Node-Level Routing Isolation for HPC Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
High-performance computer systems face challenges in achieving flexible and secure network isolation while ensuring the reliability and availability of resources, especially as system scale and complexity increase.
Innovation Solution
The proposed solution involves a node-level isolation method that configures routing tables for each computing node, allowing only valid routing information to enable communication between nodes, and combining this with topology-level and user-level isolation to achieve comprehensive network security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network virtualization is used to dynamically configure virtual networks, then resource utilization rate increases and flexibility improves, but system complexity increases
Solution Approach 1:
The patent segments the network isolation function into multiple levels: topology-level isolation (dividing physical network into isolated zones), node-level isolation (controlling communication between individual nodes), and user-level isolation (separating user workloads). This segmentation allows complex isolation requirements to be managed through simpler, hierarchical components, resolving the contradiction between flexibility and complexity.
Solution Approach 2:
The patent implements dynamic network configuration through virtualization technologies that allow virtual networks to be dynamically created, modified, and deleted without physical reconfiguration. Routing tables and network policies can be adjusted in real-time based on workload demands, providing network flexibility while abstracting the underlying complexity from users.
2Reliability
If routing tables are configured for node-level isolation, then network security improves, but communication efficiency decreases due to routing lookup overhead
Solution Approach 1:
The patent pre-configures routing tables with valid routing information before communication occurs. Nodes have their routing tables prepared in advance with all necessary routing entries, so that during actual communication, nodes only need to perform simple table lookups rather than dynamically computing routes. This preliminary preparation maintains security while minimizing communication overhead.
Solution Approach 2:
The patent implements localized routing validation where each node independently checks routing validity based on its own routing table and the source node's identity. Instead of centralized validation for all communications, each node performs local security checks, reducing the overall validation overhead while maintaining network-wide security.
3Reliability
If physical network structure is maintained for stability, then system reliability improves, but adaptability to changing resource demands decreases
Solution Approach 1:
The patent introduces virtual network layers as intermediaries between the stable physical network infrastructure and the dynamic resource allocation requirements. The virtual network layer abstracts the physical topology, allowing logical network configurations to change without affecting the underlying physical structure. This intermediary layer maintains physical stability while enabling logical adaptability.
Solution Approach 2:
The patent adds a logical dimension to the physical network by implementing virtual networks that operate overlaying the physical infrastructure. While the physical network maintains its stable topology, the virtual network layer provides dynamic configuration capabilities through software-defined networking, effectively adding adaptability in a new dimension without disrupting physical stability.
Data Source
AI summary
Disclosed are an isolation method for a high-performance computer system, and a high-performance computer system. The isolation method comprises node-level isolation performed. The node-level isolation comprises: configuring a routing table for each computing node, and configuring, in the routing table, valid routing information for computing node pairs; when any one source computing node needs to communicate with a target computing node, determining, by lookup, whether valid routing information exists between the source computing node and the target computing node according to the configured routing table; if so, allowing the source computing node to communicate with the target computing node; otherwise, forbidding the source computing node from communicating with the target computing node. The disclosure can realize network security isolation of the high-performance computer system, and guarantee the security and reliability of high-performance computers under the premise of ensuring flexible expansion and high availability of high-performance computing resources.


