Network Control Apparatus for Virtual Network Scalability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing technologies for establishing virtual networks in large-scale communication networks face limitations due to the restricted number of VLAN-ID and VLAN domain ID, which restricts the number of virtual networks that can be provided.
Innovation Solution
A control apparatus and communication system that manage network configuration information to allow terminals to belong to a second virtual network identified by a second identifier, enabling communication control based on this information, thereby bypassing the limitations of VLAN-ID and VLAN domain ID.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VLAN-ID is assigned for each IP address of a server in a large-scale network, then virtual network isolation is achieved, but the number of available VLAN-IDs becomes insufficient due to the 4,096 limit
Solution Approach 1:
The patent segments the virtual network identification function into two independent parts: VLAN-ID (for network isolation) and VLAN domain ID (for network selection). This segmentation allows the VLAN-ID to maintain its original isolation function while the VLAN domain ID provides additional virtual network differentiation, effectively multiplying the total number of available virtual networks from 4,096 to potentially millions of combinations.
Solution Approach 2:
The patent adds a new dimension (VLAN domain ID) to the existing VLAN-ID identification system. Instead of relying solely on the single VLAN-ID dimension with its 4,096 limit, the system now operates in a two-dimensional space where virtual networks are identified by the combination of VLAN domain ID and VLAN-ID, dramatically expanding the addressable space.
2Quantity of substance
If a VLAN domain ID field is added to the frame to identify additional virtual networks, then the number of virtual networks increases, but the frame structure becomes more complex
Solution Approach 1:
The patent merges the VLAN domain ID and VLAN-ID into a single VLAN tag structure within the Ethernet frame. Rather than adding separate fields that would increase frame complexity, the implementation combines both identification elements into the existing VLAN tag mechanism, allowing switches to process both identifiers through a unified structure.
Solution Approach 2:
The VLAN tag structure is designed to serve multiple functions simultaneously: it provides both VLAN domain identification and VLAN-ID identification, enables network isolation, and supports switching operations. This multi-functionality reduces the need for additional specialized fields that would complicate the frame structure.
3Reliability
If VLAN-ID is used for network virtualization, then network isolation is provided, but the system cannot support large-scale networks with many more than 4,096 virtual networks
Solution Approach 1:
The patent implements a nested identification structure where VLAN domain ID and VLAN-ID are hierarchically organized. The VLAN domain ID provides the outer layer of network selection, while the VLAN-ID provides the inner layer of network isolation. This nesting allows the system to maintain the proven isolation mechanism of VLAN-ID while adding the scalability of VLAN domain ID.
Solution Approach 2:
The system dynamically allocates and manages VLAN domain IDs and VLAN-IDs based on network requirements. Rather than using a static, fixed assignment, the control apparatus can dynamically create, modify, and remove virtual network identifiers, allowing the network to adapt and scale flexibly as needs change.
Data Source
AI summary
A control apparatus for controlling packet transfer between terminals belonging to a first virtual network identified by a first identifier includes a network configuration information management unit for holding configuration information on a second virtual network identified by a second identifier so that the terminals belong to the second virtual network; and a path control unit for controlling communication between the terminals based on the configuration information on the second virtual network.


