Container Plugin for SDN Policy Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Software-Defined Networking (SDN) environments, existing tools face challenges in performing network diagnosis and managing network policies for container-based resources, leading to complexity in securing and troubleshooting container clusters, which can result in security breaches and performance issues.

Innovation Solution

A container plugin acts as an interface between container orchestration systems and the SDN manager, configuring and managing container-based network policies through label assignment and logical network element configuration, enabling efficient policy implementation and connectivity checks across the SDN environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If existing network diagnosis tools are used in SDN environments, then network connectivity can be monitored, but it is challenging to perform effective network diagnosis and manage network policies for container-based resources

Engineering Contradiction:
Improvenetwork diagnosis capabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that bridges container orchestration systems and SDN controllers. This intermediary translates high-level network policy requirements from container systems into low-level SDN flow rules, and enables effective network diagnosis by intercepting and analyzing network traffic between containers. The intermediary resolves the contradiction by providing a specialized translation layer that makes the complex SDN infrastructure manageable through container-native interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network policies are manually configured for each container, then security can be enforced, but the configuration and management becomes complex and error-prone

Engineering Contradiction:
Improvesecurity enforcementVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the system automatically generates, configures, and enforces network policies based on container metadata and orchestration system information. The intermediary component continuously monitors container states and automatically updates SDN flow rules to maintain security policies. This eliminates manual configuration errors while maintaining strong security enforcement through automated policy generation and continuous compliance verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring network policies during container deployment before actual network traffic begins. The intermediary translates container security requirements into SDN flow rules in advance, establishing security boundaries before containers become active. This preliminary configuration ensures security is embedded from the start rather than added later, reducing complexity of ongoing management.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If centralized network management is implemented, then policy consistency is improved, but the system complexity and configuration overhead increase

Engineering Contradiction:
Improvepolicy consistencyVSAvoidmanagement overhead
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent creates a universal intermediary component that handles multiple functions: network policy translation, traffic interception and analysis, security enforcement, and diagnostics. This single multi-functional component replaces what would otherwise require separate systems for each function, achieving centralized management and policy consistency without proportionally increasing complexity. The intermediary serves as a universal controller that speaks both container orchestration protocols and SDN protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10944691B1Container-based network policy configuration in software-defined networking (SDN) environments
Publication Date: 2021.03.09 VMWARE INC
  • US10944691B1 patent drawing
  • US10944691B1 patent drawing
  • US10944691B1 patent drawing

AI summary

Example methods and systems for container-based network policy configuration in a software-defined networking (SDN) environment are disclosed. One example method may comprise: in response to detecting a first request to assign a container-based resource with a first label via a container orchestration system, assigning a logical network element associated with the container-based resource with a second label. The example method may also comprise: in response to detecting a second request to configure a container-based network policy associated with the container-based resource via the container orchestration system, identifying the logical network element by mapping the first label to the second label; and configuring the container-based network policy to be applicable to network traffic that is forwarded via the logical network element.