Service Switch Segment Mapping for VM Service Insertion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized computing environments without Software-defined Networking (SDN) support, inserting virtualized services between Virtual Machines (VMs) is challenging, as existing virtual switches do not facilitate service insertion between VMs on the same network segment, requiring advanced configurations and additional controller modules like SDN controllers, which may not be available in basic virtualized data centers.
Innovation Solution
A processing system is implemented with service machines and service switches that logically couple VMs to virtual switches, using communication interfaces to map original network segments to VM-based network segments, enabling service insertion by configuring VM-based network segments on service switches and mapping packets based on destinations, even without SDN support.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SDN solution is implemented to manage network services, then service insertion capability is improved, but device complexity and requirement for additional controller modules increases
Solution Approach 1:
The patent extracts the service insertion functionality from the complex SDN controller architecture and implements it directly within the virtual switch itself. The virtual switch is enhanced with service chain processing capabilities, allowing it to insert virtualized services without requiring external SDN controllers. This extraction of the core function from the complex control plane resolves the contradiction by maintaining service insertion capability while eliminating the need for additional controller modules.
Solution Approach 2:
The virtual switch is designed to perform service insertion autonomously without external control. It contains embedded logic to process service chains, map network segments, and route traffic through virtualized services independently. This self-service approach allows the virtual switch to provide SDN-like service insertion capabilities while avoiding the complexity of external SDN controller infrastructure.
2Adaptability or versatility
If VM-based network segments are mapped to original network segments, then service insertion is enabled, but virtual switch configuration complexity increases
Solution Approach 1:
The patent divides network segmentation into two distinct layers: original network segments (from the physical network) and VM-based network segments (from virtual machines). The virtual switch maintains separate segment definitions and mapping relationships between them. This segmentation approach enables service insertion by creating dedicated service segments while keeping configuration manageable through structured segment definitions rather than complex global reconfiguration.
Solution Approach 2:
The virtual switch acts as an intermediary between original network segments and VM-based network segments. It maintains mapping tables that translate between the two segment types, allowing service insertion without requiring direct configuration changes in either the physical network or virtual machine settings. This intermediary role simplifies operation by centralizing the complexity within the virtual switch itself rather than requiring coordinated changes across multiple system components.
3Adaptability or versatility
If service machines are logically coupled between VMs and virtual switch, then virtualized services are inserted, but network architecture complexity increases
Solution Approach 1:
The patent implements a nested architecture where service machines are logically embedded within the virtual switch's processing path. The virtual switch contains service chain processing capabilities that invoke service machines as nested components. This nesting allows virtualized services to be inserted into the network path without requiring service machines to be separate external entities, thereby reducing overall network architecture complexity while maintaining service insertion capability.
Solution Approach 2:
The virtual switch is designed with multi-functionality, serving both as a traditional network switching device and as a service chain processing platform. It handles standard packet forwarding while simultaneously providing service insertion, segment mapping, and service machine orchestration. This universal design consolidates multiple functions into a single component, reducing network architecture complexity compared to having separate dedicated service insertion infrastructure.
Data Source
AI summary
A processing system includes: a first service machine having a first service module; and a first service switch; wherein the first service machine and the first service switch are configured for logically coupling between virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the first service switch. A processing system includes: a service module; a first communication interface for communication with a virtual switch, the virtual switch configured for communicating with virtual machines; a second communication interface for communication with the virtual switch; the first communication interface being associated with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and wherein the second communication interface is associated with original network segments at the virtual switch.


