Virtual Network Nodes for Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network provisioning methods lack effective traffic isolation and fine-grained resource control between customers, as services for different customers often share the same hardware resources, leading to potential interference and failure risks.

Innovation Solution

The technique involves virtualizing physical network devices into multiple virtual nodes, using an abstracted fabric interface to create Layer-2 circuits between virtual client and core nodes, providing separate logical networks for each customer, thereby isolating traffic and resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple customers share the same hardware resources, then resource utilization is improved, but traffic isolation and reliability deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidtraffic isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing a single physical network device into multiple virtual network devices (virtual routers, virtual switches, virtual firewalls). Each virtual device is assigned to a specific customer, creating isolated logical networks while sharing the underlying physical hardware. This segmentation enables both high resource utilization and complete traffic isolation between customers.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If hardware resources are shared among customers, then device complexity is reduced, but fine-grained resource control deteriorates

Engineering Contradiction:
Improvehardware infrastructureVSAvoidresource control
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic resource allocation through virtualization, where hardware resources can be dynamically assigned and reassigned to different virtual devices based on customer needs. The system allows fine-grained control over bandwidth, processing power, and memory allocation for each virtual device, enabling adaptable resource management without increasing physical hardware complexity.

Inventive Principle:
Principle #15Dynamics

3Reliability

If virtual nodes are isolated separately, then traffic isolation is improved, but network connectivity deteriorates

Engineering Contradiction:
Improvenetwork isolationVSAvoidend-to-end connectivity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces virtual bridges and routing protocols as intermediaries between isolated virtual devices. These intermediaries enable controlled communication between virtual devices of the same customer while maintaining isolation from other customers. The system implements end-to-end connectivity through virtual network paths that traverse multiple virtual devices, with the physical network infrastructure serving as an intermediary transport layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3595245B1Network as a service using virtual nodes
Publication Date: 2021.06.16 JUNIPER NETWORKS INC
  • EP3595245B1 patent drawingFigure 1
  • EP3595245B1 patent drawingFigure 2
  • EP3595245B1 patent drawingFigure 3

AI summary

The techniques describe a network device comprising one or more processors configured to: receive configuration data configuring a plurality of virtual network nodes, wherein the configuration data configures a virtual client node including a corresponding line card having a port connected to a first customer network device, and configures a virtual core node including a corresponding line card having a port connected to a core network; provision a layer-2 (L2) circuit that includes, as an access interface, an interface logically connecting the virtual client node and virtual core node, wherein the L2 circuit provides connectivity between the virtual client node and a remote virtual client node; and forward, via the L2 circuit, packets between the virtual client node and the remote virtual client node to realize a logical network between the first customer network device and a second customer network device connected to the remote virtual PE node.