Isolated VLAN Provisioning for Secure Utility Computing Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current utility computing environments face limitations in sharing services within a VLAN, as only the management server can provide services, and resources are charged regardless of utilization, leading to inefficiencies and constraints on service provision and billing.

Innovation Solution

A method is introduced to establish an isolated VLAN for shared services, allowing selective usage and billing, utilizing data link layer/layer 2 access control technology, enabling any virtually provisioned or external resource to act as a service provider within a primary VLAN, and supporting high availability and load balancing topologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a management server provides services to all resources within a VLAN, then service availability is improved, but resource utilization efficiency deteriorates because all resources are charged regardless of actual usage

Engineering Contradiction:
Improveservice availabilityVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the VLAN into multiple isolated VLANs, each dedicated to specific service providers and consumers. This segmentation enables selective service provision where only authorized resources can access specific services, allowing for accurate tracking and billing based on actual utilization while maintaining service availability through dedicated service paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces network switches configured with promiscuous and isolated ports as intermediaries. Promiscuous ports allow service providers to receive service requests from multiple consumers, while isolated ports ensure that service traffic is properly routed and contained. This intermediary mechanism enables selective service delivery and accurate utilization tracking without compromising service availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If services are pre-wired to a central top tier switch, then service deployment speed is improved, but system flexibility deteriorates because services cannot be dynamically provisioned to arbitrary resources

Engineering Contradiction:
Improveservice deployment speedVSAvoidservice provisioning flexibility
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic service provisioning through software-configurable network switches that can dynamically create and modify VLAN assignments. Service providers and consumers can be dynamically paired through configuration changes rather than physical re-wiring, enabling both rapid service deployment and flexible adaptation to changing requirements. The system maintains pre-configured service templates for quick deployment while allowing dynamic instantiation to specific resources.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent moves service provisioning from a single dimension (physical wiring) to multiple dimensions by introducing virtual networking layers. Instead of relying solely on physical switch connections, the system uses virtual VLANs and software-defined networking to provide service connectivity, enabling dynamic provisioning while maintaining the benefits of pre-configured service templates.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If isolated VLANs are established for each shared service, then service security is improved, but network complexity increases due to multiple VLAN configurations

Engineering Contradiction:
Improveservice securityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes network switches universal by configuring them with both promiscuous and isolated port capabilities. These multi-functional switches can simultaneously handle multiple VLANs, service providers, and consumers within a single device, reducing the need for separate dedicated infrastructure for each service while maintaining strong security isolation through software configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Manufacturing precision

If technicians manually connect and configure devices for network modifications, then configuration accuracy is improved, but modification time increases significantly

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidmodification time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent enables self-service automated provisioning where the system automatically configures VLAN assignments, service provider-consumer pairings, and network switch settings through software commands. This eliminates the need for manual technician intervention while maintaining configuration accuracy through automated validation and consistent application of provisioning rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary configuration of service templates and network switch capabilities before actual service provisioning. Network switches are pre-configured with promiscuous and isolated port modes, and service templates define standard VLAN assignments and access rules. This preliminary setup enables rapid, accurate service deployment without requiring manual configuration during the provisioning process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8908708B2Secure method and apparatus for enabling the provisioning of a shared service in a utility computing environment
Publication Date: 2014.12.09 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8908708B2 patent drawing
  • US8908708B2 patent drawing
  • US8908708B2 patent drawing

AI summary

Embodiments of the invention provide a secure method for enabling the provisioning of a shared service in a utility computing environment. One embodiment establishes an account primary virtual local area network (VLAN) for at least one account in a utility computing environment. Then, a request is received from a service provider to provide a shared service to the at least one account. An isolated VLAN is established for each shared service being provisioned in the context of the account primary VLAN and a promiscuous port is provided for the service provider. A selection option is then provided to allow the at least one server to utilize the shared service provided by the service provider. An isolated port is then configured for the at least one server on an isolated VLAN between the at least one server that chooses to utilize the shared service, and the shared service.