Scope Controller Cloud Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud network architectures face limitations in scalability due to centralized communication methods, which concentrate obstacles and hinder distributed processing, leading to reduced performance as the number of hypervisors increases.
Innovation Solution
The implementation of a cloud network system with scope controllers that classify hypervisors into scopes, using virtual switches for data link layer communication within scopes and virtual routers for network layer communication between scopes and external connections, isolating data link layer communication within scopes and enabling efficient routing between scopes and external networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If centralized communication methods are used in cloud network architecture, then network management is simplified, but scalability is limited and performance decreases as the number of hypervisors increases
Solution Approach 1:
The patent segments the cloud network into multiple isolated scopes (Scope 1, Scope 2, etc.), each managed by independent scope controllers. Hypervisors are classified into different scopes, and virtual switches are deployed at each scope boundary. This segmentation allows each scope to operate independently, enabling the network to scale by simply adding new scopes without affecting existing ones, thus resolving the contradiction between simplified management and limited scalability.
2Reliability
If centralized communication methods are used, then network control is consolidated, but obstacles spread across the entire network and distributed processing is hindered
Solution Approach 1:
By dividing the network into isolated scopes with scope controllers managing each scope independently, the patent prevents obstacles from propagating across the entire network. Each scope acts as an isolated domain where failures or obstacles are contained locally, improving reliability through distributed processing while maintaining consolidated control within each scope.
Solution Approach 2:
The scope controller acts as an intermediary between different scopes and between virtual machines within a scope. It manages communication packets, determining whether to forward them within the same scope or to other scopes/routers. This intermediary mechanism enables consolidated network control while preventing obstacle propagation by localizing traffic management decisions.
3Productivity
If the number of hypervisors increases in a centralized architecture, then computing capacity is improved, but performance decreases due to communication bottlenecks
Solution Approach 1:
The patent segments communication traffic into scope-local and scope-crossing traffic. Virtual switches at scope boundaries handle local communication efficiently without involving centralized controllers, improving communication speed. Computing capacity can be increased by adding more hypervisors to existing scopes or creating new scopes, maintaining performance through distributed communication handling.
4Adaptability or versatility
If virtual machines are distributed across multiple hypervisors without scope classification, then resource utilization is improved, but network management complexity increases
Solution Approach 1:
By classifying hypervisors into scopes and deploying virtual switches at scope boundaries, the patent simplifies network management despite distributed VM placement. Each scope controller manages its local hypervisors independently, and the hierarchical structure (scope controllers → hypervisors → VMs) provides clear management boundaries, reducing overall complexity while maintaining high resource utilization.
Data Source
AI summary
A computer device forms a scope controller for a cloud network, including: memory configured to store a computer-readable instruction; and at least one processor configured to execute the instruction, wherein the cloud network may include: hypervisors classified as a plurality of scopes including a first scope; and virtual machines generated by the hypervisors, wherein the at least one processor is configured to: switch, using a virtual switch of the scope controller, a packet communicated between virtual machines generated by hypervisors classified as the first scope, and a packet received from an outside of the first scope, and route, using a virtual router of the scope controller, a packet communicated between the scope controller and a router for connecting to an outside of the cloud network, and a packet communicated between the scope controller and a different scope controller assigned to a different scope other than the first scope.


