Tag-Based Firewall Rules for SDN Virtual Machine Segregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As the number of forwarding rules in software defined networks increases, additional processing resources are required for calculating the data plane forwarding configuration, leading to management difficulties.
Innovation Solution
The method involves maintaining a data plane forwarding configuration based on tags associated with virtual machines, where tags define the type of operation and entity, allowing a single set of forwarding rules to be applied across multiple entities, reducing the need for separate rules and optimizing resource allocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the number of forwarding rules in software defined networks is increased to manage multiple entities, then the ability to provide dedicated network control for each entity is improved, but the processing resources required for calculating the data plane forwarding configuration increase
Solution Approach 1:
The patent segments the forwarding rules into two categories: entity-specific rules and VM-specific rules. The entity-specific rules are applied first to filter traffic between different entities, while the VM-specific rules handle communication within the same entity. This segmentation allows the system to provide dedicated network control for each entity without requiring separate complete rule sets for every entity, thereby reducing the overall processing resources needed while maintaining the ability to manage multiple entities independently.
2Reliability
If separate forwarding rules are generated for each entity, then network security and isolation between entities is improved, but the complexity of managing forwarding rules increases
Solution Approach 1:
The patent merges the management of entity-specific rules and VM-specific rules into a unified forwarding rule structure. Instead of managing completely separate rule sets for each entity, the system combines both types of rules in a single forwarding configuration that is applied across all entities. This merging approach maintains network security and isolation through the entity-specific portion of the rules while reducing management complexity by eliminating the need to create and maintain separate rule sets for each entity.
3Ease of operation
If a single set of forwarding rules is applied across multiple entities, then the management complexity is reduced, but the ability to provide dedicated network control for each entity deteriorates
Solution Approach 1:
The patent applies local quality by making the forwarding rules entity-specific through the use of entity identifiers. Each entity receives a customized set of forwarding rules tailored to its specific network requirements and security policies, while still using the same overall rule management framework. This allows the system to maintain ease of operation through a unified management approach while providing dedicated network control for each entity through customized rule applications.
Data Source
AI summary
Systems, methods, and software to enhance the management of software defined networks. A controller is configured to maintain a data plane configuration for a virtual machine environment based on forwarding rules. The controller is further configured to identify a virtual machine group to be deployed in the computing environment, and identify tags associated with each virtual machine in the virtual machine group. Once the tags are identified, the controller may update the data plane forwarding configuration based on the identified tags and the forwarding rules.


