Virtual I/O Server Policy-Based Network Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing environments, existing network filtering techniques such as IPsec tunneling and firewall configurations on physical routers significantly degrade network communication performance by requiring complex setups and resource-intensive operations.

Innovation Solution

A physical host executes a hypervisor that instantiates virtual machines and a virtual input/output server (VIOS), which determines the disposition of network packets based on policy data structures, allowing for efficient packet forwarding or dropping within the same packet flow without involving external routers, thus enhancing network filtering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec tunneling or firewall configurations on physical routers are used for network filtering, then network security is improved, but network communication performance significantly degrades

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork communication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the network filtering function from external physical routers and relocates it into the virtualized environment through the virtual switch. This allows filtering to be performed internally within the virtual network infrastructure, eliminating the performance degradation caused by external router processing while maintaining security requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The virtual switch acts as an intermediary component between virtual machines and physical networks, implementing policy-based filtering rules. This intermediary approach enables efficient packet filtering at the virtualization layer without requiring complex firewall configurations on physical routers, thus maintaining both security and performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IPsec tunneling or firewall configurations are implemented, then network filtering capability is improved, but setup complexity significantly increases

Engineering Contradiction:
Improvenetwork filtering capabilityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual switch is designed to provide multiple functions including packet forwarding, switching, and policy-based filtering within a single component. This multi-functionality eliminates the need for separate firewall configurations and complex router setups, simplifying the overall network filtering implementation while maintaining comprehensive filtering capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service network filtering by allowing virtual machines to be assigned security groups and filtering policies through automated configurations. This eliminates the need for manual firewall rule creation and complex setup procedures, reducing setup complexity while maintaining effective network filtering capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9037775B2Network filtering in a virtualized environment
Publication Date: 2015.05.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9037775B2 patent drawing
  • US9037775B2 patent drawing
  • US9037775B2 patent drawing

AI summary

A physical host executes a hypervisor or virtual machine monitor (VMM) that instantiates at least one virtual machine (VM) and a virtual input/output server (VIOS). The VIOS determines by reference to a policy data structure a disposition of a packet of network communication with the VM, where the disposition includes one of dropping the packet and forwarding the packet. Thereafter, the determined disposition is applied to a subsequent packet in a same packet flow as the packet.