Flexible Data Center Security Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data center architectures are complex and costly, with increased latency due to multiple layers of switches and unnecessary packet processing, leading to poor scalability and high costs as the number of servers increases.

Innovation Solution

A multi-stage switch fabric architecture with edge devices and a centralized switch core that provides any-to-any connectivity, allowing virtual resources to be migrated and managed efficiently, reducing latency and costs through a single logical entity and dynamic network management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple layers of switches are used in data center architecture, then connectivity and scalability are improved, but latency increases and packet processing becomes redundant

Engineering Contradiction:
ImproveconnectivityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent merges multiple switch layers into a single centralized switch core, eliminating redundant intermediate switching layers. This consolidation maintains any-to-any connectivity while reducing the number of packet processing hops, thereby lowering latency without sacrificing adaptability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized switch core is designed to perform multiple functions that were previously distributed across multiple switch layers, including packet routing, forwarding, and connectivity management. This universal design eliminates redundant processing while maintaining comprehensive connectivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple layers of switches are used in data center architecture, then connectivity is improved, but device complexity and costs increase

Engineering Contradiction:
ImproveconnectivityVSAvoidarchitecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent consolidates multiple distributed switch components into a single centralized switch core, dramatically simplifying the overall architecture. This merger reduces the number of devices that need to be managed, configured, and maintained, while preserving full connectivity capabilities through the unified core.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If traditional multi-layer switch architecture is used, then packet processing is thorough, but scalability becomes poor as servers increase

Engineering Contradiction:
Improvepacket processingVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The centralized switch core is designed as a universal processing platform that can handle packet processing for any number of connected servers. Its multi-functional architecture allows it to scale efficiently by accommodating increasing server counts without requiring additional switching layers, maintaining both thorough processing and scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12068978B2Methods and apparatus related to a flexible data center security architecture
Publication Date: 2024.08.20 JUNIPER NETWORKS INC
  • US12068978B2 patent drawing
  • US12068978B2 patent drawing
  • US12068978B2 patent drawing

AI summary

In one embodiment, edge devices can be configured to be coupled to a multi-stage switch fabric and peripheral processing devices. The edge devices and the multi-stage switch fabric can collectively define a single logical entity. A first edge device from the edge devices can be configured to be coupled to a first peripheral processing device from the peripheral processing devices. The second edge device from the edge devices can be configured to be coupled to a second peripheral processing device from the peripheral processing devices. The first edge device can be configured such that virtual resources including a first virtual resource can be defined at the first peripheral processing device. A network management module coupled to the edge devices and configured to provision the virtual resources such that the first virtual resource can be migrated from the first peripheral processing device to the second peripheral processing device.