Network Policy Engine for Virtual Machine Lifecycle Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualization environments with multiple virtual machines, configuring and managing network settings and security policies becomes complex and time-consuming, requiring explicit configuration for each virtual machine, which is tedious and inefficient.

Innovation Solution

A system and method that uses network policies to dynamically configure networks, allowing administrators to apply security requirements to virtual machines without explicit configuration of each machine, by utilizing a control program and policy engine that identifies and selects suitable network implementations based on existing configurations and lifecycle events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If explicit configuration is used for each virtual machine, then network security policies can be precisely controlled, but configuration time and management complexity increase significantly

Engineering Contradiction:
Improvenetwork security controlVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies universality by creating a standardized network configuration template that can be universally applied to multiple virtual machines. The template includes pre-defined network policies, security settings, and connectivity parameters that can be reused across different VMs, eliminating the need to manually configure each VM individually while maintaining consistent security controls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary action by pre-configuring network templates with all necessary security policies and network parameters before deployment. These templates are prepared in advance with validated security settings, allowing rapid instantiation of compliant virtual machine networks without requiring time-consuming manual configuration during deployment.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If individual network configuration is performed for each virtual machine, then specific security requirements can be met, but management complexity and effort increase

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges individual network configuration tasks into a unified template-based system. Multiple VM network configurations are combined into a single reusable template that encapsulates common security policies, network settings, and connectivity rules. This consolidation reduces management complexity while ensuring consistent security enforcement across all VMs through centralized template management.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If explicit network configuration is used, then network connectivity can be established, but portability and adaptability decrease

Engineering Contradiction:
Improvenetwork connectivityVSAvoidportability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent uses copying by creating reusable network configuration templates that can be replicated across different virtualization environments. These templates capture essential network topology, security policies, and connectivity parameters in a portable format that can be copied and applied to new VMs or migrated environments without requiring manual reconfiguration, thereby enhancing portability while maintaining reliable network connectivity.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2958257B1Network policy implementation for a multi-virtual machine appliance
Publication Date: 2018.08.29 CITRIX SYSTEMS INC
  • EP2958257B1 patent drawingFigure 1A
  • EP2958257B1 patent drawingFigure 1B
  • EP2958257B1 patent drawingFigure 1C

AI summary

A networking policy implementation for a multi-virtual machine appliance that includes a method for selecting a network implementation by applying a network policy to existing network configurations within a virtualization environment of a computing device. A control program that executes within the virtualization environment, receives an event notification generated by a virtual machine in response to a lifecycle event. The control program, in response to receiving the notification, invokes a policy engine that applies a network policy to existing network configurations of the virtualization environment. This network policy can correspond to the virtual machine or to a network object connected to virtual interface objects of the virtual machine. The policy engine then identifies an existing network configuration that has attributes which satisfy the network policy, and selects a network implementation that satisfies the network policy and the network configuration.