Cloud Network Tool Optimizer Segregating User Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud-based server networks, existing tool aggregation devices face challenges in monitoring network activity due to security and confidentiality issues, especially when multiple users share virtualized resources, as they cannot segregate traffic effectively without exposing internal network infrastructure.
Innovation Solution
The implementation of cloud-based network tool optimizers that use master filters defined by the service provider and user filters defined by each user, combined by a filter rules compiler to segregate and control traffic, ensuring secure forwarding of packets to network monitoring tools while protecting internal traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If packet traffic is copied from a physical server processing system platform to monitoring tools, then network monitoring capability is provided, but security and confidentiality issues arise because packets from multiple independent user entities are mixed together
Solution Approach 1:
The patent segments packet traffic from multiple users into separate logical channels using virtualization technology. Each user's packets are tagged with unique identifiers (such as VLAN tags or custom metadata) that allow the monitoring system to distinguish and separate traffic from different user entities, preventing security breaches while maintaining monitoring capabilities
Solution Approach 2:
The patent introduces an intermediary component (a virtual switch or network function virtualization element) between the physical server platform and monitoring tools. This intermediary receives packets from the server, applies segmentation and tagging, and forwards packets to appropriate monitoring instances, thereby isolating user traffic and preventing direct exposure of internal network infrastructure
2Ease of operation
If the controlling entity opens its network infrastructure to user entities for monitoring, then users can monitor their traffic, but the controlling entity's internal network traffic and infrastructure become visible to users
Solution Approach 1:
The patent extracts only the necessary packet copies required for user monitoring while leaving the main network infrastructure intact and closed. Virtual switching elements create logical copies of packets for monitoring purposes without requiring physical access to or exposure of the controlling entity's internal network infrastructure, thereby enabling user monitoring while maintaining infrastructure security
Solution Approach 2:
The patent adds a virtualization dimension to the physical network infrastructure. By introducing virtual switches, virtual networks, and logical packet routing layers above the physical infrastructure, users can monitor their traffic through virtual interfaces without any physical or logical exposure of the underlying internal network infrastructure
3Adaptability or versatility
If tool aggregation devices are used to provide shared access to monitored network packets, then packet access is improved, but the devices cannot effectively segregate traffic in virtualized cloud environments without exposing internal infrastructure
Solution Approach 1:
The patent implements a universal virtual switching platform that serves multiple functions simultaneously: it aggregates packets from multiple users, segments traffic by user identity, applies quality of service policies, and provides monitored access to multiple monitoring tools. This multi-functional approach replaces the need for separate aggregation devices for each user while maintaining effective traffic segregation through virtualization
Data Source
AI summary
Network tool optimizers for server cloud networks and related methods are disclosed. In part, master filters are defined to segregate and control user traffic, and user filters are defined to forward the user traffic to cloud-based network tools or tool instances. A master user interface and user interfaces for each user are provided so that the master filters and user filters can be defined and managed. A filter rules compiler within the cloud-based network tool optimizer then combines the master filters with the user filters, resolves conflicts in favor of the master filters, and generates filter engine rules that are applied to filter engines within the network tool optimizer for the cloud network. The filter engines then forward packets received at input ports for the network tool optimizer to output ports for the network tool optimizer that are coupled to network tools or tool instances within the cloud network.


