSAvoidoperational costs
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent enables customers to autonomously configure their own network devices through a customer portal interface. Customers can directly modify configuration parameters such as routing, firewall rules, and quality of service settings without requiring service provider intervention. This self-service capability dramatically improves configuration agility and eliminates the need for service provider personnel to manually manage each customer's configuration changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments configuration control authority by creating virtual network instances that isolate each customer's configuration space. Through virtualization, the system divides the physical network device into multiple virtual instances, each with its own configuration namespace. This segmentation allows customers to independently manage their own configurations while the service provider maintains overall system control, resolving the contradiction between centralized security and decentralized agility.

Inventive Principle:
Principle #1Segmentation

2Productivity

If service provider delegates configuration control to customers, then configuration agility improves and operational costs decrease, but security risks increase due to coarse access-control parameters

Engineering Contradiction:
Improveconfiguration agilityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements fine-grained access control by segmenting the configuration space into customer-specific virtual network instances. Each instance has its own isolated configuration namespace, preventing customers from accessing or modifying other customers' configurations. This segmentation transforms the coarse access control of conventional systems into fine-grained control, allowing configuration delegation while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between the customer configuration requests and the physical network device. This virtualization intermediary enforces access control policies, validates configuration changes, and ensures that customer actions remain within their authorized boundaries. The intermediary maintains security while enabling customer autonomy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If conventional multi-tenant routers are used with coarse access control, then device complexity is reduced, but security vulnerabilities increase allowing customers to modify other customers' traffic

Engineering Contradiction:
Improveaccess-control structureVSAvoidtraffic isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the network device into multiple virtual instances, each handling a specific customer's traffic. This segmentation creates logical isolation boundaries that prevent cross-contamination between customers. Each virtual instance has dedicated configuration parameters and traffic forwarding rules, ensuring that customers cannot inadvertently or maliciously modify other customers' traffic while maintaining manageable device complexity through virtualization abstraction.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a virtualization dimension to the physical network device architecture. By introducing this additional logical layer, the system achieves fine-grained traffic isolation without increasing physical device complexity. The virtualization dimension provides the necessary security boundaries while keeping the underlying hardware manageable through software-based abstraction and control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10469476B1Method, system, and apparatus for delegating control over the configuration of multi-tenant network devices
Publication Date: 2019.11.05 JUNIPER NETWORKS INC
  • US10469476B1 patent drawing
  • US10469476B1 patent drawing
  • US10469476B1 patent drawing

AI summary

The disclosed apparatus may include (1) providing a framework that enables a customer entity of a service provider to configure, via a customer portal, a network device of the service provider that directs network traffic of the customer entity, (2) creating, for the customer entity by way of the framework, a virtual network that includes at least a portion of the network device of the service provider, (3) detecting an attempt by the customer entity to configure at least a portion of the virtual network via the customer portal, and then in response to detecting the attempt by the customer entity, (4) performing a configuration operation that configures the portion of the virtual network as directed by the customer entity via the customer portal. Various other apparatuses, systems, and methods are also disclosed.