Distributed Virtual Switch for Hybrid Cloud L2 Extension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current hybrid cloud technologies face challenges in providing secure, scalable, and seamless connectivity between private and public clouds, as existing solutions like Open VPN and IPSec VPN-based L3 network extensions require modifications to enterprise infrastructure and do not support local switching of network traffic or consistent enterprise policies.

Innovation Solution

A distributed virtual switch (DVS) architecture is implemented, establishing a secure Layer 2 (L2) network overlay using a Layer 4 (L4) tunnel between private and public clouds, enabling a cloud virtual Ethernet module (cVEM) to switch inter-VM traffic and manage private application VMs as if they were within the private cloud, while maintaining consistent network policies and infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Open VPN or IPSec VPN-based L3 network extensions are used to connect private and public clouds, then secure connectivity is provided, but enterprise infrastructure modifications are required and local switching of network traffic is not supported

Engineering Contradiction:
Improvesecure connectivityVSAvoidinfrastructure modifications
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A distributed virtual switch (DVS) is introduced as an intermediary component that extends enterprise networking capabilities into the public cloud. The DVS includes virtual switch instances in both the private cloud and public cloud, which work together to provide Layer 2 networking without requiring modifications to existing enterprise infrastructure. This intermediary virtual switching fabric enables local traffic switching and maintains consistent enterprise network policies across the hybrid cloud environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from traditional Layer 3 VPN-based connectivity to a Layer 2 virtual switching approach, adding a new dimensional layer to the network architecture. By implementing virtual switch instances that operate at Layer 2, the system enables local traffic switching and extends enterprise network segments into the public cloud, providing a more granular and flexible networking model that maintains compatibility with existing infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If VMs are migrated between private and public clouds, then computing elasticity is achieved, but seamless connectivity and consistent network policies are not maintained

Engineering Contradiction:
Improvecomputing elasticityVSAvoidseamless connectivity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The distributed virtual switch architecture provides universal networking capabilities that function consistently across both private and public cloud environments. The DVS implements a unified control plane that manages virtual switch instances in both clouds, ensuring that network policies, security rules, and connectivity requirements are applied uniformly regardless of where virtual machines are located. This multi-functional approach enables seamless VM migration while maintaining consistent network behavior.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements a centralized control plane that provides feedback mechanisms to maintain seamless connectivity during VM migration. The control plane monitors the state of virtual switch instances and dynamically adjusts network configurations as VMs move between clouds, ensuring that connectivity is maintained and network policies are consistently applied throughout the migration process.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If a secure L2 network overlay is established using L4 tunnel between private and public clouds, then local switching of inter-VM traffic is enabled, but network attachment requirements increase

Engineering Contradiction:
Improvelocal switching capabilityVSAvoidnetwork attachment requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple networking functions into a unified distributed virtual switch architecture. By combining the control plane, virtual switch instances, and tunnel management into an integrated system, the patent reduces the number of separate network attachments required. The DVS consolidates Layer 2 switching, Layer 4 tunneling, and policy enforcement into a single architectural framework, simplifying the overall network attachment requirements while maintaining local switching capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2842282B1Distributed virtual switch architecture for a hybrid cloud
Publication Date: 2017.07.19 CISCO TECHNOLOGY INC
  • EP2842282B1 patent drawingFigure 1
  • EP2842282B1 patent drawingFigure 2
  • EP2842282B1 patent drawingFigure 3

AI summary

In one embodiment, a secure transport layer tunnel may be established over a public network between a first cloud gateway in a private cloud and a second cloud gateway in a public cloud, where the secure transport layer tunnel is configured to provide a link layer network extension between the private cloud and the public cloud. In addition, a cloud virtual Ethernet module (cVEM) may be executed (instantiated) within the public cloud, where the cVEM is configured to switch inter- virtual-machine (VM) traffic between the private cloud and one or more private application VMs in the public cloud connected to the cVEM.