Virtual Firewalls for Multi-Tenant Policy Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network firewalls struggle to effectively manage security policies in multi-tenant distributed computing services, where tenants' policies can inadvertently affect each other, leading to compromised security and data integrity.

Innovation Solution

Implementing virtual firewalls that enforce separate firewalling policy sets for each tenant, allowing them to manage their computing resources independently without affecting other tenants, using a common firewalling component that distributes and updates policies across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional network firewall is used to protect multi-tenant distributed computing services, then security coverage is provided, but security policies of one tenant can affect other tenants, compromising security isolation

Engineering Contradiction:
Improvesecurity isolationVSAvoidfirewall architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the single conventional firewall into multiple virtual firewalls, each dedicated to a specific tenant. This segmentation isolates security policies so that one tenant's rules cannot affect others, directly resolving the security isolation problem while maintaining manageable complexity through logical separation rather than physical multiplication

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization dimension to the firewall architecture, transforming a flat, shared firewall structure into a multi-layered system where virtual firewalls operate as software abstractions over physical infrastructure. This dimensional shift enables policy isolation without requiring proportional increases in physical hardware complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If separate firewalls are implemented for each tenant to ensure policy isolation, then security isolation is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvepolicy isolationVSAvoidfirewall infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple virtual firewalls into a single shared physical firewall appliance. The virtual firewalls are software-based security domains that coexist on common hardware infrastructure, reducing device complexity compared to having separate physical firewalls for each tenant while maintaining full policy isolation through virtualization boundaries

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared firewall appliance performs multiple functions simultaneously, serving as the security enforcement point for multiple tenants through its virtualized architecture. This multi-functional design consolidates infrastructure resources while maintaining tenant-specific security policies, addressing both isolation requirements and complexity reduction

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If a shared firewall is used for multi-tenant services, then resource utilization is improved, but tenants cannot independently manage their security policies without affecting others

Engineering Contradiction:
Improveresource utilizationVSAvoidpolicy management
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent segments the firewall's policy management capability into tenant-specific virtual firewalls, each with its own configurable security rules. This allows independent policy management for each tenant while the underlying shared infrastructure maintains high resource utilization through consolidation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a firewall management component that acts as an intermediary between tenants and the shared firewall infrastructure. This mediator handles policy configuration, validation, and enforcement, enabling tenants to independently manage their security policies through simplified interfaces while preventing conflicts in the shared system

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of manufacture

If conventional firewalls are used in multi-tenant environments, then deployment simplicity is maintained, but security vulnerabilities arise from policy interference between tenants

Engineering Contradiction:
Improvefirewall deploymentVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security enforcement into isolated virtual firewall instances, eliminating the policy interference vulnerability that exists in conventional shared firewalls. This segmentation maintains deployment simplicity because virtual firewalls are software-based and can be provisioned automatically without complex physical hardware installation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates virtual copies of firewall functionality for each tenant rather than deploying separate physical firewalls. These software-based copies provide the necessary security isolation while maintaining ease of deployment through virtualization technologies that simplify provisioning and management compared to traditional hardware-based approaches

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11658971B1Virtual firewalls for multi-tenant distributed services
Publication Date: 2023.05.23 AMAZON TECH INC
  • US11658971B1 patent drawing
  • US11658971B1 patent drawing
  • US11658971B1 patent drawing

AI summary

Virtual firewalls may be established that enforce sets of policies with respect to computing resources maintained by multi-tenant distributed services. Particular subsets of computing resources may be associated with particular tenants of a multi-tenant distributed service. A tenant may establish a firewalling policy set enforced by a virtual firewall for an associated subset of computing resources without affecting other tenants of the multi-tenant distributed service. Virtual firewalls enforcing multiple firewalling policy sets may be maintained by a common firewalling component of the multi-tenant distributed service. Firewalling policy sets may be distributed at multiple locations throughout the multi-tenant distributed service. For a request targeting a particular computing resource, the common firewalling component may identify the associated virtual firewall, and submit the request to the virtual firewall for evaluation in accordance with the corresponding firewalling policy set.