Network Control System for Multi-tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management systems face challenges in achieving scalability, mobility, and multi-tenancy due to the complexity of managing large networks with shared switching elements, where user isolation and network mobility are often compromised.

Innovation Solution

A network control system that allows multiple logical datapaths to be specified for different users through shared forwarding elements, using a controller-based architecture that virtualizes control and prevents users from viewing or controlling each other's forwarding logic, employing a network information base for state management and different controller types to implement and manage flow entries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple users share the same switching elements to improve resource utilization and scalability, then network efficiency and scalability are improved, but user isolation and security are compromised

Engineering Contradiction:
Improvenetwork scalabilityVSAvoiduser isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the control plane from the data plane by introducing a centralized controller that manages multiple switching elements. The controller divides network management into logical domains, allowing each user to have isolated control over their specific forwarding rules and policies while sharing the physical switching infrastructure. This segmentation enables multiple users to share switching elements without compromising isolation, as each user's control is confined to their designated logical domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The centralized controller acts as an intermediary between multiple users and the shared switching elements. It mediates access to the switching elements by translating user-specific forwarding requirements into standardized control plane instructions. The controller ensures that users cannot directly access or interfere with each other's forwarding logic, thereby maintaining isolation while enabling efficient resource sharing through the intermediary management layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If centralized controller manages all switching elements to improve network control and scalability, then network manageability is improved, but controller complexity and single point of failure risk increase

Engineering Contradiction:
Improvenetwork manageabilityVSAvoidcontroller complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The controller is segmented into multiple functional modules, each responsible for specific control plane functions such as flow rule management, policy enforcement, and state tracking. This modular architecture reduces overall controller complexity by allowing independent development, deployment, and failure isolation of individual modules. The segmented controller can manage large numbers of switching elements efficiently while maintaining manageable complexity through functional decomposition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The controller is designed with universal interfaces and protocols that allow it to manage diverse switching elements through standardized methods. By implementing multi-functional capabilities to handle various user requirements, traffic types, and switching element types through a unified control plane, the system improves ease of operation without proportionally increasing complexity. The universal control plane can adapt to different scenarios without requiring separate management systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If detailed network state information is maintained for all users to improve forwarding decisions, then forwarding precision is improved, but information security and user privacy are compromised

Engineering Contradiction:
Improveforwarding precisionVSAvoidinformation security
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The controller implements local quality by maintaining network state information in a distributed manner across different logical domains rather than centralizing all user information in one place. Each user's forwarding rules and associated state information are stored and processed within their specific logical domain, allowing precise forwarding decisions for each user while preventing other users from accessing their information. This localized information management maintains both forwarding precision and information security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Network state information is segmented into user-specific portions that are isolated within their respective logical domains. The controller maintains separate state tables or data structures for each user, allowing precise forwarding decisions based on user-specific information without exposing other users' data. This segmentation ensures that forwarding precision is maintained through accurate state tracking while information security is preserved through logical isolation of sensitive data.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9137107B2Physical controllers for converting universal flows
Publication Date: 2015.09.15 VMWARE INC
  • US9137107B2 patent drawing
  • US9137107B2 patent drawing
  • US9137107B2 patent drawing

AI summary

Some embodiments provide a network control system for generating physical control plane data for managing first and second managed forwarding elements that implement forwarding operations associated with a first logical datapath set. The system includes a first controller instance for converting logical control plane data for the first logical datapath set to universal physical control plane (UPCP) data. The system includes a second controller instance for converting UPCP data to customized physical control plane (CPCP) data for the first managed forwarding element but not the second managed forwarding element. Each controller instance includes a network information base (NIB) storage for storing data and exchanging data with the other controller instance.