Overlay Network Communication Manager for Virtual Machine Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing communications between computing nodes separated by physical networks is complex, especially in large-scale data centers, where existing technologies struggle to provide efficient and secure network isolation and flexibility in virtual machine management.

Innovation Solution

The implementation of an overlay network using Communication Manager modules that embed virtual network address information within physical network addresses, allowing for transparent communication routing and network isolation without encapsulating physical network devices, using techniques like Stateless IP/ICMP Translation (SIIT) to translate between IPv4 and IPv6 protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share physical computing machines among multiple users, then resource utilization efficiency is improved, but network management complexity and security isolation difficulty increase

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidnetwork management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the physical network into multiple virtual networks using overlay network technology. Each virtual network is isolated and managed independently through virtual switches and routing protocols, allowing multiple users to share physical infrastructure while maintaining separate network spaces. This segmentation resolves the contradiction by dividing the complex unified network management into simpler isolated virtual network management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces overlay network protocols and virtual switching infrastructure as intermediaries between physical network devices and virtual machines. These intermediaries handle network address translation, routing, and isolation functions, simplifying the management complexity for end users while maintaining secure isolation between virtual networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If computing nodes are moved or added/removed dynamically in virtual networks, then network flexibility is improved, but maintaining network isolation and security becomes more difficult

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidnetwork isolation and security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic network configuration through overlay protocols that automatically update routing tables and network mappings when virtual machines are moved or added. The system dynamically adjusts network paths while maintaining isolation boundaries, allowing flexible node movement without compromising security or requiring manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

3Reliability

If overlay networks are used to provide virtual network isolation, then network security and flexibility are improved, but communication complexity between physical and virtual networks increases

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal overlay network protocols that can translate and route multiple types of traffic (IPv4, IPv6, ICMP) through a unified virtual switching infrastructure. This multi-functional approach handles diverse communication requirements through standardized protocols, reducing the apparent complexity for applications while maintaining security isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7865586B2Configuring communications between computing nodes
Publication Date: 2011.01.04 AMAZON TECH INC
  • US7865586B2 patent drawing
  • US7865586B2 patent drawing
  • US7865586B2 patent drawing

AI summary

Techniques are described for configuring communications between multiple computing nodes, such as computing nodes that are separated by one or more physical networks. In some situations, the techniques may be used to provide a virtual network between multiple computing nodes that are separated by one or more intermediate physical networks, such as from the edge of the one or more intermediate physical networks by modifying communications that enter and/or leave the intermediate physical networks so as to provide an overlay network without encapsulation of the communications. In some situations, the computing nodes may include virtual machine nodes hosted on one or more physical computing machines or systems, such as by or on behalf of one or more users (e.g., users of a program execution service).