Container Network Resource Isolation via Dynamic Identity Attachment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing container frameworks, such as Docker, face challenges in network resource isolation and traffic control, particularly in overlay networks, due to incompetence in managing multiple network modes, complexity in operation and configuration, and static resource allocation, which leads to inefficient resource utilization and performance degradation.

Innovation Solution

A network resource isolation method that attaches an exclusive container network identity to data packets, enabling identification across overlay and non-overlay networks, and dynamically adjusts network resources based on container operational states, optimizing resource allocation and utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If TC is used for network resource isolation in container environments, then traffic control capability is provided, but it cannot work in overlay networks because container IPs are hidden and Classid Filter loses container identification

Engineering Contradiction:
Improvenetwork mode compatibilityVSAvoidcontainer identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a tunnel endpoint identifier as an intermediary element to bridge the gap between overlay network packet routing and container identification. This identifier is extracted from the tunnel endpoint information and used to reconstruct the original container identity, enabling TC to reliably identify containers even in overlay networks where traditional IP filtering fails.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter used for container identification from traditional container IP address to tunnel endpoint identifier. This parameter transformation allows the system to maintain container identification capability in overlay networks where the container IP is encapsulated and hidden within the tunnel protocol.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If TC commands are executed for static network isolation, then network resource allocation is established, but resource allocation becomes fixed and cannot be dynamically adjusted when containers are launched or deactivated

Engineering Contradiction:
Improvenetwork isolation stabilityVSAvoidresource allocation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static TC configuration into a dynamic system by monitoring container operational states and automatically adjusting network resource isolation accordingly. When containers are launched or deactivated, the system dynamically creates or removes corresponding TC rules, enabling flexible resource allocation that adapts to changing container workloads.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors container operational states and uses this information to adjust network resource isolation policies. This closed-loop control ensures that resource allocation remains optimal and adaptive as container workloads change over time.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If TC is used for network traffic control, then traffic management capability is provided, but operation and configuration become complex requiring full understanding of traffic control details

Engineering Contradiction:
Improvetraffic control capabilityVSAvoidconfiguration simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements self-service by allowing the system to automatically generate and manage TC configurations based on container operational states. Instead of requiring manual configuration of complex TC parameters, the system autonomously creates appropriate isolation rules, simplifying operation while maintaining sophisticated traffic control capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11121965B2Network resource isolation method for container network and system thereof
Publication Date: 2021.09.14 HUAZHONG UNIV OF SCI & TECH
  • US11121965B2 patent drawing
  • US11121965B2 patent drawing

AI summary

A network resource isolation method for container networks and a system thereof, including a computation system for network resource isolation, or a system using network resource isolation, or a network resource isolation system for container networks, and methods of implementation thereof. The system provides container overlay networks with a resource isolation scheme that also reduces the use threshold for isolation of network resources and optimizes the utilization rate of network resources.