Network Control Apparatus for Port Isolation in SDN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems face challenges in scalability, mobility, and multi-tenancy, particularly in large networks like datacenters, where existing solutions often compromise one aspect to address another, and no existing products have satisfactorily met all these requirements within the Software-Defined Networking (SDN) paradigm.
Innovation Solution
A system that allows multiple logical datapath sets to be specified for different users through shared network infrastructure switching elements, utilizing a network information base (NIB) data structure to store and manage network state, provide different views of the network to users, and employ a network operating system (NOS) to configure and propagate changes to switching elements, ensuring user isolation and efficient network control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple users share the same switching elements, then resource utilization and scalability improve, but user isolation and security control become more difficult
Solution Approach 1:
The patent segments the control plane by introducing a network controller that separates control logic from forwarding elements. Each user's logical datapath set is independently managed through virtualization, allowing multiple users to share physical switching elements while maintaining isolated control planes. This segmentation enables resource sharing without compromising user isolation.
Solution Approach 2:
The network controller acts as an intermediary between users and switching elements. It receives user-specified logical datapath sets, translates them into appropriate forwarding rules, and propagates configurations to the shared switching elements. This intermediary layer abstracts the complexity of user isolation control from the switching elements themselves.
2Ease of operation
If network controller maintains comprehensive view of network state, then management decision making improves, but information security and user privacy deteriorate
Solution Approach 1:
The patent applies local quality by providing different views of the network state to different users. The network controller maintains a comprehensive global view for management decisions, while simultaneously presenting each user with only their own logical datapath set information. This selective information presentation preserves user confidentiality while enabling effective network management.
3Adaptability or versatility
If logical datapath sets are virtualized for multiple users, then multi-tenancy support improves, but system complexity and configuration management worsen
Solution Approach 1:
The network controller provides universal functionality by handling configuration management for all users through a single interface. It universally translates diverse user requirements into standardized forwarding rules that can be applied across different switching elements. This multi-functional approach simplifies configuration management despite supporting multiple tenants with different requirements.
Data Source
AI summary
Some embodiments provide a method for managing a logical switching element that includes several logical ports. The logical switching element receives and sends data packets through the logical ports. The logical switching element is implemented in a set of managed switching elements that forward data packets in a network. The method provides a set of tables for specifying forwarding behaviors of the logical switching element. The method performs a set of database join operations on the tables to specify in the tables that the logical forwarding element drops a data packet received through a first logical port when the data packet is headed to a second logical port different than the first logical port.


