Interface-Based ACLs for Scalable Layer-2 Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual networks in cloud computing environments have limitations that restrict their functionality and value, particularly in managing and routing packets within virtual local area networks (VLANs) and addressing the need for improved access control in Layer-2 networks.

Innovation Solution

Implementing a virtual Layer 3 network hosted by an underlying physical network, along with a virtual Layer 2 network, utilizing a VLAN switching and routing service (VSRS) to manage packet delivery and apply access control lists (ACLs) within virtual networks, and employing a distributed switch system to route outbound traffic based on interface-to-MAC address mappings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual networks are implemented in cloud computing environments, then resource sharing and scalability are improved, but network security and access control become more difficult to manage

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidnetwork security risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments network security control into interface-level ACLs (Access Control Lists) that are attached to specific virtual network interfaces. Each interface can have its own security rules, allowing granular control over traffic flow while maintaining overall network scalability. This segmentation enables independent security management for each interface without affecting the entire virtual network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces interface ACLs as intermediary security mechanisms between the virtual network interfaces and the underlying physical network. These ACLs act as mediators that inspect and control packet flow at the interface level, providing security without requiring changes to the core virtual network architecture or requiring manual intervention for each security rule.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If manual packet filtering is implemented for security, then access control is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveaccess control securityVSAvoidpacket filtering complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service packet filtering where interface ACLs automatically process packets based on pre-configured rules without requiring manual intervention. The system automatically applies security rules to incoming and outgoing traffic at the interface level, reducing the need for complex manual packet filtering configurations while maintaining strong access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges security filtering functionality directly into the network interface handling mechanism. By combining packet filtering with the interface processing logic, the system eliminates separate complex filtering systems and integrates security control into the fundamental packet processing path, reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Object-affected harmful factors

If traditional Layer-2 switching is used, then network isolation is maintained, but routing flexibility and inter-VLAN communication are limited

Engineering Contradiction:
Improvenetwork isolation securityVSAvoidrouting flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent creates interface ACLs that serve multiple functions simultaneously: they provide Layer-2 packet filtering for security, enable Layer-3 routing decisions for inter-VLAN communication, and maintain network isolation between different virtual networks. This multi-functionality allows a single interface mechanism to handle both isolation and routing flexibility without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds a new dimension to network control by introducing interface-level ACLs that operate independently of traditional VLAN tagging mechanisms. This new dimension allows for granular control over packet flow at the interface level, enabling routing flexibility while maintaining isolation through a different architectural approach rather than expanding existing VLAN infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250260643A1Interface-based ACLS in a layer-2 network
Publication Date: 2025.08.14 ORACLE INT CORP
  • US20250260643A1 patent drawing
  • US20250260643A1 patent drawing
  • US20250260643A1 patent drawing

AI summary

Systems and methods of interface-based ACLs in a virtual Layer-2 network. The method can include sending a packet from source compute instance in a virtual network to a destination compute instance via a destination virtual network interface card (destination VNIC) within a first virtual layer 2 network and evaluating an access control list (ACL) for the packet with a source virtual network interface card (source VNIC). ACL information relevant to the packet can be embedded in the packet. The VSRS can receive the packet and can identify the destination VNIC within the first virtual layer 2 network for delivery of the packet based on information received with the packet and mapping information contained within a mapping table. The VSRS can access ACL information from the packet and can apply the ACL information to the packet.