Direct Tunnels Bypass Virtual Switch Overlay in Hybrid Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hybrid cloud networks face challenges in optimizing network traffic flow and enforcing security policies due to bottlenecks in public cloud network gateways, which can reduce control, security, and efficiency when migrating workloads from on-premises networks to public clouds.

Innovation Solution

Implementing direct tunnels between virtual machines (VMs) to bypass the virtual switch overlay, allowing VMs to communicate directly while ensuring network and security policies are enforced through the exchange of security credentials and policy updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If direct tunnels are established between VMs to bypass the virtual switch overlay, then bandwidth requirements on public cloud network gateways are reduced and bottlenecks are minimized, but control and security enforcement may be compromised

Engineering Contradiction:
Improvenetwork traffic flow efficiencyVSAvoidsecurity policy enforcement
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces security credentials and policy enforcement mechanisms as intermediaries between VMs establishing direct tunnels. These credentials act as mediators that enable direct communication while maintaining security control, allowing the system to bypass the virtual switch overlay for performance while preserving security enforcement through credential-based authentication and policy validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments network traffic into two paths: controlled traffic that requires security policy enforcement through traditional virtual switch overlays, and trusted traffic that can bypass the overlay using direct tunnels established with security credentials. This segmentation allows simultaneous optimization of performance for trusted traffic while maintaining security control for other traffic.

Inventive Principle:
Principle #1Segmentation

2Loss of energy

If VMs communicate directly through established tunnels bypassing the virtual switch overlay, then control over network traffic is reduced, but bandwidth requirements on public cloud network gateways are reduced

Engineering Contradiction:
Improvebandwidth consumption on network gatewaysVSAvoidnetwork traffic control
Core Design Contradiction:
Loss of energyVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where VMs with valid security credentials can autonomously establish direct tunnels and bypass the virtual switch overlay without requiring manual configuration or approval. This self-service capability reduces the bandwidth burden on network gateways while maintaining operational control through pre-established security policies and credential validation.

Inventive Principle:
Principle #25Self-service

3Productivity

If direct tunnels are used to bypass virtual switch overlay, then network efficiency is improved, but the complexity of managing security credentials and policies increases

Engineering Contradiction:
Improvenetwork communication efficiencyVSAvoidsecurity credential management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal security credential system that serves multiple functions: authentication, authorization, and policy enforcement across both virtual switch overlay and direct tunnel communications. This multi-functional credential system reduces the complexity of managing separate security mechanisms for different communication paths while enabling efficient direct tunneling.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11005682B2Policy-driven switch overlay bypass in a hybrid cloud network environment
Publication Date: 2021.05.11 CISCO TECHNOLOGY INC
  • US11005682B2 patent drawing
  • US11005682B2 patent drawing
  • US11005682B2 patent drawing

AI summary

Network policies can be used to optimize the flow of network traffic between virtual machines (VMs) in a hybrid cloud environment. In an example embodiment, one or more policies can drive a virtual switch controller, a hybrid cloud manager, a hypervisor manager, a virtual switch, or other orchestrator to create one or more direct tunnels that can be utilized by a respective pair of VMs to bypass the virtual switch and enable direct communication between the VMs. The virtual switch can send the VMs network and security policies to ensure that these policies are enforced. The VMs can exchange security credentials in order to establish the direct tunnel. The direct tunnel can be used by the VMs to bypass the virtual switch and allow the VMs to communicate with each other directly.