Software Defined Access Fabric Common Subnet Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network implementations restrict a single virtual network to be associated with one subnet, making it difficult for enterprises with multiple sites to manage and isolate virtual networks while sharing resources, and existing solutions like LISP face challenges with dynamic IP address management.

Innovation Solution

A mechanism that provisions a common subnet across multiple subscribers with dynamic network policies, using a map server to generate and enforce policies that isolate subscribers and allow communication only between designated entities, such as a provider and subscriber, within the same subnet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single virtual network is restricted to one subnet, then network security and isolation are improved, but network flexibility and resource sharing capability deteriorate

Engineering Contradiction:
Improvenetwork security and isolationVSAvoidnetwork flexibility and resource sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network into virtual networks (VNs) that can span multiple subnets, with each VN containing multiple virtual switches (e.g., vSwitch1, vSwitch2) distributed across different physical switches. This allows multiple VNs to coexist in the same physical subnet while maintaining logical isolation through virtual switching layers, resolving the contradiction between security isolation and network flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer (software-defined networking) that operates above the physical network layer. By implementing virtual switches and virtual networks at this higher dimension, multiple isolated VNs can be multiplexed over the same physical subnet infrastructure, enabling both security isolation and resource sharing capability simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Quantity of substance

If multiple subnets are used to improve address allocation efficiency and network security, then network address utilization and security are improved, but network complexity and deployment difficulty worsen

Engineering Contradiction:
Improvenetwork address utilizationVSAvoidnetwork complexity and deployment difficulty
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements a universal virtual switch framework that can operate across multiple subnets and physical switches. The virtual switch abstraction provides multi-functional capabilities including addressing, routing, and isolation functions within a unified software platform, simplifying deployment compared to traditional multi-subnet configurations that require separate hardware routing components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The virtual switch acts as an intermediary layer between physical switches and virtual networks. It mediates communication between VNs across different subnets, handling address translation, packet forwarding, and isolation policies automatically, thereby reducing deployment complexity while maintaining efficient address allocation across multiple subnets.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If LISP is used for network addressing, then address management is improved, but dynamic IP address management capability deteriorates

Engineering Contradiction:
Improveaddress managementVSAvoiddynamic IP address management capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic IP address assignment within the virtual network framework. When a host joins a VN, the system dynamically assigns an IP address from the available pool in the target subnet. The virtual switch maintains binding tables that map dynamic IP addresses to physical host locations, enabling flexible address management that adapts to changing network conditions while maintaining precise address control.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12192057B2Software defined access fabric without subnet restriction to a virtual network
Publication Date: 2025.01.07 CISCO TECHNOLOGY INC
  • US12192057B2 patent drawing
  • US12192057B2 patent drawing
  • US12192057B2 patent drawing

AI summary

Systems, methods, and computer-readable storage media are provided for provisioning a common subnet across a number of subscribers and their respective virtual networks using dynamically generated network policies that provide isolation between the subscribers. The dynamic generation of the network policies is performed when a host (e.g. client) is detected (via a switch) as the host joins the computing network via virtual networks. This ability to configure a common subnet for all the subscriber virtual networks allows these subscribers to more easily access external shared services coming from a headquarter site while keeping the separation and segmentation of multiple subscriber virtual networks within a single subnet. This allows the Enterprise fabric to be more simple and convenient to deploy without making security compromises.