OpenStack Virtual Firewall With VPP Forwarding And Tenant-Specific Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual firewalls based on the OpenStack framework face limitations in forwarding efficiency due to bandwidth bottlenecks in native routing services and lack of differentiated data packet processing rules for different users in Vector Packet Processing (VPP) services.

Innovation Solution

Modify the firewall rule of a target data packet service using a preset rule, integrate a forwarding stack with higher performance, and provide a firewall configuration interface to set user-specific data packet processing rules, replacing the OpenStack routing service with a modified Vector Packet Processing (VPP) service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the native routing service of the OpenStack framework is used to control data packets based on the packet rule table, then the data packet control function is achieved, but the forwarding efficiency is limited by the bandwidth of the virtual routing

Engineering Contradiction:
Improvedata packet control functionVSAvoidforwarding efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the forwarding parameters by replacing the traditional routing service with a Vector Packet Processing (VPP) service that supports higher bandwidth forwarding. The VPP service uses optimized data structures and processing algorithms to achieve faster packet forwarding while maintaining the firewall rule-based control functionality.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes the mechanical routing service mechanism with a more advanced VPP service mechanism. The VPP service employs vectorized packet processing and optimized memory access patterns to replace the traditional routing table lookup and forwarding mechanism, achieving higher forwarding efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If the Vector Packet Processing (VPP) service is introduced to replace the packet processing mechanism of OpenStack, then the forwarding efficiency is improved, but the data packet processing rules are the same in one network and cannot meet the needs of different users

Engineering Contradiction:
Improveforwarding efficiencyVSAvoiddifferentiated data packet processing rules
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network into multiple virtual networks, each with its own set of data packet processing rules. The VPP service is configured to support multiple virtual networks independently, allowing each user or tenant to have customized firewall rules and packet processing policies specific to their virtual network requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes the VPP service multi-functional by enabling it to handle both high-performance packet forwarding and differentiated packet processing rules for multiple virtual networks simultaneously. The service is designed to be universally applicable across different network scenarios while maintaining the ability to enforce user-specific policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12432179B2Virtual firewall construction method based on openstack framework
Publication Date: 2025.09.30 INSPUR SUZHOU INTELLIGENT TECH CO LTD
  • US12432179B2 patent drawing
  • US12432179B2 patent drawing

AI summary

A virtual firewall construction method based on an OpenStack framework, and a storage medium. The method includes: modifying a firewall rule of a target data packet service according to a preset rule, and obtaining a modified target data packet service, the modified target data packet service utilizes the modified firewall rule to perform data packet control, and a forwarding stack is provided in the modified target data packet service, a forwarding performance of the forwarding stack is higher than the forwarding performance of a routing service of the OpenStack framework; a firewall configuration interface is provided in the firewall rule of the modified target data packet service, and the firewall configuration interface is configured to, according to different users under different virtual networks, set a data packet processing rule meeting requirements of the users; and replacing the routing service of the OpenStack framework according to the modified target packet service.