Virtual Switch and VLAN Segmentation for Multi-tenant Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large enterprises using private address spaces for internal addressing often lead to network conflicts when multiple enterprises share service provider resources, as different enterprises may use the same private address ranges, necessitating resource segregation and inefficient use of infrastructure.
Innovation Solution
Establishing a virtual local area network (VLAN) for each enterprise with a distinct routing table and using a virtualized router to tag network addresses, allowing host machines to be dynamically reallocated and resources to be shared among multiple tenants, while ensuring network isolation and performance mitigation through CPU resource management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If host machines are statically allocated to single tenants to avoid network conflicts, then network reliability is improved, but infrastructure utilization efficiency deteriorates
Solution Approach 1:
The patent segments the host machine into multiple virtual machines, each isolated with its own virtual network interface and routing table. This allows a single physical host to serve multiple tenants independently, resolving the contradiction by providing both isolation (reliability) and sharing (efficiency) through virtualization segmentation.
Solution Approach 2:
The patent introduces a virtual switch as an intermediary layer between virtual machines and physical network interfaces. This mediator enables multiple tenants to share the same physical infrastructure while maintaining network isolation through virtual switching rules, thus achieving both reliability and efficiency.
2Adaptability or versatility
If multiple enterprises share the same private address space, then infrastructure sharing is improved, but network conflicts increase
Solution Approach 1:
The patent changes the network addressing parameter by assigning unique virtual network identifiers and routing table entries to each tenant. This allows multiple enterprises to share infrastructure using the same private address space without conflicts, as each tenant's traffic is routed through enterprise-specific routing tables with unique identifiers.
Solution Approach 2:
The patent adds a new dimension to network addressing by introducing virtual network layers above the physical network. Each tenant operates in its own virtual network dimension with enterprise-specific routing tables, allowing infrastructure sharing while avoiding address conflicts through dimensional separation.
3Productivity
If host machines are shared among multiple tenants, then resource efficiency is improved, but performance isolation deteriorates
Solution Approach 1:
The patent segments CPU resources into dedicated allocations for each virtual machine, preventing one tenant from affecting another's performance. This segmentation maintains performance isolation while allowing multiple tenants to share the same physical host, resolving the contradiction between efficiency and isolation.
Solution Approach 2:
The patent applies local quality by assigning specific CPU cores or processing units to each virtual machine based on tenant requirements. This ensures that each tenant receives dedicated performance characteristics on the shared host, maintaining isolation while achieving resource efficiency through sharing.
Data Source
AI summary
Routers and host machines can host desktops for two or more enterprises. A virtual local area network is established for each enterprise. Each virtual local area network is connected to a plurality of host machines for the enterprise, with each host machine supporting desktops for use by the enterprise. The desktops access computer resources on the enterprise network of the enterprise to which it is connected. Resources within a host machine are shared by having a virtual switch for each enterprise the host machine supports. The virtual switch for an enterprise is connected to the virtual local area network of the enterprise. Desktops in the host machine that are allocated to the enterprise are given network addresses that include the tag for that enterprise. Virtual desktops for different enterprises can be hosted on different partitions of the same host machine.


