Dual-NIC Security Fabric Architecture for Scalable Network Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The scalability issue arises from the need for multiple node ports on each network node in a cluster of virtual machines or containers, which increases proportionately with the number of customers, leading to inefficiencies in network traffic management.

Innovation Solution

A security fabric platform with dual-NIC virtual machines and containers, utilizing service chaining and NAT routing, allows for flexible deployment and instantiation of VNFs and CNFs, enabling high scalability and efficient network service provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple node ports are opened on each network node to support network traffic transmission, then network service functionality is improved, but the number of ports increases proportionately with the number of customers, leading to scalability issues

Engineering Contradiction:
Improvenetwork service functionalityVSAvoidnumber of node ports
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments network traffic processing by introducing dedicated ingress and egress VMs that handle network traffic separately from compute workloads. Each VM in the cluster only needs a single node port, and the dedicated network VMs aggregate traffic from multiple customers, eliminating the need for multiple ports on each compute node while maintaining full network service functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dedicated ingress and egress VMs as intermediary components between network infrastructure and compute workloads. These intermediary VMs act as network translators and traffic aggregators, allowing compute nodes to communicate with external networks through a single port while the intermediary handles the complexity of multi-customer traffic management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the number of node ports increases proportionately with the number of customers, then network service coverage is improved, but scalability and operational efficiency deteriorate

Engineering Contradiction:
Improvenetwork service coverageVSAvoidoperational efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent merges network traffic processing functions into dedicated ingress and egress VMs that aggregate traffic from multiple customers. Instead of distributing multiple ports across many compute nodes, the system combines all network traffic through a centralized virtual networking layer, improving operational efficiency while maintaining comprehensive network service coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The dedicated ingress and egress VMs serve multiple functions simultaneously: they act as network translators, traffic aggregators, security gateways, and service orchestrators. This multi-functionality eliminates the need for multiple specialized ports on each node, improving operational efficiency while maintaining universal network service coverage across all customers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional node port configuration is used for network traffic, then network connectivity is established, but scalability becomes problematic as customer base grows

Engineering Contradiction:
Improvenetwork connectivityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network connectivity into two distinct paths: a simplified compute node path with a single node port, and a dedicated network VM path that handles all traffic aggregation and translation. This segmentation maintains reliable network connectivity while eliminating scalability problems by preventing the complexity of multiple ports from propagating through the entire cluster.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The dedicated ingress and egress VMs serve as intermediaries that translate between the simplified single-port compute node interface and the complex multi-customer network infrastructure. This intermediary layer maintains reliable network connectivity for each customer while protecting the scalability of the system by centralizing all connectivity complexity in specialized VMs rather than distributing it across all nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250317420A1Security fabric platform network services architecture and functionalities
Publication Date: 2025.10.09 LEVEL 3 COMMUNICATIONS LLC
  • US20250317420A1 patent drawing
  • US20250317420A1 patent drawing
  • US20250317420A1 patent drawing

AI summary

Novel tools and techniques are provided for implementing security fabric platform network services architecture and functionalities. In various embodiments, at least one VM among a plurality of virtual machines (“VMs”) that is hosted on a security fabric platform includes dual network interface controllers (“NICs”) or virtual NICs (“VNICs”). A request to perform a set of tasks may be routed to a VM of the plurality of VMs via one of the NICs or VNICs. Two or more VMs and/or one or more containers hosted on the security fabric platform and/or on one or more worker nodes may be service chained from one to another of the NICs or VNICs of the VMs and/or containers. Results of the set of tasks as processed by virtual or cloud-native network functions may be routed via a firewall, via network address translation, from and to a destination network address associated with a destination device.