Transparent Cloud Proxy for Virtualized Network Function Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems lack a method to deploy virtualized Network Functions (NFs) in a cloud-based environment without interfering with L3 network operations, requiring routing protocols within the virtualized NF, which imposes operational overhead and limits network resiliency and performance.
Innovation Solution
A transparent L2/L3 cloud-based proxy element is constructed using a virtualized NF with Address Resolution Protocol (ARP) and Neighbor Discovery (ND) proxy interfaces, allowing traffic to pass through without implementing routing protocols within the NF, enabling dynamic routing and autonomous adjustments to network topology.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If routing protocols are implemented within the virtualized NF, then the NF can act as Next Hop Router and traffic can flow through it, but operational overhead increases and network resiliency decreases
Solution Approach 1:
The patent extracts the routing protocol functionality from the virtualized NF and places it in the physical network infrastructure. The virtualized NF only needs to perform basic packet forwarding based on MAC addresses, while routing decisions are handled by traditional routers, eliminating the complexity of implementing and maintaining routing protocols within the virtualized environment.
Solution Approach 2:
The patent introduces an intermediary approach where the virtualized NF acts as a transparent bridge between L2 and L3 network layers. It uses L2 MAC address forwarding for data plane traffic while L3 routing protocols operate in the control plane between physical routers, allowing both functions to coexist without interference.
2Adaptability or versatility
If routing capabilities are added to the virtualized NF, then it can connect to network routers via routing protocols, but memory and processing resources are consumed
Solution Approach 1:
The patent removes the need for virtualized NFs to maintain routing protocol stacks, routing tables, and associated memory structures. Routing capabilities are extracted and retained in the physical router infrastructure, allowing virtualized NFs to operate with minimal resource consumption while still providing routing functionality through their L2/L3 bridge capability.
Solution Approach 2:
The patent enables multiple virtualized NF instances to share the same underlying physical routing infrastructure. Instead of each virtualized NF needing its own routing protocol implementation, they all leverage the routing capabilities of the physical routers, eliminating redundant resource consumption across multiple instances.
3Reliability
If the virtualized NF acts as Next Hop Router, then routing protocols can be maintained, but pre-programmed routing capabilities limit adaptability to new protocols
Solution Approach 1:
The patent creates a dynamic architecture where the virtualized NF can adapt to different L3 network configurations without requiring pre-programmed routing protocol support. The system dynamically routes traffic based on MAC address forwarding tables that are populated in real-time, allowing flexibility to work with various routing protocols without requiring the virtualized NF to understand or implement them.
Solution Approach 2:
The patent segments the networking functions into distinct layers: L2 MAC address forwarding is handled by the virtualized NF, while L3 routing protocol processing is handled by physical routers. This segmentation allows each component to specialize in its designated function, with the virtualized NF providing stable L2 forwarding while the physical routing infrastructure provides adaptable L3 protocol support.
Data Source
AI summary
System, device, and method of deploying layer-3 transparent cloud-based proxy network element. A virtual network function is defined between a west-side router and an east-side router. A west-side interface receives east-bound traffic from a west-side Virtual LAN. East-bound queries from the west-bound router, are intercepted and responded to by the west-side interface, the response indicating the MAC address of the west-side router instead of the east-side router. The system enables the virtual network function to transparently intercept network traffic, and to selectively apply to such traffic one or more network functions or operations, prior to forwarding the traffic or a modified version thereof to the east-side router, in a Layer-3 transparent manner.
