Overlay Network Communication Manager for Data Center Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing communications between multiple computing nodes separated by physical networks is complex, especially in large-scale data centers, where existing solutions do not effectively provide network isolation and security while allowing dynamic reconfiguration of virtual networks.
Innovation Solution
The implementation of an overlay network using Communication Manager modules that embed virtual network addresses within physical network addresses, allowing for transparent communication routing and dynamic reconfiguration of virtual networks without encapsulating physical network devices, using Stateless IP/ICMP Translation (SIIT) or similar techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtualization technologies are used to share physical computing machines among multiple users, then resource utilization efficiency is improved, but network management complexity and security isolation difficulty increase
Solution Approach 1:
The patent segments the physical network into multiple virtual networks using virtual switches and routing instances. Each virtual network is isolated with its own addressing scheme, allowing multiple users to share physical infrastructure while maintaining separate network contexts. This segmentation resolves the contradiction by enabling resource sharing through virtualization while managing complexity through structured network division.
Solution Approach 2:
The patent introduces virtual switches and routing instances as intermediary components between physical network devices and virtual machines. These intermediaries handle address translation, routing decisions, and security policies, shielding users from physical network complexity while enabling secure multi-tenant resource sharing.
2Reliability
If computing nodes are separated by physical networks, then physical network security is improved, but communication management flexibility and reconfiguration ease deteriorate
Solution Approach 1:
The patent adds a virtual network dimension overlaying the physical network infrastructure. Virtual network addresses and routing paths operate in this additional dimension, allowing flexible reconfiguration of communication patterns without altering physical network topology. This resolves the contradiction by maintaining physical network security boundaries while enabling flexible virtual network management through address translation and virtual routing.
Solution Approach 2:
The patent implements dynamic virtual network configuration where routing instances and virtual switches can be reconfigured without physical network changes. Virtual network addresses can be reassigned and routing paths dynamically adjusted, providing communication management flexibility while the underlying physical network maintains its secure, stable structure.
3Ease of operation
If virtual network addresses are embedded in physical network addresses, then communication transparency is improved, but address resolution complexity increases
Solution Approach 1:
The patent performs preliminary address resolution by maintaining mapping tables that associate virtual network addresses with physical network addresses before communication occurs. Routing instances pre-compute routing paths and perform address translation in advance, so that during actual communication, the process is transparent and does not require complex real-time resolution. This resolves the contradiction by making communication transparent through pre-established address mappings.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Techniques are described for configuring communications between multiple computing nodes, such as computing nodes that are separated by one or more physical networks. In some situations, the techniques may be used to provide a virtual network between multiple computing nodes that are separated by one or more intermediate physical networks, such as from the edge of the one or more intermediate physical networks by modifying communications that enter and/or leave the intermediate physical networks.