Network Segmentation for Native Cloud Computing Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing performance is significantly hindered due to the need for virtual machines, resulting in slower performance by 10-100 times compared to native computing, necessitating a solution for efficient resource allocation and isolation for high-performance computing tasks.
Innovation Solution
A system and method for native cloud computing that includes clusters of computing nodes and a control node to segment the data communication network, allowing for the allocation of isolated clusters with sufficient resources for direct execution of computation tasks, including provisioning operating systems and programs, and ensuring secure execution by isolating clusters communicatively and potentially physically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual machines are used to separate different user applications for security reasons, then security and isolation are improved, but computing performance deteriorates by 10-100 times
Solution Approach 1:
The patent segments the network into isolated clusters of computing nodes rather than using virtual machines on a unified system. Each cluster is physically or logically isolated through network segmentation, providing security and application separation at the network level rather than the virtualization level, thereby eliminating the performance overhead associated with VM-based isolation.
Solution Approach 2:
The patent introduces a control node as an intermediary that manages network segmentation and cluster allocation. The control node segments the data communication network to isolate clusters for native execution, mediating between the need for security isolation and the need for high-performance computing by enabling direct resource access within isolated clusters.
2Adaptability or versatility
If virtual machines are instantiated on each computing node for different user applications, then application separation is improved, but execution speed deteriorates significantly
Solution Approach 1:
The patent applies network segmentation to divide the computing infrastructure into separate clusters that can be isolated from each other. This segmentation approach provides application separation at the network level, allowing each cluster to execute applications natively without the virtualization overhead that slows execution speed.
Solution Approach 2:
The patent moves from virtualization in the software layer to network segmentation at the infrastructure layer. By isolating clusters through network segmentation rather than virtual machine instantiation, the system achieves application separation in a different dimensional space, enabling native execution speeds while maintaining security and isolation.
3Productivity
If network segmentation is used to isolate clusters for native execution, then computing performance is improved by 10-100 times, but network configuration complexity increases
Solution Approach 1:
The control node serves as an intermediary that automates network segmentation and cluster management. Rather than manually configuring complex network isolations, the control node receives allocation requests, determines suitable clusters, and automatically segments the network to isolate the selected cluster, reducing configuration complexity while enabling high-performance native execution.
Solution Approach 2:
The system enables self-service through automated cluster allocation and network segmentation. The control node automatically manages the entire process of cluster selection, resource allocation, and network isolation based on user requests, eliminating the need for manual network configuration complexity while delivering optimized computing performance.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed herein are systems, methods and storage medium associated with native cloud computing. In embodiments, a system may include a number of clusters of computing nodes, and a data communication network configured to couple the clusters of computing nodes. The system may further include a control node configured to segment or cause segmentation of the data communication network to isolate a cluster of the computing nodes from other clusters of the computing nodes, t for allocation for native execution of a computation task. The system may further include a control network coupled to the data communication network and the control node. Other embodiments may be disclosed and claimed.