Isolated VLAN Provisioning for Secure Utility Computing Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current utility computing environments face limitations in sharing services within a VLAN, as only the management server can provide services, and resources are charged regardless of utilization, leading to inefficiencies and constraints on service provision and billing.
Innovation Solution
A method is introduced to establish an isolated VLAN for shared services, allowing selective usage and billing, utilizing data link layer/layer 2 access control technology, enabling any virtually provisioned or external resource to act as a service provider within a primary VLAN, and supporting high availability and load balancing topologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a management server provides services to all resources within a VLAN, then service availability is improved, but resource utilization efficiency deteriorates because all resources are charged regardless of actual usage
Solution Approach 1:
The patent segments the VLAN into multiple isolated VLANs, each dedicated to specific service providers and consumers. This segmentation enables selective service provision where only authorized resources can access specific services, allowing for accurate tracking and billing based on actual utilization while maintaining service availability through dedicated service paths.
Solution Approach 2:
The patent introduces network switches configured with promiscuous and isolated ports as intermediaries. Promiscuous ports allow service providers to receive service requests from multiple consumers, while isolated ports ensure that service traffic is properly routed and contained. This intermediary mechanism enables selective service delivery and accurate utilization tracking without compromising service availability.
2Speed
If services are pre-wired to a central top tier switch, then service deployment speed is improved, but system flexibility deteriorates because services cannot be dynamically provisioned to arbitrary resources
Solution Approach 1:
The patent implements dynamic service provisioning through software-configurable network switches that can dynamically create and modify VLAN assignments. Service providers and consumers can be dynamically paired through configuration changes rather than physical re-wiring, enabling both rapid service deployment and flexible adaptation to changing requirements. The system maintains pre-configured service templates for quick deployment while allowing dynamic instantiation to specific resources.
Solution Approach 2:
The patent moves service provisioning from a single dimension (physical wiring) to multiple dimensions by introducing virtual networking layers. Instead of relying solely on physical switch connections, the system uses virtual VLANs and software-defined networking to provide service connectivity, enabling dynamic provisioning while maintaining the benefits of pre-configured service templates.
3Reliability
If isolated VLANs are established for each shared service, then service security is improved, but network complexity increases due to multiple VLAN configurations
Solution Approach 1:
The patent makes network switches universal by configuring them with both promiscuous and isolated port capabilities. These multi-functional switches can simultaneously handle multiple VLANs, service providers, and consumers within a single device, reducing the need for separate dedicated infrastructure for each service while maintaining strong security isolation through software configuration.
4Manufacturing precision
If technicians manually connect and configure devices for network modifications, then configuration accuracy is improved, but modification time increases significantly
Solution Approach 1:
The patent enables self-service automated provisioning where the system automatically configures VLAN assignments, service provider-consumer pairings, and network switch settings through software commands. This eliminates the need for manual technician intervention while maintaining configuration accuracy through automated validation and consistent application of provisioning rules.
Solution Approach 2:
The patent implements preliminary configuration of service templates and network switch capabilities before actual service provisioning. Network switches are pre-configured with promiscuous and isolated port modes, and service templates define standard VLAN assignments and access rules. This preliminary setup enables rapid, accurate service deployment without requiring manual configuration during the provisioning process.
Data Source
AI summary
Embodiments of the invention provide a secure method for enabling the provisioning of a shared service in a utility computing environment. One embodiment establishes an account primary virtual local area network (VLAN) for at least one account in a utility computing environment. Then, a request is received from a service provider to provide a shared service to the at least one account. An isolated VLAN is established for each shared service being provisioned in the context of the account primary VLAN and a promiscuous port is provided for the service provider. A selection option is then provided to allow the at least one server to utilize the shared service provided by the service provider. An isolated port is then configured for the at least one server on an isolated VLAN between the at least one server that chooses to utilize the shared service, and the shared service.


