Virtual Network Switch Control Plane Rule Consistency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual network switches in virtualized computer systems fail to consistently implement network rules, filters, and security features, leading to inconsistent handling of network traffic and potential security and management issues, as they lack features like ACLs, intrusion detection, and flow tables compared to external communication networks.

Innovation Solution

A method is introduced where a configuration signal is sent to a virtual network switch module within a control plane to define network rules, and a packet forwarding module is configured to implement these rules, ensuring that network traffic is processed consistently with external network elements by applying rules, filters, ACLs, mirroring capabilities, and other features defined in a configuration file.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual network switches process network traffic internally without external network elements, then network traffic handling efficiency is improved, but consistency with external network processing and security features is lost

Engineering Contradiction:
Improvenetwork traffic handling efficiencyVSAvoidconsistency with external network processing
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a virtual network switch that acts as an intermediary between virtualized computer systems and external communication networks. This virtual switch receives network traffic from virtual machines, processes it according to rules defined by external network elements, and forwards it appropriately. The virtual switch includes a control plane that communicates with external network elements to obtain configuration rules, ensuring that internal processing remains efficient while external consistency is maintained through rule-based mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual network switch is divided into functional segments: a control plane for receiving and interpreting network rules from external elements, and a data plane for actual packet forwarding and processing. This segmentation allows the control plane to maintain consistency with external networks by receiving updated rules, while the data plane efficiently handles traffic processing locally without requiring constant external intervention.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If virtual network switches operate independently without external network element features, then system simplicity is improved, but security and management capabilities are degraded

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity and management capabilities
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The virtual network switch receives network rules, filters, ACLs, and other security configurations from external network elements before processing traffic. These rules are prepared and loaded into the virtual switch's control plane in advance, enabling the system to maintain simple independent operation while possessing robust security and management capabilities when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The virtual network switch establishes feedback mechanisms with external network elements to receive updated security rules and configuration information. This feedback loop allows the virtual switch to maintain security and management capabilities aligned with external networks while continuing to operate independently for day-to-day traffic processing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9882776B2Methods and apparatus for configuring a virtual network switch
Publication Date: 2018.01.30 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9882776B2 patent drawing
  • US9882776B2 patent drawing
  • US9882776B2 patent drawing

AI summary

In one embodiment, a method includes sending a configuration signal to a virtual network switch module within a control plane of a communications network. The configuration signal is configured to define a first network rule at the virtual network switch module. The method also includes configuring a packet forwarding module such that the packet forwarding module implements a second network rule, and receiving status information from the virtual network switch module and status information from the packet forwarding module. The status information is received via the control plane.