Top of Rack Switch Virtual Network Interface for Dedicated Hardware Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional virtual networks provided by cloud providers restrict transparent access to customers' dedicated hardware due to increased latency and the inability to apply uniform network-level policies, especially when connected via virtual private networks.

Innovation Solution

Implementing a programmable Top of Rack (TOR) switch with a software-defined network (SDN) controller to create virtual network interfaces and enforce policies such as isolation, access control, and next-hop routes, allowing for uniform policy application across dedicated hardware without latency increases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customers connect dedicated hardware to cloud resources via virtual private network, then access to both cloud and on-premises resources is enabled, but latency increases and uniform network-level policies cannot be applied

Engineering Contradiction:
Improveaccess capabilityVSAvoidlatency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

A TOR switch is introduced as an intermediary device between the virtual machine and dedicated hardware. The TOR switch creates a virtual network interface that allows direct local networking, eliminating the need for VPN-based connections through external networks. This intermediary enables low-latency communication while maintaining network-level policy control through the virtualization layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If customers connect dedicated hardware to cloud resources via virtual private network, then access to both cloud and on-premises resources is enabled, but uniform network-level policies cannot be applied

Engineering Contradiction:
Improveaccess capabilityVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The TOR switch implements a virtual network interface that serves multiple functions simultaneously: it provides direct local networking for low-latency access, enforces uniform network-level policies across all connections, and maintains compatibility with existing virtualization infrastructure. This universal interface consolidates multiple access methods into a single standardized approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If TOR switch creates virtual network interface for direct local networking, then low latency and high throughput are achieved, but network-level policy control must be enforced

Engineering Contradiction:
ImprovethroughputVSAvoidpolicy enforcement complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system replaces complex software-based policy enforcement mechanisms with hardware-level policy enforcement in the TOR switch. The switch uses virtual routing and forwarding (VRF) artifacts and virtual network identifiers (VNI) to automatically apply network-level policies at the hardware forwarding plane, eliminating the need for complex software-based access control lists and policy management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11621869B2Enabling access to dedicated resources in a virtual network using top of rack switches
Publication Date: 2023.04.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11621869B2 patent drawing
  • US11621869B2 patent drawing
  • US11621869B2 patent drawing

AI summary

Systems and methods for enabling access to dedicated resources in a virtual network using top of rack switches are disclosed. A method includes a virtual filtering platform encapsulating at least one packet, received from a virtual machine, to generate at least one encapsulated packet comprising a virtual network identifier (VNI). The method further includes a TOR switch: (1) receiving the at least one encapsulated packet and decapsulating the at least one encapsulated packet to create at least one decapsulated packet, (2) using the VNI to identify a virtual routing and forwarding artifact to determine a virtual local area network interface associated with the dedicated hardware portion, and (3) transmitting the at least one decapsulated packet to the dedicated hardware portion based on at least one policy provided by a controller, where the at least one policy comprises information related to a customer of the service provider.