Network Abstraction Isolation Layer for Server Identity Masquerading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network systems face challenges in replicating servers on-demand due to embedded unique network identifiers like MAC and IP addresses, which cause identification conflicts, limiting the ability to quickly scale computing capacity or isolate machines within a network.

Innovation Solution

A network abstraction and isolation layer (NAIL) that translates and masks machine identities by modifying IP and MAC addresses in packet headers and payloads, allowing computers to communicate with different identities, thereby preventing conflicts and enabling flexible network identity management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If server replication is performed to increase computing capacity, then productivity is improved, but identification conflicts occur due to replicated unique network identifiers

Engineering Contradiction:
Improvecomputing capacityVSAvoidnetwork communication
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a Network Abstraction and Isolation Layer (NAIL) as an intermediary between the physical network interface and the operating system. This layer acts as a mediator that translates and abstracts unique network identifiers (MAC addresses, IP addresses) so that replicated servers can communicate on the network without direct identification conflicts. The NAIL intercepts network traffic and performs address translation, allowing multiple servers with identical identifiers to coexist on the same network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If SysPrep tool is used to create duplicate server systems, then adaptability is improved, but time loss occurs due to application loading and configuration requirements

Engineering Contradiction:
Improveserver replication capabilityVSAvoidapplication configuration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring the Network Abstraction and Isolation Layer with translation rules before the replicated server needs to operate. The NAIL is set up in advance to handle address translation, allowing servers to be replicated and activated immediately without requiring post-replication application configuration. This preliminary setup of the abstraction layer eliminates the time-consuming application loading and configuration step that traditionally follows server replication.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network identifiers are embedded in application programs, then reliability is improved, but device complexity increases due to the need for identifier modification during replication

Engineering Contradiction:
Improvenetwork communicationVSAvoidreplication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the network identifier translation function from the application programs and the replication process itself, placing it in the dedicated Network Abstraction and Isolation Layer. By taking out the identifier management responsibility from applications and the replication toolchain, the system maintains embedded identifiers in applications for reliability while simplifying the replication process. The NAIL handles all identifier translation centrally, eliminating the need to modify embedded identifiers during replication.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7769004B2Network abstraction and isolation layer for masquerading machine identity of a computer
Publication Date: 2010.08.03 QUEST SOFTWARE INC
  • US7769004B2 patent drawing
  • US7769004B2 patent drawing
  • US7769004B2 patent drawing

AI summary

A network abstraction and isolation layer (NAIL) for masquerading the machine identity of a computer in a network to enable the computer to communicate in the network with a different machine identity including an isolated network interface for communicating with the computer, an abstraction network interface for communicating with a network device coupled to the network, and control logic. The control logic is coupled to the isolated and abstraction network interfaces and performs machine identity translation to masquerade machine identity of the computer relative to the network. Machine identity masquerading includes selectively translating any one or more of an IP address, a MAC address, a machine name, a system identifier, and a DNS Name in the header or payload of communication packets.