Policy-Aware Virtual Tenant Network Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for migrating enterprise applications to the cloud struggle to preserve management policies such as bandwidth guarantees, firewall rules, and load balancing schemes, especially when dealing with more general middlebox policies, and lack flexibility and scalability.

Innovation Solution

A method for policy-aware deployment of enterprise virtual tenant networks that involves translating tenant resource demands and policies into network topology and bandwidth demands, pre-arranging physical resources, and using a heuristic algorithm for resource mapping and routing to ensure policy-compliant paths, incorporating OpenFlow-based network management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based schemes (virtual private cloud) are used to implement tenant policies, then performance and reliability are improved, but flexibility and scalability deteriorate

Engineering Contradiction:
Improveperformance and reliabilityVSAvoidflexibility and scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates virtual copies of physical network appliances by implementing them as virtual machines. Each physical appliance is replicated as a virtual instance that can be deployed in the cloud environment, allowing policy functions to be maintained while enabling flexibility and scalability through virtualization.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces physical hardware-based network appliances with software-based virtual machine implementations. This substitution allows the same network functions (firewall, load balancer, IDS) to be performed through virtualized components rather than dedicated physical devices, achieving both reliability and scalability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If software-based schemes are used to implement tenant policies, then flexibility is improved, but performance and management complexity deteriorate

Engineering Contradiction:
ImproveflexibilityVSAvoidperformance and management complexity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network functions into separate virtual machine instances, each responsible for specific policies (firewall, load balancing, IDS). This segmentation allows independent optimization of each function and simplifies management by isolating policy implementations rather than requiring complex integrated systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy translation layer that acts as an intermediary between high-level tenant policies and low-level network implementations. This mediator automatically translates policy requirements into actionable network configurations, reducing management complexity while maintaining flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If existing policy translation methods are used, then specific policies (bandwidth, path diversity) are improved, but adaptability to general middlebox policies deteriorates

Engineering Contradiction:
Improvespecific policy translation accuracyVSAvoidextension to general middlebox policies
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal policy translation framework that can handle multiple types of network policies (bandwidth guarantees, firewall rules, load balancing, IDS) through a single unified approach. The system translates diverse policy requirements into common virtual machine deployment and routing operations, enabling broad applicability across different policy types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9106576B2Policy-aware based method for deployment of enterprise virtual tenant networks
Publication Date: 2015.08.11 NEC CORP
  • US9106576B2 patent drawing
  • US9106576B2 patent drawing
  • US9106576B2 patent drawing

AI summary

A method for policy-aware mapping of an enterprise virtual tenant network includes receiving inputs from a hosting network and tenants, translating resource demand and policies of the tenants into a network topology and bandwidth demand on each link in the network; pre-arranging a physical resource of a physical topology for clustering servers on the network to form an allocation unit before a VTN allocation; allocating resources of the hosting network to satisfy demand of the tenants in response to a VTN demand request; and conducting a policy aware VTN mapping for enumerating all feasibly resource mappings, bounded by a predetermined counter for outputting optimal mapping with policy-compliant routing paths in the hosting network.