Physical Network Interface Packet Filtering for Nested Virtual Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional configuration operations for physical network interfaces struggle to identify and manage secondary virtual nodes nested within primary virtual nodes and packets within overlay network headers, leading to difficulties in classifying data packets and providing adequate quality of service.

Innovation Solution

A method that involves obtaining dispatch statistics for MAC addresses associated with virtual nodes, identifying filter configurations based on these statistics, and applying them to the physical network interface to classify packets and allocate resources effectively, ensuring each virtual node receives a desired quality of service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional configuration operations are used for physical network interfaces, then the system is simple to operate, but it cannot identify nested virtual nodes and packets within overlay network headers

Engineering Contradiction:
Improvecapability to identify nested virtual nodes and overlay network packetsVSAvoidcomplexity of configuration operations
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies nesting by enabling the physical network interface to filter packets based on multiple hierarchical levels of virtualization. The filter configuration identifies not only primary virtual nodes but also secondary virtual nodes nested within them, and packets nested within overlay network headers. This multi-level nesting capability allows the system to handle complex virtualized network environments while maintaining a unified filtering interface.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces an additional dimension of packet inspection by examining not only the standard packet headers but also overlay network headers that encapsulate packets for nested virtual nodes. This dimensional expansion of the filtering capability allows the system to operate effectively in multi-layer virtualized networks without requiring separate configuration mechanisms for each layer.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If traditional filtering configurations are applied, then the configuration process is straightforward, but it is incapable of classifying data packets for nested virtual nodes and packets within overlay headers

Engineering Contradiction:
Improveaccuracy of packet classificationVSAvoidease of configuration
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The virtual switch automatically obtains dispatch statistics for MAC addresses associated with virtual nodes and uses these statistics to generate appropriate filter configurations for the physical network interface. This self-service mechanism eliminates the need for manual configuration of complex multi-level virtualization filters, maintaining ease of operation while achieving high classification accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses dispatch statistics as feedback to dynamically adjust and optimize packet filtering. By monitoring the actual traffic patterns and packet flows to and from virtual nodes, the system can refine its filter configurations to improve classification accuracy while adapting to changing network conditions without requiring manual intervention.

Inventive Principle:
Principle #23Feedback

3Reliability

If the system inspects packets to determine IP addresses and MAC addresses for firewall operations, then network security is improved, but the processing time and complexity increase

Engineering Contradiction:
Improvenetwork security through packet inspectionVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary packet classification at the physical network interface level using filter configurations that identify packets destined for virtual nodes based on MAC addresses and overlay network headers. By pre-classifying packets before they reach the virtual switch and firewall processing stages, the system reduces the processing time required for subsequent security inspections while maintaining comprehensive packet examination capabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10757076B2Enhanced network processing of virtual node data packets
Publication Date: 2020.08.25 VMWARE INC
  • US10757076B2 patent drawing
  • US10757076B2 patent drawing
  • US10757076B2 patent drawing

AI summary

Described herein are systems, methods, and software to enhance the management of packet filters for host computing systems. In one implementation, a method of managing packet filters for a physical network interface on a host computing system includes obtaining dispatch statistics for media access control (MAC) addresses associated with virtual nodes communicating over the physical network interface via a virtual switch. After obtaining the dispatch statistics, the method further provides identifying a filter configuration based on the dispatch statistics, wherein the filter configuration classifies received packets at the physical network interface into processing queues based on attributes identified in the received packets, and applying the filter configuration in the physical network interface.