Multiple TCP/IP Stack Processors for Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data center systems face challenges in managing network traffic segregation, particularly with multiple IP interfaces on different VLANs, leading to issues with routing and resource allocation, which affects the functionality of virtual machine migrators and storage services across Layer 3 boundaries, and poses security risks due to shared TCP/IP stack processors across tenants.

Innovation Solution

Implementing multiple TCP/IP stack processors on a host, each with its own default gateway and resource pool, allowing for independent operation and segregation of processes, thereby enabling secure and efficient communication across subnets without relying on static routes or shared resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single TCP/IP stack processor is shared across multiple tenants, then resource utilization is improved, but security and isolation between tenants deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the single TCP/IP stack processor into multiple independent virtual TCP/IP stack processors, one for each tenant. Each virtual stack processor maintains separate network interfaces, routing tables, and connection states, ensuring complete isolation between tenants while allowing the physical hardware to be shared across multiple tenants for efficient resource utilization.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple VLAN interfaces are configured on a single TCP/IP stack processor, then network traffic segregation is improved, but routing complexity and error-proneness increase

Engineering Contradiction:
Improvenetwork traffic segregationVSAvoidrouting configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the routing functionality by creating separate virtual TCP/IP stack processors for each tenant or traffic type. Each virtual stack processor has its own simplified routing table and gateway configuration, eliminating the need for complex static route management across multiple VLAN interfaces on a single stack processor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer that acts as an intermediary between the physical network interfaces and the tenant applications. This virtual layer handles the complexity of VLAN tagging, routing table management, and gateway selection automatically, freeing applications from needing to explicitly specify virtual interfaces while maintaining proper traffic segregation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If static routes are configured for non-default gateways, then communication across Layer 3 boundaries is improved, but system security and ease of operation deteriorate

Engineering Contradiction:
ImproveLayer 3 communicationVSAvoidconfiguration simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent enables each virtual TCP/IP stack processor to automatically obtain its own default gateway and routing configuration through standard DHCP or configuration mechanisms. Each tenant's virtual stack processor independently manages its own routing table and gateway settings, eliminating the need for manual static route configuration while enabling seamless communication across Layer 3 boundaries.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9729679B2Using different TCP/IP stacks for different tenants on a multi-tenant host
Publication Date: 2017.08.08 VMWARE INC
  • US9729679B2 patent drawing
  • US9729679B2 patent drawing
  • US9729679B2 patent drawing

AI summary

Multiple TCP/IP stack processors on a host. The multiple TCP/IP stack processors are provided independently of TCP/IP stack processors implemented by virtual machines on the host. The TCP/IP stack processors provide multiple different default gateway addresses for use with multiple processes. The default gateway addresses allow a service to communicate across an L3 network. Processes outside of virtual machines that utilize the TCP/IP stack processor on a first host can benefit from using their own gateway, and communicate with their peer process on a second host, regardless of whether the second host is located within the same subnet or a different subnet. The multiple TCP/IP stack processors can use separately allocated resources. Separate TCP/IP stack processors can be provided for each of multiple tenants on the host. Separate loopback interfaces of multiple TCP/IP stack processors can be used to create separate containment for separate sets of processes on a host.