Virtual Lab Network Isolation via Unique IP Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual lab environments face networking challenges due to duplicate IP addresses when deploying multiple virtual machine configurations, leading to routing problems and impermissible network scenarios.

Innovation Solution

A method is introduced to define and deploy virtual system configurations, including virtual machines (VMs) and configuration local networks (CLNs), where each VM is associated with a CLN, and customization instructions are executed within the guest operating system to configure virtual network interface cards (VNICs), ensuring isolated and efficient network management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple virtual machine configurations are deployed simultaneously in a virtual lab environment, then testing productivity and resource utilization improve, but networking routing problems occur due to duplicate IP addresses

Engineering Contradiction:
Improvetesting productivityVSAvoidnetworking reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the network addressing space by introducing a unique deployment identifier that is concatenated with the template IP address to form a globally unique IP address for each VM instance. This segmentation approach allows multiple deployments to coexist without address conflicts, resolving the contradiction between improved productivity from parallel deployments and maintained networking reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the IP address parameter by dynamically generating unique IP addresses based on the combination of template IP address and deployment identifier. This parameter transformation ensures that each deployed VM configuration receives a unique IP address, enabling simultaneous deployments without routing problems while maintaining network reliability.

Inventive Principle:
Principle #35Parameter changes

2Manufacturing precision

If manual network configuration is performed for each virtual machine deployment, then network management precision improves, but deployment time and operational complexity increase

Engineering Contradiction:
Improvenetwork configuration precisionVSAvoiddeployment time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining network templates with IP address schemes and configuration parameters before actual VM deployment. The system prepares the network configuration blueprint in advance, which is then automatically instantiated during deployment, ensuring configuration precision while eliminating manual setup time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating VM instances from pre-configured network templates. The template contains the standardized network configuration that is copied and adapted for each deployment, ensuring consistent and precise network configuration across all VMs while significantly reducing the time required for manual configuration.

Inventive Principle:
Principle #26Copying

3Use of energy by moving object

If multiple VM configurations share the same network infrastructure, then resource utilization improves, but network isolation and security decrease

Engineering Contradiction:
Improveresource utilizationVSAvoidnetwork isolation
Core Design Contradiction:
Use of energy by moving objectVSObject-affected harmful factors

Solution Approach 1:

The patent introduces another dimension to network isolation by implementing logical segmentation through unique deployment identifiers and customized VNIC configurations. While VMs share the same physical network infrastructure for resource efficiency, the additional dimension of logical addressing and configuration isolation ensures that each deployment remains network-isolated and secure, preventing harmful cross-contamination.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8838756B2Management and implementation of enclosed local networks in a virtual lab
Publication Date: 2014.09.16 VMWARE INC
  • US8838756B2 patent drawing
  • US8838756B2 patent drawing
  • US8838756B2 patent drawing

AI summary

Methods, systems, and computer programs for creating isolated environments that include virtual machines (VM) and networks in a virtual infrastructure are presented. The method includes an operation to define a configuration of a virtual system which includes VMs, virtual network interface cards (VNIC) in the VMs, and configuration local networks (CLN). Further, the method associates each VNIC with one of the CLNs and transmits instructions to the virtual infrastructure for deploying the configuration. Deploying the configuration includes instantiating VMs and CLNs in the virtual infrastructure. Each VM is instantiated in a host monitored by a virtual lab server, and the CLNs are instantiated in the same hosts where the VMs have been instantiated. Only VMs from the configuration can connect to the instantiated CLNs. The method further transmits instructions to the virtual infrastructure to customize the VMs by executing the customization instructions in the guest operating systems of the VMs to configure the VMs' VNICs.