Multi-Tenant Application Isolation Using VLAN Broadcast Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computing platforms struggle to efficiently isolate applications associated with multiple tenants, leading to increased complexity and cost in managing network traffic and ensuring data security, particularly as the number of customers increases.

Innovation Solution

The solution involves isolating applications on a per tenant and per host basis by assigning a unique tenant identification number to each application, embedding this number in the network address, and generating a broadcast domain at the data link layer, using virtual local area networks (VLANs) to segregate traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional subnets and firewalls are used to partition the network for each tenant, then data security is provided, but device complexity and management difficulty increase significantly with the number of tenants

Engineering Contradiction:
Improvedata securityVSAvoidnetwork partition complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple tenant networks into a single shared network infrastructure, using broadcast domains and VLANs to provide logical isolation instead of physical partitioning. This allows multiple tenants to share the same network resources while maintaining security through logical separation mechanisms, thereby reducing the complexity of network management as tenant numbers increase.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces broadcast domains and VLANs as intermediary layers between tenants and the physical network infrastructure. These intermediaries provide isolation and security without requiring separate physical networks for each tenant, simplifying the overall network architecture while maintaining data security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate network partitions are created for each tenant using subnets, then data isolation is achieved, but ease of operation and management deteriorate as the number of tenants increases

Engineering Contradiction:
Improvedata isolationVSAvoidnetwork management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal network infrastructure that can serve multiple tenants simultaneously through broadcast domains and VLANs. This multi-functional approach allows a single network to provide data isolation for multiple tenants without requiring separate management for each partition, significantly improving operational ease as the tenant base grows.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the network at the data link layer using broadcast domains and VLANs rather than creating separate physical networks for each tenant. This segmentation provides data isolation while maintaining a unified management plane, making network operations easier compared to traditional subnet-based approaches.

Inventive Principle:
Principle #1Segmentation

3Productivity

If more tenants are added to the computing platform, then platform capacity and resource utilization improve, but the complexity of managing network traffic and ensuring security increases

Engineering Contradiction:
Improveplatform capacityVSAvoidnetwork management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges multiple tenant networks into a shared infrastructure using broadcast domains and VLANs, allowing the platform to accommodate more tenants without proportionally increasing network management complexity. This approach enables scalable platform capacity while maintaining manageable network operations through logical isolation mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4123973B1Isolating applications associated with multiple tenants within a computing platform
Publication Date: 2026.05.20 PALANTIR TECHNOLOGIES INC
  • EP4123973B1 patent drawingFigure 1
  • EP4123973B1 patent drawingFigure 2
  • EP4123973B1 patent drawingFigure 3

AI summary

System and method for isolating applications associated with multiple tenants within a computing platform. For example, a method includes receiving a request from a client associated with a tenant for running an application on a computing platform. The computing platform includes a plurality of hosts connected through a network. Each host is associated with a network address and configured to run applications associated with multiple tenants. One or more hosts of the plurality of hosts are identified based at least in part on the request. One or more broadcast domains including the identified one or more hosts are generated. The one or more broadcast domains are isolated in the network at a data link layer. A unique tenant identification number corresponding to the tenant is assigned to the one or more broadcast domains. The application is launched on at least one host of the identified one or more hosts. In response to launching the application on the at least one host: the unique tenant identification number is assigned to the launched application; the unique tenant identification number is added to the network address of the at least one host; and the network address of the at least one host is sent to the client associated with the tenant. The method is performed using one or more processors.