Firewall Service VM Migration via SVM Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional hardware firewalls do not leverage the flexibility and control provided by software defined networking (SDN) and network virtualization, lacking effective solutions for incorporating firewall services in virtualized environments.

Innovation Solution

A virtualization architecture that utilizes a firewall service virtual machine (SVM) to check packets for guest virtual machines, with a novel SVM interface (SVMI) allowing the firewall SVM to be accessed for packet inspection, and a firewall engine that communicates with the SVM to enforce firewall rules, including caching actions for efficient packet processing and managing rule checks across virtual network interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a traditional hardware firewall is used in a virtualized environment, then firewall functionality is provided, but flexibility and control from SDN and network virtualization are not leveraged

Engineering Contradiction:
Improveflexibility and controlVSAvoidfirewall service integration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of firewall functionality by implementing a firewall service virtual machine (SVM) that replicates traditional firewall capabilities within the virtualized environment. This allows the firewall service to be instantiated as a VM rather than requiring dedicated hardware, thereby leveraging SDN and network virtualization flexibility while maintaining firewall functionality.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a firewall engine as an intermediary component that bridges the gap between the virtualized network infrastructure and the firewall service VM. The firewall engine manages communication between the SVM and virtual network interfaces, enabling the firewall service to integrate seamlessly with the virtualized environment while maintaining control and flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the firewall SVM checks every packet against the rule set, then security is ensured, but processing performance decreases due to redundant checks

Engineering Contradiction:
Improvesecurity enforcementVSAvoidpacket processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements connection state tracking that performs preliminary actions by recording firewall rules and connection states for established sessions. When subsequent packets arrive for the same connection, the system checks the cached connection state rather than re-evaluating the complete rule set, thereby maintaining security while significantly improving processing performance for established connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the processing parameters by introducing connection state tracking that distinguishes between new connections and established connections. For established connections, the system uses simplified parameter checking based on cached states rather than full rule set evaluation, optimizing performance while maintaining security requirements.

Inventive Principle:
Principle #35Parameter changes

3Stability of the object's composition

If connection state is tracked for each GVM migration, then firewall service continuity is maintained, but system complexity increases

Engineering Contradiction:
Improvefirewall service continuityVSAvoidmigration management
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent creates a universal connection state data store that serves multiple functions: tracking connection states for security enforcement, maintaining service continuity during migrations, and providing cached information for performance optimization. This multi-functional approach maintains firewall service continuity across GVM migrations without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9215210B2Migrating firewall connection state for a firewall service virtual machine
Publication Date: 2015.12.15 VMWARE INC
  • US9215210B2 patent drawing
  • US9215210B2 patent drawing
  • US9215210B2 patent drawing

AI summary

For a host that executes one or more guest virtual machines (GVMs), some embodiments provide a novel virtualization architecture for utilizing a firewall service virtual machine (SVM) on the host to check the packets sent by and/or received for the GVMs. In some embodiments, the GVMs connect to a software forwarding element (e.g., a software switch) that executes on the host to connect to each other and to other devices operating outside of the host. Instead of connecting the firewall SVM to the host's software forwarding element that connects its GVMs, the virtualization architecture of some embodiments provides an SVM interface (SVMI) through which the firewall SVM can be accessed to check the packets sent by and/or received for the GVMs.