Hierarchical Network Control for Public Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public datacenters often lack robust and transparent security capabilities, making companies hesitant to move their networks into these environments due to the inability to exercise direct security control, as they do not have access to the virtualization software that manages forwarding elements.

Innovation Solution

A hierarchical network control system is implemented, which manages a logical network spanning across private and public datacenters by operating network controllers and managed forwarding elements within virtual machines in public datacenters, enforcing network security and forwarding rules through a gateway controller and local control agents, and utilizing a central control plane to distribute configuration rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If companies move their networks to public datacenters to reduce costs and physical server burdens, then cost and operational burden are reduced, but direct security control and access to virtualization software are lost

Engineering Contradiction:
Improveoperational burdenVSAvoiddirect security control
Core Design Contradiction:
Loss of energyVSEase of operation

Solution Approach 1:

The patent introduces a forwarding element as an intermediary component deployed within the public datacenter environment that acts as a mediator between the company's network traffic and the public datacenter's infrastructure. This forwarding element, which can be a virtual switch or router, provides the necessary security control and packet forwarding capabilities while operating within the constraints of the public datacenter architecture, thus maintaining security control without requiring direct access to the underlying virtualization software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If public datacenters provide isolated resources (VPCs) to tenants, then resource isolation and control are improved, but robust and transparent security capabilities are still lacking

Engineering Contradiction:
Improveresource isolationVSAvoidsecurity capabilities
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the network control functionality into distinct components: the forwarding element deployed within the VPC and the security/packet forwarding rules managed by the tenant. This segmentation allows the system to provide resource isolation through the VPC structure while simultaneously enabling robust security capabilities through the tenant-controlled forwarding element, resolving the contradiction between isolation and security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If network controllers and managed forwarding elements are operated within VMs in public datacenters, then network security and forwarding rules can be enforced, but system complexity increases

Engineering Contradiction:
Improvenetwork security controlVSAvoidhierarchical control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The forwarding element is designed as a universal component that performs multiple functions: packet forwarding, security rule enforcement, and integration with both the public datacenter infrastructure and the tenant's network. By consolidating these multiple functions into a single multi-functional component, the system achieves reliable network security control without proportionally increasing complexity, as the forwarding element handles diverse tasks through a unified architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10805330B2Identifying and handling threats to data compute nodes in public cloud
Publication Date: 2020.10.13 VMWARE INC
  • US10805330B2 patent drawing
  • US10805330B2 patent drawing
  • US10805330B2 patent drawing

AI summary

Some embodiments provide a method for a public cloud manager that interacts with a management system of a public datacenter. The method receives a notification from a network controller that a second data compute node is compromised. The second data compute node operates on a host machine in the public datacenter and executes a forwarding element managed by network controller. The method interacts with application programming interfaces (APIs) of the public datacenter to quarantine the data compute node.