Virtualized Network Gateway for Overlay Traffic Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud networking technologies face limitations in scalability, performance, and complexity, particularly in public and private clouds, where hardware-based solutions for traffic processing are CPU-intensive and lack advanced networking features, and managing overlay networks across different providers is challenging.
Innovation Solution
The implementation of a virtualized environment with a physical underlay network and multiple overlay networks, including a 'superlay' network that separates security and networking elements, allowing encapsulation and decapsulation of traffic within the execution environment of virtualized applications, enabling advanced networking features like VLAN tags and L2 functionality without relying on hardware-based solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If hardware-based solutions (SmartNIC, ToR Switches) are used for tenant separation and overlay encapsulation, then CPU efficiency is improved, but device complexity and automation system complexity increase
Solution Approach 1:
The patent introduces a gateway device as an intermediary component that mediates between the underlay network and overlay networks. This gateway handles encapsulation/decapsulation and tenant separation, acting as a middle layer that simplifies the overall system architecture while maintaining hardware acceleration benefits. The gateway serves as a controlled intermediary that manages the complexity rather than distributing it across multiple components.
2Productivity
If hardware-based solutions are used for overlay networking, then CPU efficiency is improved, but the range of encapsulations and routing features is limited
Solution Approach 1:
The patent segments the networking functionality into distinct layers: the underlay network handles basic transport, while multiple overlay networks provide specialized routing and encapsulation capabilities. The gateway device further segments functionality by handling L3 routing separately from L2 overlay operations. This segmentation allows each component to be optimized independently, enabling hardware acceleration for common cases while preserving software-based flexibility for advanced features.
Solution Approach 2:
The patent adds an additional networking dimension by implementing overlay networks that operate above the basic L3 underlay. This creates a multi-layered network architecture where L2 overlay networks can provide advanced routing, VLAN tagging, and encapsulation capabilities that complement the hardware-accelerated L3 underlay, effectively adding a new dimension of networking functionality rather than being constrained to a single layer.
3Adaptability or versatility
If virtual router (vRouter) in hypervisor is used for tenant separation and overlay encapsulation, then networking options and L2 functionality are improved, but CPU overhead increases significantly
Solution Approach 1:
The patent extracts the overlay encapsulation and tenant separation functionality from the hypervisor/vRouter layer and places it in a dedicated gateway device. This extraction removes the CPU-intensive networking operations from the virtualization layer, allowing the hypervisor to focus on VM management while the gateway handles packet processing. The gateway can then leverage hardware acceleration capabilities to perform these functions with minimal CPU overhead.
Solution Approach 2:
The patent replaces the software-based vRouter processing in the hypervisor with a hybrid approach using a gateway device that combines hardware acceleration (for encapsulation/decapsulation) with controlled software processing. This substitution eliminates the need for the hypervisor to perform CPU-intensive packet processing, replacing it with hardware-accelerated operations in the gateway while preserving the flexibility of software-based networking options.
4Ease of manufacture
If direct use of VLAN tags in underlay network is used for overlay networking, then implementation simplicity is improved, but scalability is limited due to 4096 VLAN limit and performance concerns with large broadcast domains
Solution Approach 1:
The patent implements nested networking where L2 overlay networks are nested within the L3 underlay network. The gateway device creates virtual network interfaces that nest overlay network traffic within underlay transport, allowing multiple overlay networks to be hierarchical layers. This nesting enables scalability beyond VLAN limits by using L3 routing in the underlay to carry L2 overlay traffic, effectively creating a nested architecture where each layer operates independently with its own addressing and routing rules.
Data Source
AI summary
Traffic is processed in a virtualised environment comprising: (i) a physical underlay network; (ii) a first overlay network (an overlay of the physical underlay network and associated with a first set of network addresses, IP1); (iii) a second overlay network (an overlay of the first overlay network and associated with a second set of network addresses, IP2); and (iv) virtualised applications each having an execution environment and being associated with at least one network address in each of the first and second sets of network addresses, IP1 and IP2. In the execution environment of a first virtualised application: (i) traffic communicated from the first virtualised application to the first overlay network is encapsulated; and/or (ii) traffic communicated from the first overlay network to the first virtualised application is decapsulated. Tenant separation processing is performed outside the execution environments of the virtualised applications.


