Layer-2 Virtual Networking Through Distributed ACLs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualized cloud environments lack efficient Layer 2 networking functionality, limiting the flexibility and performance of virtual networks.

Innovation Solution

Implementing an infinitely scalable distributed switch that emulates a single switch connecting compute instances, utilizing Layer 2 virtual network interface cards (VNICs) and local switches, and supporting Layer 2 access control lists (ACLs) to enhance network connectivity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Layer 2 networking functionality is added to virtualized cloud environments, then network connectivity and security are improved, but device complexity increases

Engineering Contradiction:
Improvenetwork connectivityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines Layer 2 switching functionality with the existing virtualized network infrastructure by integrating virtual switches into the cloud environment. This merging allows Layer 2 networking to be provided using existing physical switches and virtual network interface cards, avoiding the need for separate dedicated Layer 2 hardware while still achieving the desired connectivity and security features.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The virtual switches and network interface cards are designed to perform multiple functions including Layer 2 switching, security filtering through virtual ACLs, and integration with both physical and virtual networks. This multi-functionality reduces the need for separate specialized devices, thereby managing complexity while providing comprehensive networking capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If access control lists are implemented at Layer 2, then network security is improved, but processing overhead increases

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of implementing full packet inspection for every traffic flow, the system uses virtual ACLs that copy and apply simplified filtering rules at the virtual switch level. This allows security policies to be enforced efficiently without requiring deep packet inspection of all traffic, reducing processing overhead while maintaining security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system applies partial security filtering by implementing ACLs that focus on most critical security scenarios rather than exhaustive packet analysis. This partial action approach provides sufficient security protection for typical workloads while minimizing the processing overhead that would result from complete packet inspection of all traffic types.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If a distributed switch architecture is used, then scalability is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork scalabilityVSAvoiddistributed switch complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The distributed switch architecture segments the network into multiple virtual switches, each managing a specific subset of virtual machines or network segments. This segmentation allows the system to scale by adding more virtual switches rather than requiring a single monolithic switch to handle all traffic, thereby improving scalability while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual switches act as intermediaries between physical network infrastructure and virtual machines, abstracting the complexity of the distributed architecture from end users. This intermediary layer presents a simplified interface for network connectivity while handling the complex routing and switching decisions internally, thus improving scalability without proportionally increasing user-visible complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250317388A1Layer-2 networking using access control lists in a virtualized cloud environment
Publication Date: 2025.10.09 ORACLE INT CORP
  • US20250317388A1 patent drawing
  • US20250317388A1 patent drawing
  • US20250317388A1 patent drawing

AI summary

Techniques are described for communications in an L2 virtual network. In an example, the L2 virtual network includes a plurality of L2 compute instances hosted on a set of host machines and a plurality of L2 virtual network interfaces and L2 virtual switches hosted on a set of network virtualization devices. An L2 virtual network interface emulates an L2 port of the L2 virtual network. Access control list (ACL) information applicable to the L2 port is sent to a network virtualization device that hosts the L2 virtual network interface.