Virtual Links for Network Isolation Without VLAN Complexity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network technologies face limitations in restricting communication between different network nodes, particularly in multitenancy scenarios where overlapping IP address ranges are used, and in isolating traffic between various applications within an enterprise, without the need for extensive reconfiguration of VLANs or physical infrastructure.

Innovation Solution

The implementation of virtual links, which establish a layer three tunnel to carry layer two and three traffic between network appliances, creating a private overlay topology without modifying the underlying infrastructure, allowing for secure and isolated communication between specific nodes or applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VLANs are used to restrict communication at layer two, then communication isolation between different network nodes is improved, but device complexity and reconfiguration requirements increase

Engineering Contradiction:
Improvecommunication isolationVSAvoidVLAN configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces virtual machine interfaces and virtual switches as intermediary layers between physical network infrastructure and applications. These intermediaries handle communication isolation at the virtualization layer, eliminating the need for complex VLAN configurations on physical switches while maintaining reliable communication isolation between different virtual machines and network segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from traditional layer two VLAN-based isolation to a multi-dimensional isolation approach that operates at multiple layers including virtual machine interfaces, virtual switches, and overlay networks. This dimensional shift allows communication isolation to be implemented through virtualization abstractions rather than physical network layer configurations, reducing device complexity while maintaining isolation effectiveness.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If VLANs are configured to isolate traffic, then communication security is improved, but ease of operation and scalability deteriorate

Engineering Contradiction:
Improvecommunication securityVSAvoidnetwork reconfiguration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the virtualization management system automatically handles network isolation configuration. When virtual machines are created, moved, or modified, the system automatically configures appropriate virtual switches, interfaces, and overlay network parameters without requiring manual VLAN reconfiguration. This maintains communication security while dramatically improving ease of operation and scalability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces dynamic network isolation that can be adjusted in real-time based on workload requirements. Virtual machine interfaces and virtual switches can be dynamically created, modified, or removed without physical network reconfiguration. This dynamic approach maintains security isolation while allowing flexible operational changes and scaling as needed.

Inventive Principle:
Principle #15Dynamics

3Reliability

If physical infrastructure is modified to restrict communication, then network isolation is improved, but loss of time and productivity increase

Engineering Contradiction:
Improvenetwork isolationVSAvoidreconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-configures virtual network interfaces, virtual switches, and overlay network parameters during virtual machine provisioning or migration preparation. This preliminary configuration ensures that when virtual machines need to be moved or isolated, the network infrastructure is already prepared, eliminating the need for time-consuming physical reconfiguration while maintaining effective network isolation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces mechanical physical network reconfiguration with software-based virtual network configuration. Instead of physically moving cables, reconfiguring switches, or modifying physical infrastructure to achieve network isolation, the system uses virtual machine interfaces, virtual switches, and overlay networks that can be configured and modified through software, dramatically reducing reconfiguration time while maintaining isolation effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9967346B2Passing data over virtual links
Publication Date: 2018.05.08 CISCO TECHNOLOGY INC
  • US9967346B2 patent drawing
  • US9967346B2 patent drawing
  • US9967346B2 patent drawing

AI summary

Passing data over virtual links is disclosed, including: encapsulating a layer three data packet as an inner payload of a network data packet; and generating an outer header of the network data packet with a layer two header and a layer three header, wherein the network data packet is configured to communicate over a virtual link between a first interface of a first network appliance and a first interface of a second network appliance.