Cloud Bridge VLAN Tagging for VM Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in seamlessly transitioning virtual machines between data centers, particularly from traditional premise data centers to cloud-based data centers while maintaining configuration settings and ensuring seamless communication across the public Internet, as existing solutions struggle with maintaining VLAN configurations and efficient data transfer.

Innovation Solution

The implementation of network appliances that create a bridge or tunnel between data centers, enabling communication by detecting new MAC addresses, encapsulating and decapsulating Ethernet frames, and tagging VLAN information, allowing for the seamless integration of multiple virtual LANs across cloud bridges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machines are moved between data centers, then flexibility and resource utilization improve, but maintaining configuration settings and communication becomes difficult

Engineering Contradiction:
Improvevirtual machine mobilityVSAvoidconfiguration consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces cloud bridges as intermediary devices that facilitate communication between data centers. These bridges automatically detect new MAC addresses, encapsulate Ethernet frames, and manage VLAN tagging to maintain network connectivity and configuration consistency during virtual machine migration between premise and cloud data centers

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If VLAN tagging is implemented across cloud bridges, then network segmentation and security improve, but packet processing complexity increases

Engineering Contradiction:
Improvenetwork segmentationVSAvoidpacket processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nested VLAN tagging where multiple VLAN identifiers are encapsulated within each other across cloud bridges. The outermost VLAN tag is processed first, allowing hierarchical network segmentation while managing complexity through structured encapsulation rather than flat multi-tag processing

Inventive Principle:
Principle #7Nested doll (Nesting)

3Productivity

If multiple VLANs are multiplexed over a single tunnel, then bandwidth efficiency improves, but packet routing decisions become more complex

Engineering Contradiction:
Improvebandwidth utilizationVSAvoidrouting decisions
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments packet routing decisions by processing VLAN tags in reverse order of nesting, with the outermost tag determining the primary routing path. This allows multiple VLANs to be multiplexed over a single tunnel while maintaining simple, hierarchical routing logic that doesn't require complex multi-dimensional routing tables

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2659624B1Systems and methods for VLAN tagging via cloud bridge
Publication Date: 2017.04.12 CITRIX SYSTEMS INC
  • EP2659624B1 patent drawingFigure 1A
  • EP2659624B1 patent drawingFigure 1B
  • EP2659624B1 patent drawingFigure 1C

AI summary

The present disclosure is directed to systems and methods for supporting multiple virtual LANs (VLANs) via a single tunnel between intermediary devices. A first intermediary device of a first data center on a first network receives, from a second intermediary device of a second data center on a second network, an encapsulated packet via a tunnel established between the first intermediary device and the second intermediary device, the first intermediary device comprising a plurality of network interfaces, each network interface of the plurality of network interfaces interfacing to a corresponding virtual LAN (VLAN) network of a plurality of VLAN networks. The first intermediary device detects that the encapsulated packet has been tagged with virtual LAN (VLAN) information by the second intermediary device. The first intermediary device identifies, from the VLAN information, a VLAN network of the plurality of VLAN networks. The first intermediary device transmits a packet of the encapsulated packet via the network interface corresponding to the identified VLAN network.