Tag-Based Firewall Rules for SDN Virtual Machine Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the number of forwarding rules in software defined networks increases, additional processing resources are required for calculating the data plane forwarding configuration, leading to management difficulties.

Innovation Solution

The method involves maintaining a data plane forwarding configuration based on tags associated with virtual machines, where tags define the type of operation and entity, allowing a single set of forwarding rules to be applied across multiple entities, reducing the need for separate rules and optimizing resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of forwarding rules in software defined networks is increased to manage multiple entities, then the ability to provide dedicated network control for each entity is improved, but the processing resources required for calculating the data plane forwarding configuration increase

Engineering Contradiction:
Improveability to provide dedicated network controlVSAvoidprocessing resources required
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the forwarding rules into two categories: entity-specific rules and VM-specific rules. The entity-specific rules are applied first to filter traffic between different entities, while the VM-specific rules handle communication within the same entity. This segmentation allows the system to provide dedicated network control for each entity without requiring separate complete rule sets for every entity, thereby reducing the overall processing resources needed while maintaining the ability to manage multiple entities independently.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate forwarding rules are generated for each entity, then network security and isolation between entities is improved, but the complexity of managing forwarding rules increases

Engineering Contradiction:
Improvenetwork security and isolationVSAvoidcomplexity of managing forwarding rules
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the management of entity-specific rules and VM-specific rules into a unified forwarding rule structure. Instead of managing completely separate rule sets for each entity, the system combines both types of rules in a single forwarding configuration that is applied across all entities. This merging approach maintains network security and isolation through the entity-specific portion of the rules while reducing management complexity by eliminating the need to create and maintain separate rule sets for each entity.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If a single set of forwarding rules is applied across multiple entities, then the management complexity is reduced, but the ability to provide dedicated network control for each entity deteriorates

Engineering Contradiction:
Improvemanagement complexityVSAvoidability to provide dedicated network control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by making the forwarding rules entity-specific through the use of entity identifiers. Each entity receives a customized set of forwarding rules tailored to its specific network requirements and security policies, while still using the same overall rule management framework. This allows the system to maintain ease of operation through a unified management approach while providing dedicated network control for each entity through customized rule applications.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11429410B2Tag based firewall implementation in software defined networks
Publication Date: 2022.08.30 VMWARE INC
  • US11429410B2 patent drawing
  • US11429410B2 patent drawing
  • US11429410B2 patent drawing

AI summary

Systems, methods, and software to enhance the management of software defined networks. A controller is configured to maintain a data plane configuration for a virtual machine environment based on forwarding rules. The controller is further configured to identify a virtual machine group to be deployed in the computing environment, and identify tags associated with each virtual machine in the virtual machine group. Once the tags are identified, the controller may update the data plane forwarding configuration based on the identified tags and the forwarding rules.