Network Controller Architecture for Multi-Tenant Forwarding Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management systems face challenges in achieving scalability, mobility, and multi-tenancy due to the complexity of managing large and sophisticated networks, particularly in environments with shared network switching elements across multiple users, where traditional methods often compromise one goal at the expense of others.

Innovation Solution

A network control system that allows multiple logical datapath sets to be specified for different users through shared forwarding elements, using a controller-based architecture that virtualizes control and prevents users from viewing or controlling each other's forwarding logic, employing a hierarchy of controllers to manage and configure switching elements efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional network management methods are used to manage shared network switching elements, then network control and management capability is maintained, but scalability and multi-tenancy are compromised due to the complexity of managing large networks with multiple users

Engineering Contradiction:
Improvemulti-tenancyVSAvoidnetwork management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network control function by introducing a controller that separates the control plane from the data plane. The controller manages multiple logical datapath sets independently, allowing different users to have isolated network views and control policies on shared switching elements. This segmentation enables multi-tenancy by dividing the unified network management into user-specific logical networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a logical abstraction dimension to the physical network infrastructure. By introducing logical datapath sets that map to physical switching elements, the system creates a multi-layered architecture where users interact with logical networks rather than physical hardware directly. This dimensional transformation simplifies management complexity while enabling scalable multi-tenancy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If network control is centralized to improve management decisions, then network state visibility is improved, but scalability is hampered due to the single point of control

Engineering Contradiction:
Improvenetwork state visibilityVSAvoidscalability
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The controller is designed with universal functionality to manage multiple logical datapath sets across multiple switching elements simultaneously. It maintains a comprehensive network state view while providing standardized control interfaces that can scale to accommodate growing network sizes and additional users without requiring proportional increases in control complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of control distribution by introducing logical datapath sets that can be independently configured and managed. The controller dynamically adjusts control parameters based on user requirements and network state, allowing scalable management by transforming control from a rigid centralized model to a flexible parameter-driven model.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If users are allowed to control their own forwarding logic, then ease of operation is improved, but security and isolation between users deteriorate as users can view and control each other's forwarding logic

Engineering Contradiction:
Improveuser control capabilityVSAvoiduser isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The controller acts as an intermediary between users and the physical switching elements. Users submit control requests to the controller, which then translates and enforces these requests through controlled interfaces to the switching elements. This intermediary layer provides users with ease of operation through standardized APIs while maintaining security and isolation by preventing direct access to other users' forwarding logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Each user is assigned a specific logical datapath set with localized control authority. The controller enables users to control only their own forwarding logic within their designated logical network boundaries, while maintaining isolation from other users' control domains. This local quality approach grants user autonomy without compromising overall system security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12111787B2Chassis controller
Publication Date: 2024.10.08 VMWARE INC
  • US12111787B2 patent drawing
  • US12111787B2 patent drawing
  • US12111787B2 patent drawing

AI summary

A non-transitory machine readable medium storing a program that configures managed forwarding elements to establish tunnels between the managed forwarding elements is described. From a particular managed forwarding element, the program receives information regarding coupling of a network element to the first managed forwarding element. Upon receiving the information, the program generates a set of universal flow entries for configuring another managed forwarding element to establish a tunnel to the particular managed forwarding element.