Software Defined Access Fabric Common Subnet Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network implementations restrict a single virtual network to be associated with one subnet, making it difficult for enterprises with multiple sites to manage and isolate virtual networks while sharing resources, and existing solutions like LISP face challenges with dynamic IP address management.
Innovation Solution
A mechanism that provisions a common subnet across multiple subscribers with dynamic network policies, using a map server to generate and enforce policies that isolate subscribers and allow communication only between designated entities, such as a provider and subscriber, within the same subnet.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single virtual network is restricted to one subnet, then network security and isolation are improved, but network flexibility and resource sharing capability deteriorate
Solution Approach 1:
The patent segments the network into virtual networks (VNs) that can span multiple subnets, with each VN containing multiple virtual switches (e.g., vSwitch1, vSwitch2) distributed across different physical switches. This allows multiple VNs to coexist in the same physical subnet while maintaining logical isolation through virtual switching layers, resolving the contradiction between security isolation and network flexibility.
Solution Approach 2:
The patent introduces a virtualization layer (software-defined networking) that operates above the physical network layer. By implementing virtual switches and virtual networks at this higher dimension, multiple isolated VNs can be multiplexed over the same physical subnet infrastructure, enabling both security isolation and resource sharing capability simultaneously.
2Quantity of substance
If multiple subnets are used to improve address allocation efficiency and network security, then network address utilization and security are improved, but network complexity and deployment difficulty worsen
Solution Approach 1:
The patent implements a universal virtual switch framework that can operate across multiple subnets and physical switches. The virtual switch abstraction provides multi-functional capabilities including addressing, routing, and isolation functions within a unified software platform, simplifying deployment compared to traditional multi-subnet configurations that require separate hardware routing components.
Solution Approach 2:
The virtual switch acts as an intermediary layer between physical switches and virtual networks. It mediates communication between VNs across different subnets, handling address translation, packet forwarding, and isolation policies automatically, thereby reducing deployment complexity while maintaining efficient address allocation across multiple subnets.
3Measurement precision
If LISP is used for network addressing, then address management is improved, but dynamic IP address management capability deteriorates
Solution Approach 1:
The patent implements dynamic IP address assignment within the virtual network framework. When a host joins a VN, the system dynamically assigns an IP address from the available pool in the target subnet. The virtual switch maintains binding tables that map dynamic IP addresses to physical host locations, enabling flexible address management that adapts to changing network conditions while maintaining precise address control.
Data Source
AI summary
Systems, methods, and computer-readable storage media are provided for provisioning a common subnet across a number of subscribers and their respective virtual networks using dynamically generated network policies that provide isolation between the subscribers. The dynamic generation of the network policies is performed when a host (e.g. client) is detected (via a switch) as the host joins the computing network via virtual networks. This ability to configure a common subnet for all the subscriber virtual networks allows these subscribers to more easily access external shared services coming from a headquarter site while keeping the separation and segmentation of multiple subscriber virtual networks within a single subnet. This allows the Enterprise fabric to be more simple and convenient to deploy without making security compromises.


