Multi-port NIC Air Gap Isolation for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In scalable compute resources, existing technologies fail to adequately isolate management traffic from application data traffic, compromising security and reliability due to shared communication paths and networks.
Innovation Solution
The implementation of additional communication ports and paths, specifically multi-port NICs, allows data traffic to bypass management switches, achieving air gap isolation between management and application data networks, enhancing security through physically segregated communication paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If management traffic and application data traffic share the same physical network infrastructure, then device complexity is reduced and ease of operation is improved, but security and reliability are compromised due to lack of isolation
Solution Approach 1:
The patent segments the network infrastructure by providing separate physical network interfaces (first network interface for management traffic, second network interface for application data traffic) and separate communication paths. This segmentation ensures that management traffic and application data traffic are physically isolated from each other, preventing security compromises while maintaining manageable device complexity through structured separation.
2Reliability
If separate physical networks are used for management and application data, then security and reliability are improved through isolation, but device complexity and cost increase
Solution Approach 1:
The appliance serves multiple functions by integrating both management network operations and application data network operations within a single device. The appliance includes both a management network interface and application data network interface, allowing it to function as both a network management component and an application server, thereby reducing the need for entirely separate infrastructure systems while maintaining security isolation.
3Device complexity
If a single active uplink is used for customer network connectivity, then device complexity is reduced, but reliability is compromised due to lack of redundancy
Solution Approach 1:
The patent changes the parameter of uplink configuration from a single active connection to multiple active uplinks (including at least a first uplink and a second uplink). This parameter change enables network redundancy and failover capabilities, improving reliability by allowing the system to switch between multiple uplinks if one fails, while maintaining manageable complexity through standardized multi-homing configurations.
Data Source
AI summary
Remote configuration of network interface cards (NICs) on appliances of a scaleable compute resource such as a frame-based system is disclosed. Frames may include a frame link module (FLM). Remote configuration of NICs may allow for multiple networks to be maintained in physical or logical isolation from each other. For example, a management data network may be maintained independently of an application data network. An FLM CPU may detect an appliance, validate compatibility for the appliance, a midplane, a PHY connection, etc. Commands from the FLM CPU may configure the independent networks. Independent networks may provide redundancy and segregation by data type. A controller area network (CAN) bus may deliver configuration commands to a NIC of an attached appliance. Air gap equivalent isolation of networks based on type of network may be achieved while maintaining redundancy of networks to address potential failure of individual components.


