Network Group Management for Virtual Machine Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of configuring and maintaining desktop virtualization environments, particularly in multi-tenant networks, leads to issues such as virtual machine misconfiguration and network congestion due to inadequate isolation and traffic management.

Innovation Solution

Implementing a system that creates and manages network groups, allowing unrestricted routing within groups and restricted routing between them, using a network management device to define VLANs, assign machines, and configure routing to ensure proper isolation and traffic control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If desktop virtualization is implemented to reduce hardware costs, then resource utilization improves, but network configuration complexity increases

Engineering Contradiction:
Improveresource utilizationVSAvoidnetwork configuration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple isolated network groups (VLANs), where each group contains specific virtual machines and resources. This segmentation approach allows independent configuration and management of each network group, reducing the overall complexity of managing large-scale virtualized networks while improving resource utilization through efficient isolation and allocation.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If network size increases to support more virtual machines, then computational functionality improves, but configuration and maintenance time increases

Engineering Contradiction:
Improvecomputational functionalityVSAvoidconfiguration and maintenance time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary network group configurations with pre-defined isolation policies and routing rules. Network groups are established in advance with specific security policies, IP address allocations, and connectivity rules configured beforehand. This preliminary setup significantly reduces the time required for configuration and maintenance when adding new virtual machines, as the foundational network structure is already in place.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If network isolation is increased to prevent misconfiguration, then system reliability improves, but network management complexity increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces network groups as intermediary layers between individual virtual machines and the core network infrastructure. These network groups act as mediators that enforce isolation policies, control traffic flow, and manage security rules. This intermediary structure improves system reliability by preventing misconfiguration and unauthorized access, while simplifying network management through centralized control of the intermediary layers rather than individual machine management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10868771B2Methods and systems for creating and managing network groups
Publication Date: 2020.12.15 CITRIX SYSTEMS INC
  • US10868771B2 patent drawing
  • US10868771B2 patent drawing
  • US10868771B2 patent drawing

AI summary

The embodiments are directed to methods and devices for creating one or more network groups. The methods and devices can define a network group with one or more properties. The methods and devices can identify a plurality of isolated networks, and can assign the plurality of isolated networks to the defined network group. The methods and devices can assign machines to at least one of the plurality of isolated networks, wherein the network group enables unrestricted routing.