Edge Modules for Virtual Network Communication Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing large-scale computer networks has become increasingly complex due to the scale and scope of data centers, with existing technologies struggling to efficiently provision, administer, and manage physical computing resources across diverse geographical locations and virtual environments.
Innovation Solution
A system for managing communications in a managed virtual computer network that overlays a substrate network, using configurable network services, edge modules, and communication manager modules to integrate and manage computing nodes and external nodes, enabling efficient communication and resource sharing across diverse locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtualization technologies are used to share physical computing resources among multiple customers, then resource utilization efficiency is improved, but network management complexity increases
Solution Approach 1:
The patent introduces a network virtualization layer as an intermediary between physical computing resources and multiple customers. This virtualization layer abstracts and manages the complexity of physical resource sharing, enabling efficient multi-tenant resource utilization while isolating management complexity within the virtualization infrastructure rather than propagating it to end users.
Solution Approach 2:
The patent segments the network management function into distinct virtualized components that can be independently managed and allocated to different customers. By dividing the monolithic network management task into modular virtual network instances, the system achieves efficient resource sharing while containing management complexity within manageable segments.
2Adaptability or versatility
If external nodes are integrated into the managed virtual computer network, then network versatility and connectivity are improved, but network security and isolation are compromised
Solution Approach 1:
The patent implements a nested virtualization architecture where external nodes are integrated through multiple layers of virtualization. External nodes are encapsulated within virtual network boundaries that are themselves nested within the managed virtual computer network, allowing versatile connectivity while maintaining security isolation through the nested virtualization layers.
Solution Approach 2:
The patent applies different security and isolation characteristics to different parts of the network based on their function and sensitivity. External nodes receive appropriate levels of access and isolation tailored to their specific requirements, allowing the network to achieve overall versatility while maintaining localized security controls where needed.
Data Source
AI summary
Techniques are described for managing communications for a managed virtual computer network overlaid on a distinct substrate computer network, including for communications involving computing nodes of the managed virtual computer network connected to the substrate network and/or other external nodes of the managed virtual computer network that are not connected to the substrate network. The managed virtual computer network may have multiple associated virtual network addresses, and the managing of the communications may further include using one or more edge modules to direct all communication that have a destination virtual network address within a range or other group of multiple virtual network addresses assigned to one or more external nodes to be forwarded over the substrate network to an edge module associated with the one or more external nodes, including to route communications between different external nodes via the substrate network.


