Hardware-Based Cross-Domain Micro-Segmentation With Unified Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing micro-segmentation systems lack interoperability between virtualized and physical networks, leading to inefficiencies and security vulnerabilities in data centers with applications spread across domains.

Innovation Solution

A unified controller is used to manage micro-segmentation across virtual, physical, and container networks, employing Ethernet virtual private networks (EVPN) and hardware-based ACL/firewall rules to enforce segmentation policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate SDN controllers are used for physical and virtual networks, then each domain can be managed independently, but interoperability and unified security control are lost

Engineering Contradiction:
Improvedomain independenceVSAvoidinteroperability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges the control functions for physical and virtual networks into a single unified SDN controller. This controller manages both domains through a common control plane, enabling consistent policy enforcement and interoperability across hybrid network architectures while maintaining the ability to handle diverse network types.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified SDN controller is designed with multi-functionality to handle both physical network switching and virtual network virtualization tasks. It implements universal interfaces and protocols that allow it to operate across different network domains, providing consolidated security control and policy management capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If software-based firewall rules are used for micro-segmentation, then flexibility in policy configuration is improved, but processing performance and latency increase

Engineering Contradiction:
Improvepolicy configuration flexibilityVSAvoidtraffic processing speed
Core Design Contradiction:
Ease of operationVSSpeed

Solution Approach 1:

The patent replaces software-based packet filtering with hardware-based filtering using ASICs (Application-Specific Integrated Circuits) in network switches. This substitution moves the filtering function from the software processing plane to the hardware data plane, achieving high-speed packet classification and enforcement while maintaining policy flexibility through the control plane.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system segments the network into micro-segments using hardware-based VLANs and EVPN technology. This segmentation is enforced at the hardware level through switch ASICs, enabling high-performance packet filtering and isolation while the control plane maintains flexible policy configuration capabilities.

Inventive Principle:
Principle #1Segmentation

3Speed

If hardware-based filtering is used for micro-segmentation, then processing performance is improved, but device complexity increases

Engineering Contradiction:
Improvepacket filtering speedVSAvoidhardware configuration complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent introduces a unified SDN controller as an intermediary between the flexible policy configuration needs and the hardware filtering implementation. This controller abstracts the hardware complexity by providing a simplified programming interface for policy definition, while automatically translating policies into hardware-specific commands for ASICs and switches.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses standardized hardware interfaces and protocols that allow different switch vendors' devices to be controlled uniformly. The SDN controller maintains an abstracted view of the network topology and translates diverse hardware configurations into a unified control model, simplifying management while enabling hardware-accelerated filtering.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250286890A1System and methods for hardware-based cross-domain micro-segmentation
Publication Date: 2025.09.11 METALSOFT CLOUD INC
  • US20250286890A1 patent drawing
  • US20250286890A1 patent drawing
  • US20250286890A1 patent drawing

AI summary

A computer network includes: a plurality of hierarchically interconnected nodes that include virtual machines, physical bare metal hosts and container namespaces, wherein the plurality of hierarchically interconnected nodes implement applications across a virtual network domain, a physical network domain and a container network domain; and a single controller configured to provide unified policy application to the plurality of hierarchically interconnected nodes across the virtual network domain, the physical network domain and the container network domain.