Service Operation Chaining in Multi-Tenant SDN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service chaining solutions are not robust enough to take advantage of the flexibility and control provided by software defined networking (SDN) and network virtualization, particularly in multi-tenant environments where middlebox services need to be efficiently deployed and managed across heterogeneous networks.

Innovation Solution

A method for forwarding tenant traffic through a set of service machines to perform a set of service operations, where the service machines can be standalone appliances or virtual machines, and the method involves classification of data message flows to identify the required service operations, embedding the service chain in tunnel headers, and routing the encapsulated messages through a service function path defined by network addresses of service machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service chaining solutions are implemented in multi-tenant environments, then service operations can be performed on tenant traffic, but the solutions are not robust enough to take advantage of SDN and network virtualization flexibility

Engineering Contradiction:
Improveflexibility and controlVSAvoidrobustness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments service chaining into discrete service functions that can be independently deployed and managed as virtual network functions (VNFs). Each service function is encapsulated and can be chained together through virtualization, allowing flexible composition while maintaining robust individual service delivery. This segmentation enables services to be deployed across multiple tenants without interference while preserving SDN control capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a service chaining controller as an intermediary that manages the composition, deployment, and orchestration of service functions. This controller acts as a mediator between the SDN infrastructure and the service functions, providing robust management while enabling flexible service chaining. The controller handles service function lifecycle management, chain composition, and dynamic reconfiguration, thereby resolving the contradiction between robustness and flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If middlebox services are deployed as hardware appliances, then service operations can be performed, but flexibility and control from SDN and network virtualization are not utilized

Engineering Contradiction:
Improveservice operation performanceVSAvoidflexibility and control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces traditional hardware appliance middlebox services with virtualized software-based service functions. This substitution allows services to run on standard infrastructure while being orchestrated through SDN controllers, thereby gaining flexibility and virtualization benefits without sacrificing service operational capabilities. The virtualization layer maintains service functionality while enabling dynamic deployment and management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a universal service chaining framework that can accommodate multiple types of middlebox services (firewall, load balancing, intrusion detection, etc.) as standardized virtual network functions. This universal platform allows different service types to be deployed consistently across the infrastructure, providing both the reliability of proven service operations and the flexibility of virtualized deployment. The standardized VNF interface enables multi-tenant support while maintaining service quality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If service machines are deployed in multi-tenant environments, then efficient resource utilization can be achieved, but complex classification and routing of tenant traffic is required

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidclassification and routing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where service functions automatically classify and route tenant traffic based on embedded identifiers in the data messages. The service chaining controller configures service machines with tenant-specific routing rules, enabling automated classification without manual intervention. This self-service approach reduces operational complexity while maintaining efficient multi-tenant resource utilization through automated service function selection and traffic steering.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary classification and service chain determination at the ingress point before traffic is distributed to service machines. The service chaining controller pre-configures service function chains based on tenant requirements and traffic characteristics, so that when traffic arrives at service machines, the classification and routing decisions have already been made. This preliminary action simplifies the processing burden on service machines while maintaining efficient multi-tenant resource utilization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12341680B2Service operation chaining
Publication Date: 2025.06.24 VMWARE INC
  • US12341680B2 patent drawing
  • US12341680B2 patent drawing
  • US12341680B2 patent drawing

AI summary

For a multi-tenant environment, some embodiments of the invention provide a novel method for forwarding tenant traffic through a set of service machines to perform a set of service operations on the tenant traffic. In some embodiments, the method performs a classification operation on a data message flow of a tenant, in order to identify a set of service operations to perform on the data message flow. For some data message flows, the classification operation selects the identified set of service operations from several candidate sets of service operations that are viable service operation sets for similar data message flows of the tenant. In some embodiments, the classification operation is based on a set of attributes associated with the data message flow (e.g., five tuple identifier, i.e., protocol and source and destination ports and IP addresses).