Container Communication Interface Management via Virtual Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing device resources such as communication interfaces between different containers on a single communication device while maintaining isolation between containers is challenging, particularly when switching focus between containers, which can lead to processing time and power consumption issues and temporary loss of WiFi connectivity.

Innovation Solution

A communication device with a physical communication interface and at least one processor configured to operate multiple containers, where each container has a virtual communication interface managed by a communication interface management unit, allowing concurrent management of connections and controlling access to the physical interface based on profiles and available external connections, with the ability to block direct network communications and hide network nodes from external connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If containers share a physical communication interface to enable concurrent access, then resource utilization improves, but managing isolation and switching between containers becomes complex

Engineering Contradiction:
Improveresource utilizationVSAvoidinterface management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the communication interface management by creating separate virtual communication interfaces for each container (first virtual communication interface for first container, second virtual communication interface for second container). This segmentation allows each container to have its own isolated interface while sharing the physical hardware, thus improving resource utilization while maintaining management simplicity through virtualization abstraction.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network controller as an intermediary component that manages the physical communication interface and routes traffic between multiple virtual communication interfaces. This mediator handles the complexity of switching and isolation, allowing containers to access shared resources without direct management overhead, thereby improving productivity while containing complexity within the controller.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system switches focus between containers to manage the physical interface, then isolation is maintained, but network connectivity is temporarily lost and processing time increases

Engineering Contradiction:
Improvecontainer isolationVSAvoidprocessing time and connectivity loss
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables continuous network connectivity for multiple containers simultaneously by allowing multiple virtual communication interfaces to be active at the same time, each managed by its own communication interface management unit. This eliminates the need to switch focus between containers, maintaining continuous useful action (network communication) without interruption, thus reducing time loss while maintaining isolation through virtualization.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent sets up preliminary routing rules and network controller configurations that pre-establish the paths for multiple virtual interfaces before switching or connection changes are needed. This preliminary configuration allows the system to handle container operations without temporary connectivity loss, as the routing infrastructure is already in place to accommodate multiple concurrent connections.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If multiple containers concurrently access the physical interface, then productivity improves, but security and privacy isolation becomes challenging

Engineering Contradiction:
Improveconcurrent access capabilityVSAvoidsecurity and privacy isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the network space by creating separate virtual communication interfaces and isolated network namespaces for each container. The first container communicates through the first virtual communication interface while the second container uses the second virtual communication interface, ensuring that traffic from different containers remains segregated at the virtual interface level, thus maintaining security and privacy isolation while enabling concurrent physical interface access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network controller acts as a secure intermediary that enforces isolation policies between multiple virtual communication interfaces. It routes traffic from the first virtual communication interface and second virtual communication interface through controlled paths, preventing direct communication between containers while allowing both to access the physical interface concurrently, thus maintaining security and privacy while improving productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If direct network communications between containers are blocked, then security improves, but network flexibility and inter-container communication capability deteriorates

Engineering Contradiction:
Improvesecurity isolationVSAvoidinter-container communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network controller serves as a controlled intermediary that blocks direct network communications between virtual communication interfaces while providing managed communication paths when needed. Containers cannot directly communicate through the physical interface, maintaining security isolation, but the network controller can facilitate authorized inter-container communication through controlled routing, thus preserving both security and necessary flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network controller provides multi-functional capability by simultaneously enforcing security isolation (blocking direct container-to-container communication) and enabling controlled inter-container communication (through managed routing paths). This universal component handles both security enforcement and communication facilitation, maintaining reliability while preserving adaptability for legitimate inter-container needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3497888B1Device, method and products for managing a communication interface of a communication device
Publication Date: 2021.08.11 HUAWEI TECH CO LTD
  • EP3497888B1 patent drawingFigure 1
  • EP3497888B1 patent drawingFigure 2
  • EP3497888B1 patent drawingFigure 3

AI summary

Methods and devices for managing a physical communication interface can include operating a first communication interface management unit in a first container operating on the communication device, the first communication interface management unit managing a connection to a first virtual communication interface having a network connection with the physical communication interface; and concurrently with the operation of the first communication interface, operating a second communication interface management unit in a second container operating on the communication device, the second communication interface management unit managing a connection to a second virtual communication interface having a network connection with the physical communication interface.