Virtual Firewalls for Multi-Tenant Policy Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network firewalls struggle to effectively manage security policies in multi-tenant distributed computing services, where tenants' policies can inadvertently affect each other, leading to compromised security and data integrity.
Innovation Solution
Implementing virtual firewalls that enforce separate firewalling policy sets for each tenant, allowing them to manage their computing resources independently without affecting other tenants, using a common firewalling component that distributes and updates policies across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional network firewall is used to protect multi-tenant distributed computing services, then security coverage is provided, but security policies of one tenant can affect other tenants, compromising security isolation
Solution Approach 1:
The patent divides the single conventional firewall into multiple virtual firewalls, each dedicated to a specific tenant. This segmentation isolates security policies so that one tenant's rules cannot affect others, directly resolving the security isolation problem while maintaining manageable complexity through logical separation rather than physical multiplication
Solution Approach 2:
The patent introduces a virtualization dimension to the firewall architecture, transforming a flat, shared firewall structure into a multi-layered system where virtual firewalls operate as software abstractions over physical infrastructure. This dimensional shift enables policy isolation without requiring proportional increases in physical hardware complexity
2Reliability
If separate firewalls are implemented for each tenant to ensure policy isolation, then security isolation is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent merges multiple virtual firewalls into a single shared physical firewall appliance. The virtual firewalls are software-based security domains that coexist on common hardware infrastructure, reducing device complexity compared to having separate physical firewalls for each tenant while maintaining full policy isolation through virtualization boundaries
Solution Approach 2:
The shared firewall appliance performs multiple functions simultaneously, serving as the security enforcement point for multiple tenants through its virtualized architecture. This multi-functional design consolidates infrastructure resources while maintaining tenant-specific security policies, addressing both isolation requirements and complexity reduction
3Productivity
If a shared firewall is used for multi-tenant services, then resource utilization is improved, but tenants cannot independently manage their security policies without affecting others
Solution Approach 1:
The patent segments the firewall's policy management capability into tenant-specific virtual firewalls, each with its own configurable security rules. This allows independent policy management for each tenant while the underlying shared infrastructure maintains high resource utilization through consolidation
Solution Approach 2:
The patent introduces a firewall management component that acts as an intermediary between tenants and the shared firewall infrastructure. This mediator handles policy configuration, validation, and enforcement, enabling tenants to independently manage their security policies through simplified interfaces while preventing conflicts in the shared system
4Ease of manufacture
If conventional firewalls are used in multi-tenant environments, then deployment simplicity is maintained, but security vulnerabilities arise from policy interference between tenants
Solution Approach 1:
The patent segments the security enforcement into isolated virtual firewall instances, eliminating the policy interference vulnerability that exists in conventional shared firewalls. This segmentation maintains deployment simplicity because virtual firewalls are software-based and can be provisioned automatically without complex physical hardware installation
Solution Approach 2:
The patent creates virtual copies of firewall functionality for each tenant rather than deploying separate physical firewalls. These software-based copies provide the necessary security isolation while maintaining ease of deployment through virtualization technologies that simplify provisioning and management compared to traditional hardware-based approaches
Data Source
AI summary
Virtual firewalls may be established that enforce sets of policies with respect to computing resources maintained by multi-tenant distributed services. Particular subsets of computing resources may be associated with particular tenants of a multi-tenant distributed service. A tenant may establish a firewalling policy set enforced by a virtual firewall for an associated subset of computing resources without affecting other tenants of the multi-tenant distributed service. Virtual firewalls enforcing multiple firewalling policy sets may be maintained by a common firewalling component of the multi-tenant distributed service. Firewalling policy sets may be distributed at multiple locations throughout the multi-tenant distributed service. For a request targeting a particular computing resource, the common firewalling component may identify the associated virtual firewall, and submit the request to the virtual firewall for evaluation in accordance with the corresponding firewalling policy set.


