Universal Cloud Classification as a Service for Dynamic Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud classification technologies lack the ability to enable and disable universal cloud classification (UCC) on-demand and dynamically on a per-tenant, per-service, or per-workload basis, leading to inefficiencies in traffic classification and policy enforcement in cloud environments, particularly in multi-tenancy scenarios where conventional methods like VLANs and IP addresses are insufficient.

Innovation Solution

The introduction of UCC as a Service (UCCaaS) provides a system and method to assign and manage cloud-IDs, service-IDs, and tenant-IDs within the network layer, enabling dynamic and on-demand UCC through software-defined networking (SDN) controllers, OpenFlow applications, and APIs to define and enforce flow rules for packet forwarding, thereby supporting granular policy enforcement across cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If UCC is enabled in a cloud environment, then traffic classification and policy enforcement capability is improved, but device complexity and operational flexibility deteriorate because UCC must be enabled or disabled for the entire environment without per-tenant or per-service control

Engineering Contradiction:
Improvetraffic classification capabilityVSAvoidoperational flexibility
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the UCC functionality from the overall cloud environment, allowing it to be independently enabled or disabled for specific tenants, services, or workloads. This is achieved through a UCC service component that can be selectively activated without affecting the entire cloud infrastructure, thus maintaining traffic classification capabilities where needed while preserving operational flexibility elsewhere.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic control mechanisms that allow UCC to be enabled or disabled on-demand for different cloud entities. The system can dynamically adjust UCC activation status based on tenant requirements, service types, or workload characteristics, transforming the static all-or-nothing UCC enablement into a flexible, adaptive system that responds to changing operational needs.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If conventional methods like VLANs and IP addresses are used for classification, then ease of operation is maintained, but measurement precision and classification accuracy deteriorate in multi-tenancy cloud environments

Engineering Contradiction:
Improveoperational simplicityVSAvoidclassification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces a UCC service component as an intermediary layer between the network infrastructure and cloud tenants. This mediator provides enhanced classification capabilities through cloud-IDs, service-IDs, and tenant-IDs without requiring changes to existing network operations. The intermediary translates and enriches conventional classification methods with additional contextual information, achieving higher precision while maintaining ease of operation through automated ID assignment and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10652155B2Universal cloud classification [UCC]as a service
Publication Date: 2020.05.12 CISCO TECHNOLOGY INC
  • US10652155B2 patent drawing
  • US10652155B2 patent drawing
  • US10652155B2 patent drawing

AI summary

Disclosed is a system and method of providing transport-level identification and isolation of container traffic. The method includes assigning, by a software-defined-network (SDN) controller in an SDN-enable cloud environment, a service-ID to a service, a tenant-ID to a tenant and/or workload-ID to yield universal cloud classification details, and extracting, from a data flow, the universal cloud classification details. The method includes receiving a policy, generating flow rules based on the policy and universal cloud classification details, and transmitting the flow rules to an openflow application to confine packet forwarding decisions for the data flow.