Cloud Network Tool Optimizer Segregating User Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based server networks, existing tool aggregation devices face challenges in monitoring network activity due to security and confidentiality issues, especially when multiple users share virtualized resources, as they cannot segregate traffic effectively without exposing internal network infrastructure.

Innovation Solution

The implementation of cloud-based network tool optimizers that use master filters defined by the service provider and user filters defined by each user, combined by a filter rules compiler to segregate and control traffic, ensuring secure forwarding of packets to network monitoring tools while protecting internal traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If packet traffic is copied from a physical server processing system platform to monitoring tools, then network monitoring capability is provided, but security and confidentiality issues arise because packets from multiple independent user entities are mixed together

Engineering Contradiction:
Improvenetwork monitoring capabilityVSAvoidsecurity and confidentiality issues
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments packet traffic from multiple users into separate logical channels using virtualization technology. Each user's packets are tagged with unique identifiers (such as VLAN tags or custom metadata) that allow the monitoring system to distinguish and separate traffic from different user entities, preventing security breaches while maintaining monitoring capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component (a virtual switch or network function virtualization element) between the physical server platform and monitoring tools. This intermediary receives packets from the server, applies segmentation and tagging, and forwards packets to appropriate monitoring instances, thereby isolating user traffic and preventing direct exposure of internal network infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the controlling entity opens its network infrastructure to user entities for monitoring, then users can monitor their traffic, but the controlling entity's internal network traffic and infrastructure become visible to users

Engineering Contradiction:
Improveuser ability to monitor trafficVSAvoidexposure of internal network traffic
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent extracts only the necessary packet copies required for user monitoring while leaving the main network infrastructure intact and closed. Virtual switching elements create logical copies of packets for monitoring purposes without requiring physical access to or exposure of the controlling entity's internal network infrastructure, thereby enabling user monitoring while maintaining infrastructure security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent adds a virtualization dimension to the physical network infrastructure. By introducing virtual switches, virtual networks, and logical packet routing layers above the physical infrastructure, users can monitor their traffic through virtual interfaces without any physical or logical exposure of the underlying internal network infrastructure

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If tool aggregation devices are used to provide shared access to monitored network packets, then packet access is improved, but the devices cannot effectively segregate traffic in virtualized cloud environments without exposing internal infrastructure

Engineering Contradiction:
Improveshared packet accessVSAvoidtraffic segregation capability
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal virtual switching platform that serves multiple functions simultaneously: it aggregates packets from multiple users, segments traffic by user identity, applies quality of service policies, and provides monitored access to multiple monitoring tools. This multi-functional approach replaces the need for separate aggregation devices for each user while maintaining effective traffic segregation through virtualization

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10389642B2Cloud-based network tool optimizers for server cloud networks
Publication Date: 2019.08.20 KEYSIGHT TECH SINGAPORE (SALES) PTE LTD
  • US10389642B2 patent drawing
  • US10389642B2 patent drawing
  • US10389642B2 patent drawing

AI summary

Network tool optimizers for server cloud networks and related methods are disclosed. In part, master filters are defined to segregate and control user traffic, and user filters are defined to forward the user traffic to cloud-based network tools or tool instances. A master user interface and user interfaces for each user are provided so that the master filters and user filters can be defined and managed. A filter rules compiler within the cloud-based network tool optimizer then combines the master filters with the user filters, resolves conflicts in favor of the master filters, and generates filter engine rules that are applied to filter engines within the network tool optimizer for the cloud network. The filter engines then forward packets received at input ports for the network tool optimizer to output ports for the network tool optimizer that are coupled to network tools or tool instances within the cloud network.