ARP-Based Context Transmission for Virtual Machine Firewall Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firewall technologies struggle to efficiently incorporate identifiers of users and processes into firewall rules, especially in virtualized networks, due to difficulties in determining and mapping these identifiers.

Innovation Solution

The proposed solution utilizes ARP requests and responses as communication vehicles to transmit and disseminate context information about users and processes between hypervisors and a central controller, enabling enhanced firewall rules that utilize user and process identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TCP sessions are used to communicate context information between hypervisors and central controller, then reliable data transmission is achieved, but communication time and setup overhead increase

Engineering Contradiction:
Improvereliability of context information transmissionVSAvoidcommunication setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by using ARP requests and responses to pre-establish communication channels and transmit context information before TCP sessions are fully established. The ARP-based mechanism performs initial data exchange in advance, reducing the time needed for subsequent TCP connection setup and enabling faster firewall rule enforcement.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If Geneve headers are used to communicate context information, then data structure is standardized, but communication efficiency decreases compared to ARP-based approach

Engineering Contradiction:
Improvestandardization of data structureVSAvoidcommunication efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the context information transmission function from the Geneve header mechanism and implements it through ARP requests and responses. By taking out the data transmission task from the less efficient Geneve-based system and placing it in the faster ARP protocol, the invention achieves improved communication efficiency while maintaining structured data organization through the ARP message format.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If firewall rules incorporate user and process identifiers, then security granularity is improved, but difficulty in determining and mapping identifiers increases

Engineering Contradiction:
Improvesecurity rule granularityVSAvoiddifficulty in determining user and process identifiers
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces ARP requests and responses as intermediary mechanisms between hypervisors and the central controller for exchanging context information about users and processes. This intermediary ARP-based communication system simplifies the difficulty of determining and mapping identifiers by providing a standardized, efficient protocol for retrieving the necessary identification data needed for granular security rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12341753B2ARP-based annotations for virtual machines
Publication Date: 2025.06.24 VMWARE INC
  • US12341753B2 patent drawing
  • US12341753B2 patent drawing
  • US12341753B2 patent drawing

AI summary

Solutions for ARP-based annotations for virtual machines. In some solutions, a hypervisor implemented in a first host might determine that a first process is executing on the first host. The hypervisor can determine first context information for the first process, generate an Address Resolution Protocol (ARP) request, and/or transmit a first packet comprising the ARP request and the context information to a central controller as an indication that the first process is executing on the first host.