Container Network Resource Isolation via Dynamic Identity Attachment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing container frameworks, such as Docker, face challenges in network resource isolation and traffic control, particularly in overlay networks, due to incompetence in managing multiple network modes, complexity in operation and configuration, and static resource allocation, which leads to inefficient resource utilization and performance degradation.
Innovation Solution
A network resource isolation method that attaches an exclusive container network identity to data packets, enabling identification across overlay and non-overlay networks, and dynamically adjusts network resources based on container operational states, optimizing resource allocation and utilization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If TC is used for network resource isolation in container environments, then traffic control capability is provided, but it cannot work in overlay networks because container IPs are hidden and Classid Filter loses container identification
Solution Approach 1:
The patent introduces a tunnel endpoint identifier as an intermediary element to bridge the gap between overlay network packet routing and container identification. This identifier is extracted from the tunnel endpoint information and used to reconstruct the original container identity, enabling TC to reliably identify containers even in overlay networks where traditional IP filtering fails.
Solution Approach 2:
The patent changes the parameter used for container identification from traditional container IP address to tunnel endpoint identifier. This parameter transformation allows the system to maintain container identification capability in overlay networks where the container IP is encapsulated and hidden within the tunnel protocol.
2Reliability
If TC commands are executed for static network isolation, then network resource allocation is established, but resource allocation becomes fixed and cannot be dynamically adjusted when containers are launched or deactivated
Solution Approach 1:
The patent transforms the static TC configuration into a dynamic system by monitoring container operational states and automatically adjusting network resource isolation accordingly. When containers are launched or deactivated, the system dynamically creates or removes corresponding TC rules, enabling flexible resource allocation that adapts to changing container workloads.
Solution Approach 2:
The patent implements a feedback mechanism where the system continuously monitors container operational states and uses this information to adjust network resource isolation policies. This closed-loop control ensures that resource allocation remains optimal and adaptive as container workloads change over time.
3Adaptability or versatility
If TC is used for network traffic control, then traffic management capability is provided, but operation and configuration become complex requiring full understanding of traffic control details
Solution Approach 1:
The patent implements self-service by allowing the system to automatically generate and manage TC configurations based on container operational states. Instead of requiring manual configuration of complex TC parameters, the system autonomously creates appropriate isolation rules, simplifying operation while maintaining sophisticated traffic control capabilities.
Data Source
AI summary
A network resource isolation method for container networks and a system thereof, including a computation system for network resource isolation, or a system using network resource isolation, or a network resource isolation system for container networks, and methods of implementation thereof. The system provides container overlay networks with a resource isolation scheme that also reduces the use threshold for isolation of network resources and optimizes the utilization rate of network resources.

