Network Interface Device Multiple MAC Identifier Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing environments, traditional network interface devices typically have only one MAC identifier, leading to performance and security issues when operating in promiscuous mode to handle multiple guest environments, as it requires examining all data packets and compromises network security.

Innovation Solution

A system that allows network interface devices to support multiple MAC identifiers, enabling logical separation of data packets based on MAC identifiers by reserving and activating additional identifiers, which can be universally administered or locally administered, without requiring the device to be in promiscuous mode.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a network interface device operates in promiscuous mode to handle multiple guest environments, then it can receive and examine all data packets for multiple virtual machines, but network security is compromised and performance deteriorates due to examining all data packets

Engineering Contradiction:
Improveability to handle multiple guest environmentsVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the network traffic handling by assigning different MAC identifiers to different virtual network interface devices. Each virtual NIC is associated with a specific MAC address, allowing the physical network interface device to filter packets based on destination MAC addresses without needing to examine all packets in promiscuous mode. This segmentation enables multiple guest environments to be handled independently while maintaining security and performance.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a network interface device operates in promiscuous mode to handle multiple guest environments, then it can receive and examine all data packets for multiple virtual machines, but performance deteriorates due to examining all data packets

Engineering Contradiction:
Improveability to handle multiple guest environmentsVSAvoiddata packet processing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the network interface device with multiple MAC identifiers before runtime. The system reserves and activates additional MAC identifiers in advance, allowing the device to perform hardware-level filtering on incoming packets based on destination MAC addresses. This eliminates the need for software-level examination of all packets, significantly improving processing efficiency while maintaining the ability to handle multiple guest environments.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If a network interface device uses a single MAC identifier, then the device structure remains simple, but it cannot efficiently support multiple virtual network interface devices in virtualized environments

Engineering Contradiction:
ImproveMAC identifier managementVSAvoidsupport for multiple virtual network interface devices
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by enabling a single physical network interface device to support multiple MAC identifiers and correspondingly multiple virtual network interface devices. The system allows the network interface device to be configured with additional MAC identifiers that can be reserved and activated dynamically, making the device universally applicable to multiple virtual machines without requiring separate physical network cards for each guest environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8184631B2Method for specifying a MAC identifier for a network-interface-device
Publication Date: 2012.05.22 ORACLE AMERICAN INC
  • US8184631B2 patent drawing
  • US8184631B2 patent drawing
  • US8184631B2 patent drawing

AI summary

One embodiment of the present invention provides a system that specifies a MAC identifier for a network-interface-device in a computing device. In this system, the network-interface-device is configured to connect to a network though a port. During operation, the network-interface-device receives data packets through this port, and accepts a data packet if the data packet contains a destination that matches the MAC identifier for the network-interface-device, which can be a universally-administered MAC identifier. The system is also configured to determine whether the network-interface-device supports one or more additional MAC identifiers. If so, the system adds and activates an additional MAC identifier. By activating the newly-added MAC identifier in the computing device, the system allows the network-interface-device to logically separate data packets based on MAC identifiers.