Hardware-Based Cross-Domain Micro-Segmentation With Unified Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing micro-segmentation systems lack interoperability between virtualized and physical networks, leading to inefficiencies and security vulnerabilities in data centers with applications spread across domains.
Innovation Solution
A unified controller is used to manage micro-segmentation across virtual, physical, and container networks, employing Ethernet virtual private networks (EVPN) and hardware-based ACL/firewall rules to enforce segmentation policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If separate SDN controllers are used for physical and virtual networks, then each domain can be managed independently, but interoperability and unified security control are lost
Solution Approach 1:
The patent merges the control functions for physical and virtual networks into a single unified SDN controller. This controller manages both domains through a common control plane, enabling consistent policy enforcement and interoperability across hybrid network architectures while maintaining the ability to handle diverse network types.
Solution Approach 2:
The unified SDN controller is designed with multi-functionality to handle both physical network switching and virtual network virtualization tasks. It implements universal interfaces and protocols that allow it to operate across different network domains, providing consolidated security control and policy management capabilities.
2Ease of operation
If software-based firewall rules are used for micro-segmentation, then flexibility in policy configuration is improved, but processing performance and latency increase
Solution Approach 1:
The patent replaces software-based packet filtering with hardware-based filtering using ASICs (Application-Specific Integrated Circuits) in network switches. This substitution moves the filtering function from the software processing plane to the hardware data plane, achieving high-speed packet classification and enforcement while maintaining policy flexibility through the control plane.
Solution Approach 2:
The system segments the network into micro-segments using hardware-based VLANs and EVPN technology. This segmentation is enforced at the hardware level through switch ASICs, enabling high-performance packet filtering and isolation while the control plane maintains flexible policy configuration capabilities.
3Speed
If hardware-based filtering is used for micro-segmentation, then processing performance is improved, but device complexity increases
Solution Approach 1:
The patent introduces a unified SDN controller as an intermediary between the flexible policy configuration needs and the hardware filtering implementation. This controller abstracts the hardware complexity by providing a simplified programming interface for policy definition, while automatically translating policies into hardware-specific commands for ASICs and switches.
Solution Approach 2:
The system uses standardized hardware interfaces and protocols that allow different switch vendors' devices to be controlled uniformly. The SDN controller maintains an abstracted view of the network topology and translates diverse hardware configurations into a unified control model, simplifying management while enabling hardware-accelerated filtering.
Data Source
AI summary
A computer network includes: a plurality of hierarchically interconnected nodes that include virtual machines, physical bare metal hosts and container namespaces, wherein the plurality of hierarchically interconnected nodes implement applications across a virtual network domain, a physical network domain and a container network domain; and a single controller configured to provide unified policy application to the plurality of hierarchically interconnected nodes across the virtual network domain, the physical network domain and the container network domain.


