Application-Based Network Segmentation in Virtualized Hosts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing environments, conventional network segmentation at the virtual machine level is inefficient as it requires deploying multiple virtual machines to satisfy different network security requirements for applications, leading to resource wastage and inability to allow users to access different networks with different applications.

Innovation Solution

Implementing application-based network segmentation, where different target networks are defined for different applications supported by the same virtual machine, using fine-grained network controls to direct packets through specific virtual network interfaces based on configured network policies, allowing each application to access its designated network without necessitating additional virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network segmentation at the virtual machine level is used, then network security can be maintained, but resource efficiency deteriorates due to requiring multiple virtual machines

Engineering Contradiction:
Improvenetwork securityVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies segmentation by dividing network access at the application level rather than the virtual machine level. Each application on a virtual machine is assigned to specific target networks through network policies, enabling fine-grained network segmentation that improves security without requiring multiple virtual machines, thus resolving the contradiction between security and resource efficiency

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different network access rights to different applications on the same virtual machine. Each application receives customized network policies tailored to its specific security requirements, allowing granular control over network access without duplicating the entire virtual machine, thereby improving both security and resource utilization

Inventive Principle:
Principle #3Local quality

2Reliability

If multiple virtual machines are deployed to satisfy different network security requirements, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidvirtual machine deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling a single virtual machine to serve multiple network security roles through application-level segmentation. Different applications on the same virtual machine can access different target networks according to their security requirements, eliminating the need to deploy separate virtual machines for each network segment and reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transitions from vertical segmentation (multiple virtual machines) to horizontal segmentation (multiple applications on the same virtual machine accessing different networks). This dimensional shift allows network security to be achieved through application-level policies rather than through deploying additional virtual machine layers, thereby reducing complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If application-based network segmentation is implemented, then resource efficiency is improved, but network policy management complexity increases

Engineering Contradiction:
Improveresource efficiencyVSAvoidnetwork policy management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the system automatically detects application identifiers and socket operations, and dynamically applies appropriate network policies. This automated feedback loop reduces manual policy configuration complexity while maintaining fine-grained control over network access for each application, thereby improving resource efficiency without proportionally increasing management complexity

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10608881B2Application-based network segmentation in a virtualized computing environment
Publication Date: 2020.03.31 VMWARE INC
  • US10608881B2 patent drawing
  • US10608881B2 patent drawing
  • US10608881B2 patent drawing

AI summary

Example methods are provided for host to implement application-based network segmentation in a virtualized computing environment. The method may comprise detecting an egress packet from a virtualized computing instance supported by the host for transmission to a destination and identifying a source application associated with the egress packet. The source application may be one of multiple applications supported by the virtualized computing instance, the multiple applications being associated with respective target networks. The method may further comprise, based on a network policy configured for the source application, determining a particular target network associated with the source application; and sending, to the destination, the egress packet via a physical network interface controller (NIC) associated with the particular target network.