Distributed Virtual Switch for Hybrid Cloud L2 Extension
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current hybrid cloud technologies face challenges in providing secure, scalable, and seamless connectivity between private and public clouds, as existing solutions like Open VPN and IPSec VPN-based L3 network extensions require modifications to enterprise infrastructure and do not support local switching of network traffic or consistent enterprise policies.
Innovation Solution
A distributed virtual switch (DVS) architecture is implemented, establishing a secure Layer 2 (L2) network overlay using a Layer 4 (L4) tunnel between private and public clouds, enabling a cloud virtual Ethernet module (cVEM) to switch inter-VM traffic and manage private application VMs as if they were within the private cloud, while maintaining consistent network policies and infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Open VPN or IPSec VPN-based L3 network extensions are used to connect private and public clouds, then secure connectivity is provided, but enterprise infrastructure modifications are required and local switching of network traffic is not supported
Solution Approach 1:
A distributed virtual switch (DVS) is introduced as an intermediary component that extends enterprise networking capabilities into the public cloud. The DVS includes virtual switch instances in both the private cloud and public cloud, which work together to provide Layer 2 networking without requiring modifications to existing enterprise infrastructure. This intermediary virtual switching fabric enables local traffic switching and maintains consistent enterprise network policies across the hybrid cloud environment.
Solution Approach 2:
The patent transitions from traditional Layer 3 VPN-based connectivity to a Layer 2 virtual switching approach, adding a new dimensional layer to the network architecture. By implementing virtual switch instances that operate at Layer 2, the system enables local traffic switching and extends enterprise network segments into the public cloud, providing a more granular and flexible networking model that maintains compatibility with existing infrastructure.
2Adaptability or versatility
If VMs are migrated between private and public clouds, then computing elasticity is achieved, but seamless connectivity and consistent network policies are not maintained
Solution Approach 1:
The distributed virtual switch architecture provides universal networking capabilities that function consistently across both private and public cloud environments. The DVS implements a unified control plane that manages virtual switch instances in both clouds, ensuring that network policies, security rules, and connectivity requirements are applied uniformly regardless of where virtual machines are located. This multi-functional approach enables seamless VM migration while maintaining consistent network behavior.
Solution Approach 2:
The system implements a centralized control plane that provides feedback mechanisms to maintain seamless connectivity during VM migration. The control plane monitors the state of virtual switch instances and dynamically adjusts network configurations as VMs move between clouds, ensuring that connectivity is maintained and network policies are consistently applied throughout the migration process.
3Ease of operation
If a secure L2 network overlay is established using L4 tunnel between private and public clouds, then local switching of inter-VM traffic is enabled, but network attachment requirements increase
Solution Approach 1:
The patent merges multiple networking functions into a unified distributed virtual switch architecture. By combining the control plane, virtual switch instances, and tunnel management into an integrated system, the patent reduces the number of separate network attachments required. The DVS consolidates Layer 2 switching, Layer 4 tunneling, and policy enforcement into a single architectural framework, simplifying the overall network attachment requirements while maintaining local switching capabilities.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one embodiment, a secure transport layer tunnel may be established over a public network between a first cloud gateway in a private cloud and a second cloud gateway in a public cloud, where the secure transport layer tunnel is configured to provide a link layer network extension between the private cloud and the public cloud. In addition, a cloud virtual Ethernet module (cVEM) may be executed (instantiated) within the public cloud, where the cVEM is configured to switch inter- virtual-machine (VM) traffic between the private cloud and one or more private application VMs in the public cloud connected to the cVEM.