Logical Port Classifications for Virtual Network Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network virtualization technologies face challenges in efficiently implementing port features such as port isolation and security across large networks due to the limited number of bits in 802.1PQ tags and DSCP fields, which are inadequate for classifying logical flows in virtualized environments, leading to unsustainable network state requirements as the number of logical networks grows.

Innovation Solution

A network control system that uses port group identifiers to classify logical source and destination ports into disjoint groups, encoding these identifiers in tunneled traffic to minimize the number of forwarding rules needed at each physical network element, allowing for scalable implementation of logical port classifications and features like port isolation and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If 802.1PQ tags and DSCP fields are used for traffic classification, then priority encoding is achieved, but the number of distinct values is limited to 7 or more with unsustainable network state growth

Engineering Contradiction:
Improveclassification precisionVSAvoidnetwork state
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the classification task by introducing a two-level hierarchy: logical port group identifiers (coarse-grained classification) and individual logical port identifiers (fine-grained classification). This segmentation allows the system to manage classification state efficiently by grouping ports into manageable categories rather than tracking each port individually, thus reducing overall network state while maintaining classification precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to traffic classification by introducing logical port group identifiers that operate alongside traditional 802.1PQ tags and DSCP fields. This creates a multi-dimensional classification space where traffic can be categorized by port group, protocol, and priority independently, allowing for more efficient state management in physical network devices while supporting the exponential growth of logical ports in virtualized environments.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If logical forwarding elements span hundreds or thousands of hypervisors, then network virtualization scalability is achieved, but the amount of network state required increases at an unsustainable rate

Engineering Contradiction:
Improvevirtualization scalabilityVSAvoidnetwork state
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the classification functionality across multiple hypervisors and logical forwarding elements by introducing a centralized logical port group identifier system. Instead of maintaining separate classification states at each hypervisor, the system consolidates classification logic by grouping ports across the entire virtualized network, allowing state to be managed centrally and reused across hundreds or thousands of hypervisors without proportional state growth.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The logical port group identifiers serve multiple functions simultaneously: they classify traffic for QoS policies, enforce port isolation rules, and provide security group membership across the entire virtualized network. This multi-functionality eliminates the need for separate classification mechanisms at each logical forwarding element, reducing overall network state while supporting extensive virtualization scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If port features are implemented in physical network devices for all logical networks, then port isolation and security are achieved, but scalability becomes infeasible due to limited bits in classification fields

Engineering Contradiction:
Improveport securityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces logical port group identifiers as an intermediary layer between physical network devices and virtualized logical networks. This intermediary enables physical switches to enforce port security and isolation policies without needing to understand or track individual virtual machine ports. The logical port group acts as a mediator that aggregates multiple logical ports into a single classification unit, allowing physical devices to scale efficiently while maintaining security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the classification parameters from individual logical port identifiers (which would require tracking thousands of ports) to logical port group identifiers (which require tracking only groups). This parameter transformation reduces the state space in physical network devices from O(n) individual ports to O(g) groups, where g << n, enabling scalability while maintaining port security and isolation features.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10834239B2Method and system for implementing logical port classifications
Publication Date: 2020.11.10 VMWARE INC
  • US10834239B2 patent drawing
  • US10834239B2 patent drawing
  • US10834239B2 patent drawing

AI summary

The network control system of some embodiments implements logical port classifications to implement different features of logical networks onto a physical network. The network control system of some embodiments modifies flow entries at forwarding elements of the physical network to implement the logical network. The network control system classifies logical source and destination ports into disjoint equivalence classes for logical network flows in a virtualized network, and encodes this information in the tunneled traffic carrying the logical flow. The network control system of some such embodiments provides logical port classifications to minimize the necessary flow entries at each forwarding element of the physical network.