Virtualized Network Gateway for Overlay Traffic Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud networking technologies face limitations in scalability, performance, and complexity, particularly in public and private clouds, where hardware-based solutions for traffic processing are CPU-intensive and lack advanced networking features, and managing overlay networks across different providers is challenging.

Innovation Solution

The implementation of a virtualized environment with a physical underlay network and multiple overlay networks, including a 'superlay' network that separates security and networking elements, allowing encapsulation and decapsulation of traffic within the execution environment of virtualized applications, enabling advanced networking features like VLAN tags and L2 functionality without relying on hardware-based solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hardware-based solutions (SmartNIC, ToR Switches) are used for tenant separation and overlay encapsulation, then CPU efficiency is improved, but device complexity and automation system complexity increase

Engineering Contradiction:
ImproveCPU efficiencyVSAvoidautomation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary component that mediates between the underlay network and overlay networks. This gateway handles encapsulation/decapsulation and tenant separation, acting as a middle layer that simplifies the overall system architecture while maintaining hardware acceleration benefits. The gateway serves as a controlled intermediary that manages the complexity rather than distributing it across multiple components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If hardware-based solutions are used for overlay networking, then CPU efficiency is improved, but the range of encapsulations and routing features is limited

Engineering Contradiction:
ImproveCPU efficiencyVSAvoidnetworking features range
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the networking functionality into distinct layers: the underlay network handles basic transport, while multiple overlay networks provide specialized routing and encapsulation capabilities. The gateway device further segments functionality by handling L3 routing separately from L2 overlay operations. This segmentation allows each component to be optimized independently, enabling hardware acceleration for common cases while preserving software-based flexibility for advanced features.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds an additional networking dimension by implementing overlay networks that operate above the basic L3 underlay. This creates a multi-layered network architecture where L2 overlay networks can provide advanced routing, VLAN tagging, and encapsulation capabilities that complement the hardware-accelerated L3 underlay, effectively adding a new dimension of networking functionality rather than being constrained to a single layer.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If virtual router (vRouter) in hypervisor is used for tenant separation and overlay encapsulation, then networking options and L2 functionality are improved, but CPU overhead increases significantly

Engineering Contradiction:
Improvenetworking optionsVSAvoidCPU overhead
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the overlay encapsulation and tenant separation functionality from the hypervisor/vRouter layer and places it in a dedicated gateway device. This extraction removes the CPU-intensive networking operations from the virtualization layer, allowing the hypervisor to focus on VM management while the gateway handles packet processing. The gateway can then leverage hardware acceleration capabilities to perform these functions with minimal CPU overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the software-based vRouter processing in the hypervisor with a hybrid approach using a gateway device that combines hardware acceleration (for encapsulation/decapsulation) with controlled software processing. This substitution eliminates the need for the hypervisor to perform CPU-intensive packet processing, replacing it with hardware-accelerated operations in the gateway while preserving the flexibility of software-based networking options.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of manufacture

If direct use of VLAN tags in underlay network is used for overlay networking, then implementation simplicity is improved, but scalability is limited due to 4096 VLAN limit and performance concerns with large broadcast domains

Engineering Contradiction:
Improveimplementation simplicityVSAvoidscalability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements nested networking where L2 overlay networks are nested within the L3 underlay network. The gateway device creates virtual network interfaces that nest overlay network traffic within underlay transport, allowing multiple overlay networks to be hierarchical layers. This nesting enables scalability beyond VLAN limits by using L3 routing in the underlay to carry L2 overlay traffic, effectively creating a nested architecture where each layer operates independently with its own addressing and routing rules.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11811560B2Processing traffic in a virtualised environment
Publication Date: 2023.11.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11811560B2 patent drawing
  • US11811560B2 patent drawing
  • US11811560B2 patent drawing

AI summary

Traffic is processed in a virtualised environment comprising: (i) a physical underlay network; (ii) a first overlay network (an overlay of the physical underlay network and associated with a first set of network addresses, IP1); (iii) a second overlay network (an overlay of the first overlay network and associated with a second set of network addresses, IP2); and (iv) virtualised applications each having an execution environment and being associated with at least one network address in each of the first and second sets of network addresses, IP1 and IP2. In the execution environment of a first virtualised application: (i) traffic communicated from the first virtualised application to the first overlay network is encapsulated; and/or (ii) traffic communicated from the first overlay network to the first virtualised application is decapsulated. Tenant separation processing is performed outside the execution environments of the virtualised applications.