Multi-tenant VLAN Device Provisioning State Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multi-tenant computing systems, such as cloud computing systems, are vulnerable to attacks where hackers can access virtual local area networks (VLANs) and reconfigure devices, leading to malicious actions and data breaches.
Innovation Solution
An apparatus and method that utilize a processor and memory to detect new devices connecting to the system, placing them in a provisioning state where they cannot access operational equipment or data, and then configure them as part of a tenant VLAN with a token that enables secure access for the new tenant, while also allowing for the repurposing and reconfiguration of existing devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If new devices are allowed to connect and operate immediately in a multi-tenant computing system, then device availability and operational efficiency are improved, but system security and data protection deteriorate due to potential hacker access and malicious actions
Solution Approach 1:
The system performs preliminary actions by detecting new devices and automatically placing them in a provisioning state before they can access operational equipment. This preemptive measure ensures devices are secured prior to full operation, resolving the contradiction between immediate availability and security protection
Solution Approach 2:
The provisioning state acts as an intermediary environment between device connection and full system access. Devices in this intermediate state can be configured and authorized without directly accessing operational equipment or tenant data, thus maintaining security while enabling device integration
2Object-affected harmful factors
If new devices are placed in a provisioning state that restricts access to operational equipment and data, then system security is improved, but device operational capability and configuration efficiency worsen
Solution Approach 1:
The system enables self-service configuration for devices in provisioning state by allowing them to communicate with a provisioning server for automated setup. This maintains security restrictions while improving configuration efficiency without requiring manual intervention for each device
Solution Approach 2:
The provisioning state serves multiple functions simultaneously: it restricts access to operational equipment for security, enables device configuration through provisioning servers, and prepares devices for future tenant assignments. This multi-functionality resolves the contradiction between security restrictions and operational capability
3Adaptability or versatility
If existing devices are repurposed and reconfigured for new tenants, then resource utilization and system adaptability are improved, but security risk and potential malicious access worsen
Solution Approach 1:
Before repurposing existing devices for new tenants, the system performs preliminary security measures by placing devices in provisioning state, clearing previous configurations, and establishing new security credentials. This preemptive security approach enables resource reutilization while preventing carryover of malicious configurations
Solution Approach 2:
The system extracts and removes previous device configurations, tenant data associations, and security credentials before reassigning devices to new tenants. This extraction process eliminates potential security risks from prior usage while maintaining the physical device for continued resource utilization
Data Source
AI summary
An apparatus for securely configuring a tenant VLAN includes a processor and a memory that stores code executable by the processor. The code is executable by the processor to detect connection of a new device to a computing system. The new device is designated for use by a new tenant and the new device in a default state prior to configuration for use by the new tenant. The computing system is a multi-tenant system. The code is executable by the processor to command the new device to enter a provisioning state in response to detecting connection of the new device. The new device in the provisioning state is unable to access operational equipment of the computing system and data stored by tenants of the computing system.


