Network Address Grouping for Virtual Interface Service Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined data centers with virtualized networking, efficiently implementing many firewall rules across a logical network is challenging due to the need for optimized management of service rules, particularly in distributed environments where existing methods do not adequately reduce the number of flow entries or minimize churn caused by rule changes.

Innovation Solution

A method that groups network addresses into non-overlapping sets and generates flow entries based on these groups, reducing the number of flow entries required for service rules and minimizing changes by assigning priority values in a manner that minimizes re-assignment when rules are added or modified, using techniques like conjunctive matching and address set normalization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional methods are used to implement firewall rules in distributed environments, then service rules can be applied to multiple virtual interfaces, but the number of flow entries increases significantly and management complexity increases

Engineering Contradiction:
Improveservice rules applicationVSAvoidflow entries management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines service rules from multiple virtual interfaces by identifying common network addresses and merging their flow entries. Instead of maintaining separate flow entries for each virtual interface, the system merges rules that apply to multiple interfaces, reducing the total number of flow entries while maintaining the ability to apply service rules across distributed environments.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal flow entries that can serve multiple virtual interfaces simultaneously. By identifying network addresses that are common across multiple virtual interfaces and creating a single flow entry that applies to all of them, the system achieves multi-functionality where one flow entry performs the service rule enforcement for multiple interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If firewall rules are implemented across multiple virtual interfaces, then distributed firewall services are achieved, but the number of flow entries required increases

Engineering Contradiction:
Improvedistributed firewall servicesVSAvoidnumber of flow entries
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges flow entries for common network addresses across multiple virtual interfaces. When the same network address appears in service rules for multiple virtual interfaces, the system creates a single merged flow entry that handles all instances, thereby reducing the total quantity of flow entries while maintaining distributed firewall service reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the flow entry management by separating unique network addresses from common network addresses. Unique addresses get individual flow entries, while common addresses across multiple virtual interfaces are segmented out and handled by shared flow entries, reducing the overall number of flow entries required.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If service rules are added or modified in distributed environments, then firewall functionality is updated, but churn increases causing more re-assignments

Engineering Contradiction:
Improverule changesVSAvoidre-assignment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent merges service rules that apply to multiple virtual interfaces into unified flow entries. When rules are added or modified, the system updates the merged flow entry once rather than updating separate flow entries for each virtual interface, significantly reducing churn and re-assignment time while maintaining the ability to adapt firewall functionality.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If traditional flow entry management is used, then service rules can be implemented, but network resource usage increases and transaction time increases

Engineering Contradiction:
Improveservice rule implementationVSAvoidtransaction time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges flow entries for common network addresses across multiple virtual interfaces, reducing the total number of flow entries that need to be processed. This merging reduces network resource usage and decreases transaction time for service rule implementation while maintaining reliable service rule enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10275273B2Efficient computation of address groupings across multiple network interfaces
Publication Date: 2019.04.30 VMWARE INC
  • US10275273B2 patent drawing
  • US10275273B2 patent drawing
  • US10275273B2 patent drawing

AI summary

Certain embodiments described herein are generally directed to normalizing service rules across multiple virtual interfaces (VIFs). For example, certain embodiments described herein relate to a method for managing service rules. The method may include receiving a plurality of service rules for a set of VIFs, wherein each service rule corresponds to at least one network address and grouping the network addresses into non-overlapping groups of network addresses, wherein the grouping is performed over the service rules corresponding to the set of VIFs. In certain embodiments, flow entries may be generated based on the grouping of the network addresses.