Virtual Network Interface Application Traffic Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network appliances that implement Quality of Service (QoS) policies through deep packet inspection incur performance overhead and increased costs due to the need for physical resources, which is not efficiently managed in cloud-based applications.

Innovation Solution

A method and system that segregate network traffic based on applications using a virtual network interface, associating guest data packets with respective applications and applying QoS policies through application port interfaces, eliminating the need for physical appliances by leveraging virtual computing elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical network appliances are used to implement QoS policies through deep packet inspection, then network traffic prioritization is achieved, but performance overhead and operational costs increase

Engineering Contradiction:
ImproveQoS policy implementationVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates a virtual copy of network appliance functionality by implementing QoS policies through software-based deep packet inspection within the virtual network interface card (VNIC) driver. This virtual implementation replicates the packet inspection and prioritization capabilities of physical appliances without requiring dedicated hardware, thereby reducing performance overhead while maintaining QoS reliability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent merges the QoS policy implementation functionality directly into the virtual network interface card driver, combining previously separate functions (packet inspection, policy application, and network interface operations) into a single integrated software component. This consolidation eliminates the need for separate physical network appliances and reduces operational costs while maintaining effective traffic prioritization

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If physical network appliances are deployed for deep packet inspection, then application-based traffic segregation is achieved, but device complexity and operational costs increase

Engineering Contradiction:
Improveapplication-based traffic segregationVSAvoidphysical appliance deployment
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual representation of network appliance functionality within the VNIC driver, implementing deep packet inspection and application-based traffic segregation through software. This virtual copy provides the same adaptability and versatility in traffic management without the complexity of physical appliance deployment, maintenance, and integration

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual network interface card driver serves multiple functions simultaneously: it acts as a network interface driver, performs deep packet inspection, implements QoS policies, and enables application-based traffic segregation. This multi-functional approach replaces multiple specialized physical devices with a single universal software component, reducing device complexity while maintaining versatility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11115337B2Network traffic segregation on an application basis in a virtual computing environment
Publication Date: 2021.09.07 VMWARE INC
  • US11115337B2 patent drawing
  • US11115337B2 patent drawing
  • US11115337B2 patent drawing

AI summary

The technology disclosed herein enables segregation of network traffic on an application basis. In a particular embodiment, a method is performed in a virtual network interface for a first guest Operating System (OS) executing on a host and includes receiving guest data packets from the first guest OS. The method further includes associating the guest data packets with respective ones of a plurality of applications executing within the first guest OS and separating the guest data packets into respective ones of a plurality of application port interfaces each corresponding to at least one of the plurality of applications. The method also includes passing the guest data packets to a host network interface using the plurality of application port interfaces.