Graph-Based Network Fabric for Cloud Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Accessing and monitoring virtualized traffic traversing cloud computing platforms for analysis is challenging due to multi-tenancy and location independence in public clouds, which restricts the use of traditional agent-based monitoring technologies, leading to complex architectures, performance degradation, and reactive visibility.

Innovation Solution

A visibility platform integrated into cloud computing platforms, using agents, network visibility appliances, and controllers to selectively mirror, filter, and forward virtualized traffic, providing a coherent view across public cloud architectures and enabling centralized management and traffic routing through programmable switches and graph-based network fabrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional agent-based monitoring technologies are used in public clouds, then monitoring capability is provided, but system complexity increases and performance degrades

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a visibility platform as an intermediary layer between cloud infrastructure and monitoring tools. This platform includes a programmable switch that sits at the network level, capturing traffic before it reaches virtual machines. The switch acts as a mediator that provides monitoring capabilities without requiring agents inside each VM, thereby reducing architectural complexity while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of deploying software agents in each virtual machine with a hardware-based solution using a programmable network switch. The switch captures and forwards traffic at the network level, eliminating the need for complex agent-based systems and reducing overall architecture complexity while maintaining monitoring effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional agent-based monitoring technologies are used in public clouds, then monitoring capability is provided, but performance degradation occurs

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The visibility platform with programmable switch acts as an intermediary that captures traffic at the network level before it enters the virtual machine processing path. This approach provides monitoring capability without adding overhead to the actual system operations, thereby maintaining productivity while ensuring reliable monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If cloud platforms provide on-demand access to shared resources, then resource efficiency is improved, but traffic visibility and control are lost

Engineering Contradiction:
Improveresource flexibilityVSAvoidtraffic visibility
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The programmable switch is configured in advance to capture and forward traffic to the visibility platform before the traffic is processed by virtual machines. This preliminary action ensures that traffic visibility is maintained from the outset, allowing cloud platforms to provide on-demand access to shared resources without losing traffic information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The visibility platform serves as an intermediary that provides traffic visibility and control capabilities in the cloud environment. It captures traffic at the network level and makes it available for analysis without interfering with the on-demand resource access and flexibility that cloud platforms provide.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If network traffic is routed through multiple network objects, then traffic management capability is improved, but routing complexity increases

Engineering Contradiction:
Improvetraffic management capabilityVSAvoidrouting complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a graph-based network fabric where the network topology and routing paths are dynamic and programmable. The system can adapt routing paths based on traffic requirements and network conditions, providing flexible traffic management capability while the graph representation simplifies the complexity of routing through multiple network objects.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The visibility platform provides multiple functions including traffic capture, filtering, forwarding, and analysis through a unified system. This multi-functionality reduces the need for separate specialized devices and simplifies the overall routing complexity while maintaining comprehensive traffic management capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12068905B2Graph-based network fabric for a network visibility appliance
Publication Date: 2024.08.20 GIGAMON INC
  • US12068905B2 patent drawing
  • US12068905B2 patent drawing
  • US12068905B2 patent drawing

AI summary

With exponential growth in virtualized traffic within physical data centers, many end users (e.g., individuals and enterprises) have begun moving work processes and data to cloud computing platforms. A visibility platform can be used to monitor virtualized traffic traversing a cloud computing platform, such as Amazon Web Services, VMware, or OpenStack. But it can be difficult to manage how the visibility platform handles incoming virtualized traffic. Introduced here, therefore, are graphs that visually represent the network fabric of a visibility platform. When the network fabric of the visibility platform is represented as a graph, an end user can easily modify the network fabric, for example, by adding, removing, or modifying nodes that represent network objects, adding, removing, or modifying connections between pairs of nodes that represent traffic flows between pairs of network objects, etc.