Virtual Network Nodes for Traffic Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network provisioning methods lack effective traffic isolation and fine-grained resource control between customers, as services for different customers often share the same hardware resources, leading to potential interference and failure risks.
Innovation Solution
The technique involves virtualizing physical network devices into multiple virtual nodes, using an abstracted fabric interface to create Layer-2 circuits between virtual client and core nodes, providing separate logical networks for each customer, thereby isolating traffic and resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple customers share the same hardware resources, then resource utilization is improved, but traffic isolation and reliability deteriorate
Solution Approach 1:
The patent applies segmentation by dividing a single physical network device into multiple virtual network devices (virtual routers, virtual switches, virtual firewalls). Each virtual device is assigned to a specific customer, creating isolated logical networks while sharing the underlying physical hardware. This segmentation enables both high resource utilization and complete traffic isolation between customers.
2Device complexity
If hardware resources are shared among customers, then device complexity is reduced, but fine-grained resource control deteriorates
Solution Approach 1:
The patent implements dynamic resource allocation through virtualization, where hardware resources can be dynamically assigned and reassigned to different virtual devices based on customer needs. The system allows fine-grained control over bandwidth, processing power, and memory allocation for each virtual device, enabling adaptable resource management without increasing physical hardware complexity.
3Reliability
If virtual nodes are isolated separately, then traffic isolation is improved, but network connectivity deteriorates
Solution Approach 1:
The patent introduces virtual bridges and routing protocols as intermediaries between isolated virtual devices. These intermediaries enable controlled communication between virtual devices of the same customer while maintaining isolation from other customers. The system implements end-to-end connectivity through virtual network paths that traverse multiple virtual devices, with the physical network infrastructure serving as an intermediary transport layer.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The techniques describe a network device comprising one or more processors configured to: receive configuration data configuring a plurality of virtual network nodes, wherein the configuration data configures a virtual client node including a corresponding line card having a port connected to a first customer network device, and configures a virtual core node including a corresponding line card having a port connected to a core network; provision a layer-2 (L2) circuit that includes, as an access interface, an interface logically connecting the virtual client node and virtual core node, wherein the L2 circuit provides connectivity between the virtual client node and a remote virtual client node; and forward, via the L2 circuit, packets between the virtual client node and the remote virtual client node to realize a logical network between the first customer network device and a second customer network device connected to the remote virtual PE node.