Scoped Network Address Pool Management for Virtual Data Centers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computer systems, managing large numbers of virtual machines with dynamic network interfaces poses challenges in efficiently allocating unique network addresses while ensuring security and performance, as existing methods lack a structured approach to address pool management.

Innovation Solution

Implementing a hierarchy of groups within a virtual data center to organize machines and associate them with specific network address pools, allowing for the selection of network addresses based on machine context, which enhances security and performance by reducing the pool of available addresses and enabling stricter traffic rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a large pool of network addresses is used to accommodate many virtual machines, then the system can support more virtual machines, but security and performance management become more difficult

Engineering Contradiction:
Improvecapacity to support virtual machinesVSAvoidcomplexity of address pool management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the network address pool into multiple scoped pools associated with different groups (tenant groups, project groups, namespace groups). Each scope has its own address pool, allowing independent management and reducing the complexity of managing a single large pool while maintaining the capacity to support many virtual machines across different scopes.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If network addresses are dynamically allocated to virtual machines, then flexibility and adaptability improve, but control over address allocation and security management deteriorates

Engineering Contradiction:
Improvedynamic address allocation flexibilityVSAvoidcontrol over address allocation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements different address pool management policies for different scopes. Each scope (tenant, project, namespace) can have its own address pool with specific allocation rules, allowing dynamic allocation within each scope while maintaining centralized control through the hierarchical structure. This enables flexible dynamic allocation without losing overall control.

Inventive Principle:
Principle #3Local quality

3Device complexity

If a flat network address structure is used, then simplicity is maintained, but security enforcement and traffic management become less effective

Engineering Contradiction:
Improvesimplicity of network structureVSAvoidsecurity risks and performance issues
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a hierarchical nested structure where scopes are nested within groups, and address pools are nested within scopes. This nested structure enables sophisticated security enforcement and traffic management through scope-based policies while maintaining relative simplicity through the organized hierarchical framework. Each nested level can enforce security rules without complicating the overall structure.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10423433B2Scoped network address pool management
Publication Date: 2019.09.24 RED HAT ISRAEL
  • US10423433B2 patent drawing
  • US10423433B2 patent drawing
  • US10423433B2 patent drawing

AI summary

Systems and methods for storing and managing pools of network addresses. An example method may comprise: receiving, by a processing device, a request for a network address to be associated with a network interface of a machine, wherein the machine is represented by one of: a virtual machine or a computer system; identifying a hierarchy of groups that include the machine; searching the hierarchy of groups to identify a group having an associated pool of network addresses; and selecting a network address from the pool of network addresses.