Multi-tenant VPN Microsegmentation Flow Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional networking approaches are inadequate for virtual private networks (VPNs) as they do not provide sufficient customer control over flows, leading to inefficiencies and lack of granular control.

Innovation Solution

The implementation of a multi-tenant virtual private network (VPN) microsegmentation system that uses a microsegmentation engine to tag, track, and enforce policies on flows within the VPN, providing increased control and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional networking approaches are used in VPN environments, then network infrastructure is simpler to manage, but customer control over flows is insufficient

Engineering Contradiction:
Improvecustomer control over flowsVSAvoidnetworking system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the network into microsegments and assigning unique identifiers to each segment. This allows granular control over individual flows while maintaining overall system manageability through hierarchical organization of network segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a networking system as an intermediary layer between traditional network infrastructure and VPN environments. This intermediary provides flow control capabilities and policy enforcement without requiring changes to underlying physical infrastructure, thus maintaining ease of operation while enabling fine-grained control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If microsegmentation is implemented in multi-tenant VPNs, then granular control over flows is achieved, but system complexity increases

Engineering Contradiction:
Improvegranular control over flowsVSAvoidmicrosegmentation system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal networking system that handles multiple functions including flow tracking, policy enforcement, and microsegmentation management through a single integrated platform. This multi-functional approach reduces the need for separate systems for each function, thereby managing complexity while providing comprehensive flow control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes by dynamically assigning and modifying segment identifiers and policy parameters based on flow characteristics. This allows the system to adapt to different networking scenarios without requiring structural changes, managing complexity through flexible parameter management rather than rigid system architecture.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional networking approaches are used, then system simplicity is maintained, but security and performance optimization are limited

Engineering Contradiction:
Improvenetwork securityVSAvoidcontrol system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining security policies and microsegment boundaries before network operations begin. This proactive approach enables security enforcement at the source without requiring complex real-time decision-making systems, thereby improving security while managing complexity through advance preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250193111A1Multi-tenant virtual private network microsegmentation
Publication Date: 2025.06.12 ALKIRA INC
  • US20250193111A1 patent drawing
  • US20250193111A1 patent drawing
  • US20250193111A1 patent drawing

AI summary

What is disclosed is tagging a first flow of a multi-tenant virtual private network (VPN) with a first tag. Continuously tracking, based on the first tag, the first flow of the multi-tenant VPN. Capturing one or more characteristics of the first flow of the multi-tenant VPN. Categorizing the first flow of the multi-tenant VPN based on the one or more characteristics of the first flow. Providing the categorization of the first flow to a first tenant of the multi-tenant VPN. Receiving, based on input from the first tenant and the categorization of the first flow, a first policy. Enforcing the first policy on the first flow based on the first tag of the first flow and the continuous tracking of the first flow.