SDN Appliance Disaggregates Policy Enforcement for Custom Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Custom computing or storage assets in cloud environments often lack the capability to apply security policies, disrupting resource deployment and limiting scalability due to hardware restrictions, especially when using bare-metal servers or non-VM workloads, which can impact performance and hinder migration of high-throughput workloads to the cloud.

Innovation Solution

Implementing an SDN appliance that disaggregates policy processing from the host, using an FPGA to move SDN policy enforcement off the host and provide high availability and fault tolerance, allowing for flexible SDN policy application and scalable networking, enabling seamless integration of custom hardware into cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are implemented on a customer's virtual network, then security is improved, but management plane connectivity to injected compute instances is disrupted

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement plane connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments network connectivity into two separate planes: a management plane for controlling injected compute instances and a data plane for customer traffic. This segmentation allows security policies to be applied to the data plane while preserving management plane connectivity, resolving the contradiction between security and operational access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dedicated data plane as an intermediary component that sits between the customer's virtual network and the injected compute instances. This intermediary enables security policies to be enforced on customer traffic while allowing the management plane to maintain direct connectivity to instances for provisioning and control operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If SDN policy stack is loaded on a network device, then SDN policy application capability is improved, but hardware restrictions and limitations prevent implementation

Engineering Contradiction:
ImproveSDN policy application capabilityVSAvoidhardware compatibility
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent introduces an SDN appliance as an intermediary device that runs the full SDN policy stack. This appliance acts as a mediator between the network devices and the control plane, enabling sophisticated SDN policy application without requiring modifications to hardware-restricted network devices or switches.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The SDN appliance provides universal SDN policy application capability that can work with various network device types and hardware configurations. By centralizing the SDN stack in a universal appliance rather than requiring it on every network device, the system achieves policy versatility without being constrained by individual hardware limitations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traffic is sent through several software hops for additional SDN policies, then policy enforcement is improved, but networking service performance drops

Engineering Contradiction:
Improvepolicy enforcementVSAvoidnetworking service performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts SDN policy enforcement from the host system and moves it to a dedicated SDN appliance. This extraction eliminates the performance penalty of multiple software hops on the host by consolidating policy processing in a specialized appliance, thereby maintaining policy enforcement while improving networking service performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a virtual network interface card (vNIC) that copies network traffic to the SDN appliance for policy processing. This copying mechanism allows the main network path to continue efficiently while a copy of the traffic is processed for policy enforcement, minimizing performance impact on the primary networking services.

Inventive Principle:
Principle #26Copying

4Power

If custom hardware is integrated into cloud environments, then hardware capability and performance are improved, but capability to apply policies is lost

Engineering Contradiction:
Improvehardware capabilityVSAvoidpolicy application capability
Core Design Contradiction:
PowerVSAdaptability or versatility

Solution Approach 1:

The patent introduces an SDN appliance as an intermediary that bridges custom hardware and the policy management system. The appliance receives traffic from custom hardware endpoints and applies SDN policies, thereby enabling policy application capability on custom hardware that lacks native policy enforcement capabilities while preserving the hardware's performance advantages.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11190406B1Injecting network endpoints into a SDN
Publication Date: 2021.11.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11190406B1 patent drawing
  • US11190406B1 patent drawing
  • US11190406B1 patent drawing

AI summary

A virtual network comprising virtual machines executing at a computing environment is implemented. A flexibly extensible NIC (eNIC) is executed at a software defined networking (SDN) appliance. A data packet is received that is addressed to a host that is connected to the virtual network. Based on a layer 2 address and a network identifier, the virtual switch identifies the host represented by the eNIC that is associated with the data packet. A policy associated with the host is determined and applied to the data packet. The policy is dynamically adjustable based on the host.