Hierarchical Chassis Control for Multi-Tenant Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems face challenges in achieving scalability, mobility, and multi-tenancy due to the complexity of managing large and sophisticated networks, particularly in environments with shared network switching elements across multiple users, where traditional methods often compromise one goal at the expense of others.
Innovation Solution
A network control system that allows multiple logical datapath sets to be specified for different users through shared forwarding elements, using a controller-based architecture to virtualize control and prevent users from viewing or controlling each other's forwarding logic, employing a hierarchical structure with API, logical, physical, and chassis controllers to manage and configure switching elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional network management methods are used to manage large and sophisticated networks, then network control is achieved, but scalability and user isolation are compromised
Solution Approach 1:
The patent segments the network control function by introducing a controller that separates the control plane from the data plane. The controller manages multiple logical datapath sets independently, allowing each user to have isolated logical networks while sharing physical switching elements. This segmentation enables scalable network management without requiring complex manual configuration of each switching element.
Solution Approach 2:
The controller acts as an intermediary between users and the physical switching elements. It receives high-level networking policies from users, translates them into low-level forwarding rules, and pushes them to the appropriate switching elements. This intermediary layer abstracts the complexity of network management, enabling users to define logical datapaths without needing to understand the underlying physical network topology.
2Productivity
If shared forwarding elements are used across multiple users, then resource utilization improves, but user isolation and security are weakened
Solution Approach 1:
The patent implements local quality by creating distinct logical datapath sets with unique forwarding rules for each user. Each logical datapath set is configured with specific access control lists, routing policies, and quality of service parameters tailored to that user's requirements. This allows different users to have customized network behaviors while sharing the same physical infrastructure, maintaining both resource efficiency and user isolation.
Solution Approach 2:
The controller creates virtual copies of networking functionality through logical datapath sets. Each user receives a virtualized networking experience that appears as if they have dedicated switching elements, while in reality, multiple users share the same physical hardware. The controller maintains separate forwarding state for each user, effectively copying the isolation properties of dedicated hardware into a shared environment.
3Measurement precision
If low-level configuration of individual components is used, then precise network control is achieved, but ease of operation and scalability are reduced
Solution Approach 1:
The system implements dynamics by allowing network configurations to be modified through high-level policies that the controller automatically translates into detailed forwarding rules. Users can dynamically adjust networking parameters such as routing paths, access control policies, and quality of service settings without manually configuring each switching element. The controller handles the complexity of translating these dynamic policy changes into precise low-level configurations.
Data Source
AI summary
A non-transitory machine readable medium storing a program that configures managed forwarding elements to establish tunnels between the managed forwarding elements is described. From a particular managed forwarding element, the program receives information regarding coupling of a network element to the first managed forwarding element. Upon receiving the information, the program generates a set of universal flow entries for configuring another managed forwarding element to establish a tunnel to the particular managed forwarding element.


