Application Slice Overlay Networks for Cross-Cluster Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing container-based service deployment systems face challenges in managing namespaces, resource quotas, and network traffic isolation across multiple Kubernetes clusters, leading to operational complexities, security concerns, and resource contention.

Innovation Solution

The Mesh Platform introduces the concept of Application Slices, which creates logical boundaries for pods and services to communicate seamlessly across clusters, using slice routers and gateways to establish an overlay network with namespace-driven connectivity, resource quota management, and zero-trust security, enabling efficient deployment and management of microservices across clusters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple Kubernetes clusters are interconnected to enable cross-cluster service deployment, then service scalability and flexibility are improved, but operational complexity and management difficulty increase

Engineering Contradiction:
Improveservice scalabilityVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the multi-cluster system into isolated application slices, where each slice operates as an independent logical unit with its own namespace, network policies, and resource quotas. This segmentation allows multiple clusters to be interconnected while maintaining manageable boundaries through slice isolation, reducing operational complexity despite increased scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces slice gateways as intermediary components that manage cross-cluster communication. These gateways handle service discovery, traffic forwarding, and authentication between clusters, abstracting the complexity of direct cluster-to-cluster interactions and simplifying operational management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Use of energy by moving object

If shared resources are used across multiple applications in multi-cluster deployments, then resource utilization efficiency is improved, but security concerns and resource contention increase

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent divides shared resources into slice-isolated segments, where each application slice has dedicated access to specific resources within its namespace. This segmentation enables efficient resource utilization across multiple applications while maintaining security through enforced isolation boundaries that prevent unauthorized access and resource contention.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control and isolation policies to different slices, allowing each slice to have customized security and resource management characteristics. This local quality approach enables secure shared resource usage by tailoring resource allocation and access permissions to each application's specific requirements.

Inventive Principle:
Principle #3Local quality

3Stability of the object's composition

If namespace and network policy management is centralized across clusters, then configuration consistency is improved, but operational overhead and management burden increase

Engineering Contradiction:
Improveconfiguration consistencyVSAvoidoperational overhead
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The patent segments namespace and network policy management into slice-level units, where each slice maintains its own configuration namespace. This segmentation enables configuration consistency within each slice while reducing operational overhead by allowing independent slice management rather than requiring centralized control across all clusters.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal slice templates that can be replicated across multiple clusters, enabling consistent namespace and network policy configurations to be deployed uniformly. This multi-functionality approach maintains configuration consistency while reducing operational overhead through template-based deployment rather than manual configuration management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If application slices implement isolated overlay networks across clusters, then network security and traffic isolation are improved, but network infrastructure complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces overlay network virtualization as an intermediary layer that provides isolated network paths for each application slice across clusters. This virtualization approach improves network security and traffic isolation by creating logical separation without requiring physical network infrastructure changes, thereby managing complexity through software-based abstraction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a logical network dimension through overlay networks that operate independently of the underlying physical network infrastructure. This dimensionality change enables secure traffic isolation for each slice by creating virtual network layers, managing complexity by separating logical network requirements from physical network implementation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12126675B2Distributed computing system employing application slice overlay networks
Publication Date: 2024.10.22 AVESHA INC
  • US12126675B2 patent drawing
  • US12126675B2 patent drawing
  • US12126675B2 patent drawing

AI summary

A distributed computing system has one or more clusters each including compute nodes connected by a cluster network and executing microservices in respective containers organized into pods. The system includes application slice components (routers, slice gateways) distributed among the clusters to define and operate application slices each providing application slice services for respective sets of pods distributed among the clusters. Each slice gateway provides an interface between local pods of the application slice and remote pods of the application slice on a respective different cluster. Each slice is associated with namespaces, network policies and resource quotas for the applications onboarded on the slice. The slice routers and slice gateways for a given application slice form a respective slice-specific overlay network providing cross-cluster network services including service discovery and traffic forwarding with isolation from other application slices that co-reside on the clusters.