Context-Aware Network Introspection for SDN User Differentiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network introspection tools are inadequate for Software-Defined Networking (SDN) environments, leading to increased time in root-causing and solving network problems due to their inability to differentiate between users sharing the same IP address and lack of insight into packet flows among virtual machines and applications.

Innovation Solution

Implementing context-aware network introspection in SDN environments, where hosts detect and analyze packet flow information and context data to generate detailed network map information, enabling system administrators to diagnose issues more effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional network introspection tools are used in SDN environments, then the tools can provide basic network monitoring, but they cannot differentiate between users sharing the same IP address and lack insight into packet flows among virtual machines and applications

Engineering Contradiction:
Improveuser differentiation capabilityVSAvoidSDN environment compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the network identification problem by introducing multiple identification layers beyond IP addresses. It divides user identification into device-level identifiers (MAC addresses, device fingerprints) and application-level identifiers (process IDs, container IDs), enabling differentiation of users sharing the same IP address through hierarchical segmentation of identification data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds new dimensions to network introspection by incorporating contextual information layers (application context, user context, device context) beyond traditional network layer data. This multi-dimensional approach enables precise user differentiation and packet flow analysis in SDN environments where IP addresses alone are insufficient.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of time

If conventional network introspection tools are used, then the system structure remains simple, but the time required for root-causing and solving network problems increases

Engineering Contradiction:
Improvenetwork problem-solving timeVSAvoidintrospection system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by proactively collecting and storing contextual information (application metadata, user profiles, device characteristics, packet flow patterns) before network problems occur. This pre-collected context enables rapid problem diagnosis and root cause analysis when issues arise, significantly reducing network troubleshooting time despite increased system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary contextual information layer between the network packet flow and the analysis engine. This intermediary layer aggregates and structures multi-source data (application context, user context, device context) into standardized formats, enabling efficient problem-solving without requiring direct complex interactions between multiple system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If context-aware network introspection is implemented, then diagnostic effectiveness is improved, but the system requires collecting and processing multiple types of context information

Engineering Contradiction:
Improvenetwork diagnosis effectivenessVSAvoidinformation collection complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a multi-functional context collection framework that gathers diverse information types (network packets, application metadata, device characteristics, user profiles) through a unified architecture. This universal approach improves diagnostic effectiveness while managing complexity through standardized collection and processing mechanisms applicable across different SDN environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies self-service by enabling the introspection system to automatically collect, correlate, and analyze contextual information without requiring manual configuration or intervention. The system autonomously gathers data from multiple sources, correlates it with stored context information, and generates diagnostic insights, thereby improving ease of operation despite the complexity of handling multiple information types.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10938681B2Context-aware network introspection in software-defined networking (SDN) environments
Publication Date: 2021.03.02 VMWARE INC
  • US10938681B2 patent drawing
  • US10938681B2 patent drawing
  • US10938681B2 patent drawing

AI summary

Example methods are provided for a first host to perform context-aware network mapping a software-defined networking (SDN) environment. One example method may comprise: detecting multiple packet flows that include an egress packet flow originating from a first endpoint and destined for a second host, and an ingress packet flow originating from a second host or a third host and destined for the first endpoint or a second endpoint. The method may also comprise: in response to detecting the egress packet flow, obtaining first packet flow information and first context information; in response to detecting the ingress packet flow, obtaining second packet header information and second context information; and generating network map information that identifies the egress packet flow based on the first packet flow information and first context information, and the ingress packet flow based on the second packet flow information and second context information.