Shared VPN Gateway for Multi-Tenant Overlay Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment of per-tenant VPN gateways in multi-tenant data storage environments leads to increased network resource utilization and management overhead, resulting in higher capital and operational expenses as the number of tenants grows.

Innovation Solution

Implementing a shared VPN-overlay gateway that allows multiple tenants to connect their remote networks to overlay networks through secure connections, reducing the need for individual VPN gateways and leveraging existing VPN clients, hardware, and software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If per-tenant VPN gateways are deployed for each tenant in a multi-tenant environment, then each tenant can have dedicated secure network access, but network resource utilization increases and management overhead increases

Engineering Contradiction:
Improvesecure network accessVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple per-tenant VPN gateway functions into a single shared VPN gateway that serves multiple tenants simultaneously. The gateway uses tenant identifiers in packet metadata to route traffic appropriately, combining what were previously separate gateway instances into one consolidated system that reduces management overhead while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared VPN gateway is designed to perform multiple functions for different tenants through a single instance. It handles authentication, encryption, and routing for multiple tenants using their respective identifiers, making the gateway universal rather than tenant-specific, thereby reducing the number of gateways needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If per-tenant VPN gateways are deployed for each tenant, then dedicated network connections are provided, but capital expenses and operational expenses increase dramatically

Engineering Contradiction:
Improvededicated network connectionVSAvoidnetwork resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple dedicated-sounding connections into a shared infrastructure. By using a single VPN gateway that processes packets from multiple tenants with tenant-specific metadata, it creates the effect of dedicated connections without requiring separate physical or virtual gateway instances for each tenant, thus reducing network resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Instead of creating actual separate gateway instances for each tenant, the system uses virtual copying through metadata tagging. Each tenant's traffic is marked with their identifier, allowing the shared gateway to handle their traffic as if it were dedicated, without the actual resource duplication of separate gateway hardware or software instances.

Inventive Principle:
Principle #26Copying

3Device complexity

If a shared VPN gateway is implemented to reduce costs, then capital expenditures and management overhead decrease, but the system must handle multiple tenants through a single connection point

Engineering Contradiction:
Improvenumber of gatewaysVSAvoidtenant traffic separation
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces tenant identifiers as intermediary metadata in packet headers. This intermediary mechanism allows the shared gateway to distinguish between different tenants' traffic without requiring separate gateways. The identifier acts as a mediator that enables the single gateway to handle multiple tenants' traffic separately and securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of packet identification by adding or modifying metadata fields to include tenant identifiers. This parameter change enables the shared gateway to differentiate and route traffic from different tenants through the same physical infrastructure, solving the multi-tenant handling problem without increasing gateway count.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10348689B2Interconnecting external networks with overlay networks in a shared computing environment
Publication Date: 2019.07.09 KYNDRYL INC
  • US10348689B2 patent drawing
  • US10348689B2 patent drawing
  • US10348689B2 patent drawing

AI summary

A method includes obtaining, by one or more processor, data from a virtual network of a tenant and an identifier of the tenant, where the virtual network of the tenant is one of at least two virtual networks in a shared computing environment where the at least two virtual networks overlay a physical network. Based on obtaining the identifier of the tenant, the method includes setting, by one or more processor, the identifier in metadata of the data and based on the identifier in the metadata, identifying, by the one or more processor, a network connection associated with the tenant. The method also includes identifying, by the one or more processor, a policy of the network connection and processing the data with the policy to create processed data and transmitting, by the one or more processor, the processed data through the network connection.