Multi-port NIC Air Gap Isolation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In scalable compute resources, existing technologies fail to adequately isolate management traffic from application data traffic, compromising security and reliability due to shared communication paths and networks.

Innovation Solution

The implementation of additional communication ports and paths, specifically multi-port NICs, allows data traffic to bypass management switches, achieving air gap isolation between management and application data networks, enhancing security through physically segregated communication paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If management traffic and application data traffic share the same physical network infrastructure, then device complexity is reduced and ease of operation is improved, but security and reliability are compromised due to lack of isolation

Engineering Contradiction:
Improvenetwork infrastructure complexityVSAvoidtraffic isolation security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the network infrastructure by providing separate physical network interfaces (first network interface for management traffic, second network interface for application data traffic) and separate communication paths. This segmentation ensures that management traffic and application data traffic are physically isolated from each other, preventing security compromises while maintaining manageable device complexity through structured separation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate physical networks are used for management and application data, then security and reliability are improved through isolation, but device complexity and cost increase

Engineering Contradiction:
Improvetraffic isolation securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The appliance serves multiple functions by integrating both management network operations and application data network operations within a single device. The appliance includes both a management network interface and application data network interface, allowing it to function as both a network management component and an application server, thereby reducing the need for entirely separate infrastructure systems while maintaining security isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If a single active uplink is used for customer network connectivity, then device complexity is reduced, but reliability is compromised due to lack of redundancy

Engineering Contradiction:
Improveuplink configuration complexityVSAvoidnetwork connectivity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent changes the parameter of uplink configuration from a single active connection to multiple active uplinks (including at least a first uplink and a second uplink). This parameter change enables network redundancy and failover capabilities, improving reliability by allowing the system to switch between multiple uplinks if one fails, while maintaining manageable complexity through standardized multi-homing configurations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10742493B1Remote network interface card management
Publication Date: 2020.08.11 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10742493B1 patent drawing
  • US10742493B1 patent drawing
  • US10742493B1 patent drawing

AI summary

Remote configuration of network interface cards (NICs) on appliances of a scaleable compute resource such as a frame-based system is disclosed. Frames may include a frame link module (FLM). Remote configuration of NICs may allow for multiple networks to be maintained in physical or logical isolation from each other. For example, a management data network may be maintained independently of an application data network. An FLM CPU may detect an appliance, validate compatibility for the appliance, a midplane, a PHY connection, etc. Commands from the FLM CPU may configure the independent networks. Independent networks may provide redundancy and segregation by data type. A controller area network (CAN) bus may deliver configuration commands to a NIC of an attached appliance. Air gap equivalent isolation of networks based on type of network may be achieved while maintaining redundancy of networks to address potential failure of individual components.