Distributed Virtual Switches for Scalable Multi-Tenant Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional distributed virtual switches fail to address scalability, mobility, and multi-tenancy in large networks, as they do not effectively bridge IP subnets, scale to support thousands of end hosts, and integrate physical hosts in a flexible manner.
Innovation Solution
A virtual platform that creates distributed virtual switches to enable secure and efficient communication between virtual and physical machines across different subnets and VLANs, supporting integration with traditional IP networks and providing features like NAT functionality and stateful firewalling, while managing VLANs or tunnels to maintain isolation and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If conventional distributed virtual switches are used, then network functionality is provided for virtual machines, but scalability to support tens of thousands of end hosts is limited
Solution Approach 1:
The patent segments the virtual switch functionality into distributed virtual switch components that can be distributed across multiple physical hosts. Each host runs a instance of the virtual switch, and they work together as a coordinated system. This segmentation allows the network to scale to tens of thousands of end hosts by adding more host instances rather than requiring a single complex centralized switch.
Solution Approach 2:
The patent introduces a new dimensional approach by creating a distributed architecture that spans multiple physical hosts and network segments. Instead of scaling horizontally within a single switch device, the system scales by adding vertical dimensions of host instances and network segments, allowing exponential growth in supported end hosts.
2Reliability
If tenant isolation is retained, then security and multi-tenancy are improved, but mobility of virtual machines is complicated
Solution Approach 1:
The patent creates a universal distributed virtual switch architecture that can simultaneously support multiple tenants with isolation requirements while also enabling virtual machine mobility. The system provides multi-functionality by implementing both strict tenant isolation and seamless migration capabilities within the same framework, allowing a single platform to serve diverse operational requirements.
Solution Approach 2:
The distributed virtual switch acts as an intermediary layer between virtual machines and physical network infrastructure. This intermediary maintains tenant isolation policies while simultaneously enabling mobility by managing the abstraction between virtual and physical network states, allowing VMs to move without breaking isolation guarantees.
3Ease of operation
If L2 domains are extended, then virtual machine mobility is improved, but the domain cannot scale to large sizes
Solution Approach 1:
The patent segments large L2 domains into manageable distributed virtual switch instances across multiple physical hosts. Each instance manages a portion of the overall domain, allowing the total domain to scale to large sizes while maintaining the mobility benefits of L2 connectivity. The segmented architecture prevents the single-domain scalability limitations.
Solution Approach 2:
The patent extends L2 domains into another dimension by distributing them across multiple physical hosts and network segments. Instead of being constrained to a single L2 domain size, the system creates multi-dimensional L2 connectivity that can scale to tens of thousands of hosts while preserving mobility capabilities.
4Adaptability or versatility
If distributed virtual switches are decoupled from underlying hardware, then adaptability and flexibility are improved, but integration with physical network infrastructure becomes complex
Solution Approach 1:
The distributed virtual switch serves as an intermediary layer between virtual machines and physical network infrastructure. This intermediary provides hardware independence by abstracting physical network details while simultaneously managing integration complexity through standardized interfaces and protocols for communicating with physical switches and routers.
Solution Approach 2:
The patent creates a universal distributed virtual switch platform that can adapt to different hardware configurations and physical network infrastructures. The system provides multi-functionality by supporting various physical network technologies while maintaining a consistent virtualized interface, thereby achieving both hardware independence and simplified integration.
Data Source
AI summary
In general, the present invention relates to a virtual platform in which one or more distributed virtual switches can be created for use in virtual networking. According to some aspects, the distributed virtual switch according to the invention provides the ability for virtual and physical machines to more readily, securely, and efficiently communicate with each other even if they are not located on the same physical host and/or in the same subnet or VLAN. According other aspects, the distributed virtual switches of the invention can support integration with traditional IP networks and support sophisticated IP technologies including NAT functionality, stateful firewalling, and notifying the IP network of workload migration. According to further aspects, the virtual platform of the invention creates one or more distributed virtual switches which may be allocated to a tenant, application, or other entity requiring isolation and/or independent configuration state. According to still further aspects, the virtual platform of the invention manages and/or uses VLAN or tunnels (e.g, GRE) to create a distributed virtual switch for a network while working with existing switches and routers in the network. The present invention finds utility in both enterprise networks, datacenters and other facilities.


