Logical Network Parsing for Multi-Site Policy Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing logical networks that span multiple physical sites, such as datacenters, is challenging due to the need for self-containment and seamless data transfer between sites, with existing solutions failing to effectively address these issues.

Innovation Solution

A network management system with a global manager and local managers at each site, utilizing a hierarchical tree structure to manage logical network elements and policies across sites, ensuring data synchronization and failover resilience through asynchronous replication and distributed databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a logical network spans multiple physical sites, then data transfer capability between sites is improved, but system complexity and management difficulty increase

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system divides the logical network management into site-specific segments, where each site maintains its own logical network configuration independently. This segmentation allows data transfer between sites while keeping each site's management complexity contained and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components (such as gateway devices or protocol translators) that facilitate communication between different physical sites. These intermediaries handle the complexity of inter-site data transfer, allowing sites to maintain simple local configurations while achieving sophisticated multi-site connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If sites are made self-contained, then site autonomy and reliability are improved, but network integration and data sharing between sites deteriorate

Engineering Contradiction:
Improvesite autonomyVSAvoiddata sharing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Each physical site is segmented as an autonomous logical network unit with its own configuration and management. This segmentation ensures site self-containment and reliability while the system provides mechanisms for controlled data sharing between segmented units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal protocols and interfaces that enable autonomous sites to communicate and share data effectively. The multi-functional architecture allows sites to operate independently while simultaneously participating in the broader federated network for data sharing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Stability of the object's composition

If global configuration is centralized, then policy consistency across sites is improved, but configuration time and system responsiveness worsen

Engineering Contradiction:
Improvepolicy consistencyVSAvoidconfiguration time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring policy templates and validation rules at the global level. When configuration changes are needed, the centralized system has already prepared the framework, allowing for faster propagation and implementation of consistent policies across all sites.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The centralized configuration system implements feedback mechanisms that monitor policy application at each site and automatically adjust configurations to maintain consistency. This feedback loop reduces manual configuration time while ensuring policy uniformity across the federated network.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12399886B2Parsing logical network definition for different sites
Publication Date: 2025.08.26 VMWARE INC
  • US12399886B2 patent drawing
  • US12399886B2 patent drawing
  • US12399886B2 patent drawing

AI summary

Some embodiments provide a method for distributing a service rule that is to be enforced across a first set of sites and that is defined by reference to a group identifier that identifies a group of machines. The method distributes the service rule to each site in the first set of sites. The method identifies at least one site in the first set of sites that is not in a second set of sites that has already received a definition of the group. The method distributes the group definition to each identified site in the first set of sites that has not already received the definition of the group.