Distributed Virtual Switches for Scalable Multi-Tenant Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional distributed virtual switches fail to address scalability, mobility, and multi-tenancy in large networks, as they do not effectively bridge IP subnets, scale to support thousands of end hosts, and integrate physical hosts in a flexible manner.

Innovation Solution

A virtual platform that creates distributed virtual switches to enable secure and efficient communication between virtual and physical machines across different subnets and VLANs, supporting integration with traditional IP networks and providing features like NAT functionality and stateful firewalling, while managing VLANs or tunnels to maintain isolation and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional distributed virtual switches are used, then network functionality is provided for virtual machines, but scalability to support tens of thousands of end hosts is limited

Engineering Contradiction:
Improvenumber of end hostsVSAvoidswitch architecture complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the virtual switch functionality into distributed virtual switch components that can be distributed across multiple physical hosts. Each host runs a instance of the virtual switch, and they work together as a coordinated system. This segmentation allows the network to scale to tens of thousands of end hosts by adding more host instances rather than requiring a single complex centralized switch.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional approach by creating a distributed architecture that spans multiple physical hosts and network segments. Instead of scaling horizontally within a single switch device, the system scales by adding vertical dimensions of host instances and network segments, allowing exponential growth in supported end hosts.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If tenant isolation is retained, then security and multi-tenancy are improved, but mobility of virtual machines is complicated

Engineering Contradiction:
Improvetenant isolationVSAvoidvirtual machine mobility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal distributed virtual switch architecture that can simultaneously support multiple tenants with isolation requirements while also enabling virtual machine mobility. The system provides multi-functionality by implementing both strict tenant isolation and seamless migration capabilities within the same framework, allowing a single platform to serve diverse operational requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The distributed virtual switch acts as an intermediary layer between virtual machines and physical network infrastructure. This intermediary maintains tenant isolation policies while simultaneously enabling mobility by managing the abstraction between virtual and physical network states, allowing VMs to move without breaking isolation guarantees.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If L2 domains are extended, then virtual machine mobility is improved, but the domain cannot scale to large sizes

Engineering Contradiction:
Improvevirtual machine mobilityVSAvoiddomain size
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent segments large L2 domains into manageable distributed virtual switch instances across multiple physical hosts. Each instance manages a portion of the overall domain, allowing the total domain to scale to large sizes while maintaining the mobility benefits of L2 connectivity. The segmented architecture prevents the single-domain scalability limitations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extends L2 domains into another dimension by distributing them across multiple physical hosts and network segments. Instead of being constrained to a single L2 domain size, the system creates multi-dimensional L2 connectivity that can scale to tens of thousands of hosts while preserving mobility capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Adaptability or versatility

If distributed virtual switches are decoupled from underlying hardware, then adaptability and flexibility are improved, but integration with physical network infrastructure becomes complex

Engineering Contradiction:
Improvehardware independenceVSAvoidphysical network integration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The distributed virtual switch serves as an intermediary layer between virtual machines and physical network infrastructure. This intermediary provides hardware independence by abstracting physical network details while simultaneously managing integration complexity through standardized interfaces and protocols for communicating with physical switches and routers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal distributed virtual switch platform that can adapt to different hardware configurations and physical network infrastructures. The system provides multi-functionality by supporting various physical network technologies while maintaining a consistent virtualized interface, thereby achieving both hardware independence and simplified integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11425055B2Method and apparatus for implementing and managing virtual switches
Publication Date: 2022.08.23 VMWARE INC
  • US11425055B2 patent drawing
  • US11425055B2 patent drawing
  • US11425055B2 patent drawing

AI summary

In general, the present invention relates to a virtual platform in which one or more distributed virtual switches can be created for use in virtual networking. According to some aspects, the distributed virtual switch according to the invention provides the ability for virtual and physical machines to more readily, securely, and efficiently communicate with each other even if they are not located on the same physical host and/or in the same subnet or VLAN. According other aspects, the distributed virtual switches of the invention can support integration with traditional IP networks and support sophisticated IP technologies including NAT functionality, stateful firewalling, and notifying the IP network of workload migration. According to further aspects, the virtual platform of the invention creates one or more distributed virtual switches which may be allocated to a tenant, application, or other entity requiring isolation and/or independent configuration state. According to still further aspects, the virtual platform of the invention manages and/or uses VLAN or tunnels (e.g, GRE) to create a distributed virtual switch for a network while working with existing switches and routers in the network. The present invention finds utility in both enterprise networks, datacenters and other facilities.