Hierarchical Network Control for Public Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public datacenters often lack robust and transparent security capabilities, making companies hesitant to move their networks into these environments due to the inability to exercise direct security control, as they do not have access to the virtualization software that manages forwarding elements.
Innovation Solution
A hierarchical network control system is implemented, which manages a logical network spanning across private and public datacenters by operating network controllers and managed forwarding elements within virtual machines in public datacenters, enforcing network security and forwarding rules through a gateway controller and local control agents, and utilizing a central control plane to distribute configuration rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If companies move their networks to public datacenters to reduce costs and physical server burdens, then cost and operational burden are reduced, but direct security control and access to virtualization software are lost
Solution Approach 1:
The patent introduces a forwarding element as an intermediary component deployed within the public datacenter environment that acts as a mediator between the company's network traffic and the public datacenter's infrastructure. This forwarding element, which can be a virtual switch or router, provides the necessary security control and packet forwarding capabilities while operating within the constraints of the public datacenter architecture, thus maintaining security control without requiring direct access to the underlying virtualization software.
2Adaptability or versatility
If public datacenters provide isolated resources (VPCs) to tenants, then resource isolation and control are improved, but robust and transparent security capabilities are still lacking
Solution Approach 1:
The patent applies segmentation by dividing the network control functionality into distinct components: the forwarding element deployed within the VPC and the security/packet forwarding rules managed by the tenant. This segmentation allows the system to provide resource isolation through the VPC structure while simultaneously enabling robust security capabilities through the tenant-controlled forwarding element, resolving the contradiction between isolation and security.
3Reliability
If network controllers and managed forwarding elements are operated within VMs in public datacenters, then network security and forwarding rules can be enforced, but system complexity increases
Solution Approach 1:
The forwarding element is designed as a universal component that performs multiple functions: packet forwarding, security rule enforcement, and integration with both the public datacenter infrastructure and the tenant's network. By consolidating these multiple functions into a single multi-functional component, the system achieves reliable network security control without proportionally increasing complexity, as the forwarding element handles diverse tasks through a unified architecture.
Data Source
AI summary
Some embodiments provide a method for a public cloud manager that interacts with a management system of a public datacenter. The method receives a notification from a network controller that a second data compute node is compromised. The second data compute node operates on a host machine in the public datacenter and executes a forwarding element managed by network controller. The method interacts with application programming interfaces (APIs) of the public datacenter to quarantine the data compute node.


