Logical Port Classifications for Virtual Network Scalability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network virtualization technologies face challenges in efficiently implementing port features such as port isolation and security across large networks due to the limited number of bits in 802.1PQ tags and DSCP fields, which are inadequate for classifying logical flows in virtualized environments, leading to unsustainable network state requirements as the number of logical networks grows.
Innovation Solution
A network control system that uses port group identifiers to classify logical source and destination ports into disjoint groups, encoding these identifiers in tunneled traffic to minimize the number of forwarding rules needed at each physical network element, allowing for scalable implementation of logical port classifications and features like port isolation and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If 802.1PQ tags and DSCP fields are used for traffic classification, then priority encoding is achieved, but the number of distinct values is limited to 7 or more with unsustainable network state growth
Solution Approach 1:
The patent segments the classification task by introducing a two-level hierarchy: logical port group identifiers (coarse-grained classification) and individual logical port identifiers (fine-grained classification). This segmentation allows the system to manage classification state efficiently by grouping ports into manageable categories rather than tracking each port individually, thus reducing overall network state while maintaining classification precision.
Solution Approach 2:
The patent adds a new dimension to traffic classification by introducing logical port group identifiers that operate alongside traditional 802.1PQ tags and DSCP fields. This creates a multi-dimensional classification space where traffic can be categorized by port group, protocol, and priority independently, allowing for more efficient state management in physical network devices while supporting the exponential growth of logical ports in virtualized environments.
2Adaptability or versatility
If logical forwarding elements span hundreds or thousands of hypervisors, then network virtualization scalability is achieved, but the amount of network state required increases at an unsustainable rate
Solution Approach 1:
The patent merges the classification functionality across multiple hypervisors and logical forwarding elements by introducing a centralized logical port group identifier system. Instead of maintaining separate classification states at each hypervisor, the system consolidates classification logic by grouping ports across the entire virtualized network, allowing state to be managed centrally and reused across hundreds or thousands of hypervisors without proportional state growth.
Solution Approach 2:
The logical port group identifiers serve multiple functions simultaneously: they classify traffic for QoS policies, enforce port isolation rules, and provide security group membership across the entire virtualized network. This multi-functionality eliminates the need for separate classification mechanisms at each logical forwarding element, reducing overall network state while supporting extensive virtualization scalability.
3Reliability
If port features are implemented in physical network devices for all logical networks, then port isolation and security are achieved, but scalability becomes infeasible due to limited bits in classification fields
Solution Approach 1:
The patent introduces logical port group identifiers as an intermediary layer between physical network devices and virtualized logical networks. This intermediary enables physical switches to enforce port security and isolation policies without needing to understand or track individual virtual machine ports. The logical port group acts as a mediator that aggregates multiple logical ports into a single classification unit, allowing physical devices to scale efficiently while maintaining security policies.
Solution Approach 2:
The patent changes the classification parameters from individual logical port identifiers (which would require tracking thousands of ports) to logical port group identifiers (which require tracking only groups). This parameter transformation reduces the state space in physical network devices from O(n) individual ports to O(g) groups, where g << n, enabling scalability while maintaining port security and isolation features.
Data Source
AI summary
The network control system of some embodiments implements logical port classifications to implement different features of logical networks onto a physical network. The network control system of some embodiments modifies flow entries at forwarding elements of the physical network to implement the logical network. The network control system classifies logical source and destination ports into disjoint equivalence classes for logical network flows in a virtualized network, and encodes this information in the tunneled traffic carrying the logical flow. The network control system of some such embodiments provides logical port classifications to minimize the necessary flow entries at each forwarding element of the physical network.


