Fabric Computing System SDN Controller Secure Partitioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization systems lack adequate security between partitions and require multiple network cards and host bus adapters to interface with data center platforms, leading to complexity and increased resource needs.

Innovation Solution

The Forward Fabric platform system employs a software-defined network with an interconnect backplane and a Forward Fabric Manager to create secure partitions, eliminating the need for network cards and host bus adapters by using non-stop fabric segments for communication between nodes and the data center platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple network cards and host bus adapters are used to interface each partition with the data center platform, then connectivity and communication capability are improved, but device complexity and infrastructure requirements increase

Engineering Contradiction:
Improveconnectivity capabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple network cards and host bus adapters into a single unified fabric interface. The fabric computing system uses a shared fabric network infrastructure that consolidates what would traditionally require multiple separate network interfaces, thereby reducing device complexity while maintaining comprehensive connectivity to the data center platform.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The fabric interface serves multiple functions simultaneously - it provides network connectivity, storage access, and communication capabilities that would traditionally require separate dedicated hardware interfaces. This universal fabric interface replaces multiple specialized network cards and HBAs, reducing overall infrastructure complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If partitions are able to intercommunicate in conventional virtualization systems, then resource sharing and collaboration are improved, but security between partitions deteriorates

Engineering Contradiction:
Improveresource sharing efficiencyVSAvoidpartition security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The fabric computing system introduces a fabric manager and fabric network as intermediaries between partitions. Rather than allowing direct intercommunication between partitions (which compromises security), all communication flows through the fabric manager that enforces security policies and authorization rules, thereby maintaining both security and resource sharing capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments communication paths into controlled fabric network channels managed by the fabric manager. Each partition communicates through dedicated fabric network paths that are logically segmented and controlled, allowing resource sharing while maintaining security boundaries through the fabric manager's authorization mechanisms.

Inventive Principle:
Principle #1Segmentation

3Reliability

If securely partitioned virtualization systems use dedicated physical resources for each partition, then security is improved, but device complexity and hardware requirements increase

Engineering Contradiction:
Improvepartition securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges dedicated physical resource allocation with shared fabric network infrastructure. Instead of requiring separate physical network cards and cables for each partition, the system combines multiple partitions' connectivity needs into a shared fabric network that is logically partitioned and secured by the fabric manager, reducing hardware requirements while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10599458B2Fabric computing system having an embedded software defined network
Publication Date: 2020.03.24 UNISYS CORP
  • US10599458B2 patent drawing
  • US10599458B2 patent drawing
  • US10599458B2 patent drawing

AI summary

A Forward Fabric platform system for coupling to a data center platform. The Forward Fabric platform system includes a plurality of nodes, an interconnect backplane coupled between the nodes, and a Forward Fabric Manager (FFM) coupled to the nodes via the interconnect backplane for controlling and managing the Forward Fabric platform system. The Forward Fabric manager creates at least one secure partition (s-Par) application executing within at least one of the nodes. At least one of the nodes having a secure partition (s-Par) application executing therein also includes a software defined network (SDN) controller executing therein for receiving configuration information and providing at least one secure and non-stop Forward Fabric endpoint on the Forward Fabric platform system for connecting with at least one endpoint on the data center platform. At least one of the nodes having a secure partition (s-Par) application executing therein also includes a traffic control component and a router switch component. At least one the nodes is coupled to the data center platform via one or more non-stop fabric segments.