Network Controller Architecture for Multi-Tenant Forwarding Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network management systems face challenges in achieving scalability, mobility, and multi-tenancy due to the complexity of managing large and sophisticated networks, particularly in environments with shared network switching elements across multiple users, where traditional methods often compromise one goal at the expense of others.
Innovation Solution
A network control system that allows multiple logical datapath sets to be specified for different users through shared forwarding elements, using a controller-based architecture that virtualizes control and prevents users from viewing or controlling each other's forwarding logic, employing a hierarchy of controllers to manage and configure switching elements efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional network management methods are used to manage shared network switching elements, then network control and management capability is maintained, but scalability and multi-tenancy are compromised due to the complexity of managing large networks with multiple users
Solution Approach 1:
The patent segments the network control function by introducing a controller that separates the control plane from the data plane. The controller manages multiple logical datapath sets independently, allowing different users to have isolated network views and control policies on shared switching elements. This segmentation enables multi-tenancy by dividing the unified network management into user-specific logical networks.
Solution Approach 2:
The patent adds a logical abstraction dimension to the physical network infrastructure. By introducing logical datapath sets that map to physical switching elements, the system creates a multi-layered architecture where users interact with logical networks rather than physical hardware directly. This dimensional transformation simplifies management complexity while enabling scalable multi-tenancy.
2Loss of information
If network control is centralized to improve management decisions, then network state visibility is improved, but scalability is hampered due to the single point of control
Solution Approach 1:
The controller is designed with universal functionality to manage multiple logical datapath sets across multiple switching elements simultaneously. It maintains a comprehensive network state view while providing standardized control interfaces that can scale to accommodate growing network sizes and additional users without requiring proportional increases in control complexity.
Solution Approach 2:
The system changes the parameter of control distribution by introducing logical datapath sets that can be independently configured and managed. The controller dynamically adjusts control parameters based on user requirements and network state, allowing scalable management by transforming control from a rigid centralized model to a flexible parameter-driven model.
3Ease of operation
If users are allowed to control their own forwarding logic, then ease of operation is improved, but security and isolation between users deteriorate as users can view and control each other's forwarding logic
Solution Approach 1:
The controller acts as an intermediary between users and the physical switching elements. Users submit control requests to the controller, which then translates and enforces these requests through controlled interfaces to the switching elements. This intermediary layer provides users with ease of operation through standardized APIs while maintaining security and isolation by preventing direct access to other users' forwarding logic.
Solution Approach 2:
Each user is assigned a specific logical datapath set with localized control authority. The controller enables users to control only their own forwarding logic within their designated logical network boundaries, while maintaining isolation from other users' control domains. This local quality approach grants user autonomy without compromising overall system security.
Data Source
AI summary
A non-transitory machine readable medium storing a program that configures managed forwarding elements to establish tunnels between the managed forwarding elements is described. From a particular managed forwarding element, the program receives information regarding coupling of a network element to the first managed forwarding element. Upon receiving the information, the program generates a set of universal flow entries for configuring another managed forwarding element to establish a tunnel to the particular managed forwarding element.


