Network Controller Virtualizing Switching Elements for Multi-User Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management systems face challenges in scalability, mobility, and multi-tenancy, particularly in large networks like datacenters, where existing solutions struggle to provide efficient network control and isolation while sharing network infrastructure among users.

Innovation Solution

A system that utilizes a network information base (NIB) to virtualize control of shared network switching elements, allowing multiple users to have separate logical datapath sets without viewing or controlling each other's switching logic, using a network operating system (NOS) to manage and propagate changes to the NIB, and employing Type I and Type II network virtualization approaches for different user configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network switching elements are shared across multiple users to improve resource utilization, then productivity is improved, but user isolation and security are compromised

Engineering Contradiction:
Improveresource utilizationVSAvoiduser isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the control plane by introducing a network controller that separates control logic from forwarding elements. Each user's network policies and configurations are managed independently through virtual network instances, allowing multiple users to share physical infrastructure while maintaining logical isolation. The controller divides network management into discrete controllable units that can be allocated to different users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network controller acts as an intermediary between users and shared network infrastructure. It mediates access to switching elements by translating user-specific policies into device-specific configurations. The controller maintains separate policy databases for different users and enforces isolation by preventing one user's policies from affecting another user's network traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If low-level configuration of individual network components is used to maintain precise control, then manufacturing precision is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improvenetwork control precisionVSAvoidconfiguration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The network controller serves as an intermediary that abstracts complex device configurations from users. It provides high-level policy interfaces where users can define network behavior without manually configuring individual switching elements. The controller translates these abstract policies into detailed device-specific configurations, maintaining precision while reducing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network controller provides universal management capabilities across diverse network devices. Instead of requiring users to learn device-specific configuration protocols for each switching element, the controller offers a unified interface that works across multiple device types. This multi-functional approach maintains precise control while simplifying operations through consistent management procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If extensive network knowledge is required to perform complicated network tasks, then measurement precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork state awarenessVSAvoidnetwork management ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The network controller acts as an intermediary that maintains comprehensive network state information and presents simplified views to users. It collects detailed network state data from all switching elements and processes this information centrally. Users interact with the controller through high-level interfaces that automatically translate their intent into precise network configurations, eliminating the need for users to possess extensive network knowledge.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the network controller continuously monitors network state and automatically adjusts configurations based on observed conditions. This closed-loop control provides users with accurate network state awareness without requiring them to manually gather or interpret complex network data. The controller's feedback mechanisms maintain precision by continuously adapting to actual network conditions while keeping operations simple for users.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240259265A1Network control apparatus and method for populating logical datapath sets
Publication Date: 2024.08.01 VMWARE INC
  • US20240259265A1 patent drawing
  • US20240259265A1 patent drawing
  • US20240259265A1 patent drawing

AI summary

For a network control system that receives, from a user, logical datapath sets that logically express desired forwarding behaviors that are to be implemented by a set of managed switching elements, a controller for managing several managed switching elements that forward data in a network that includes the managed switching elements is described. The controller includes a set of modules for detecting a change in one or more managed switching elements and for updating logical datapath set based on the detected change. The logical datapath set is for subsequent translation into a set of physical forwarding behaviors of the managed switching elements.