Network Controller for Multi-Tenant Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems face challenges in achieving scalability, mobility, and multi-tenancy due to the complexity of managing large networks with shared switching elements, where users' access control and network topology knowledge are required, leading to difficulties in isolating users and managing forwarding logic.
Innovation Solution
A network control system that allows multiple logical datapaths to be specified for different users through shared forwarding elements, using a network controller to manage and virtualize control, preventing users from viewing or controlling each other's forwarding logic, by employing a control module and virtualization module to transform logical control plane data into physical control plane data and propagate it to managed switching elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network management is performed through low-level configuration of individual components with shared switching elements, then users can access network resources, but user isolation and control complexity deteriorate as network size increases
Solution Approach 1:
The patent introduces a network controller as an intermediary device that sits between the management plane and the switching elements. This controller abstracts the complexity of managing shared switching elements by providing a centralized control mechanism that handles user isolation, access control lists, and forwarding logic without requiring direct low-level configuration of each component. The controller maintains a global view of the network state and translates high-level management decisions into specific switching element configurations.
2Productivity
If multiple users share the same switching elements to improve resource utilization, then network efficiency improves, but user isolation and security deteriorate
Solution Approach 1:
The patent segments the control plane into multiple virtual controllers, each responsible for a specific user or tenant. This segmentation allows each user to have their own isolated control instance that manages their forwarding logic and access control lists independently. The virtual controllers communicate with the physical switching elements through a standardized interface, enabling multiple users to share the same physical infrastructure while maintaining logical isolation. Each virtual controller maintains its own view of the network state for its assigned user, preventing cross-user interference.
3Measurement precision
If network configurations depend on underlying network topology and current state information, then accurate network control is achieved, but management difficulty and knowledge requirements increase
Solution Approach 1:
The network controller implements self-service mechanisms by automatically discovering and maintaining the global network state through interactions with switching elements and management applications. The controller proactively collects topology information, monitors network conditions, and updates its internal state model without requiring manual intervention. This automated state maintenance reduces the knowledge burden on network operators, as the controller handles the complexity of tracking network changes and translating them into appropriate configuration decisions.
Data Source
AI summary
A network control system for generating physical control plane data for managing first and second managed forwarding elements that implement forwarding operations associated with a first logical datapath set is described. The system includes (1) a first controller for converting logical control plane data for the first logical datapath set to universal physical control plane (UPCP) data, (2) a second controller for converting UPCP data to customized physical control plane (CPCP) data for the first managed forwarding element but not the second managed forwarding element, and (3) a third controller for receiving UPCP data generated by the first controller instance, identifying the second controller as the controller instance responsible for generating the CPCP data for the first managed forward element, and supplying the received UPCP data to the second controller. Each controller includes a network information base (NIB) storage for exchanging data with another controller instance.


