Virtual NIC Network Containers for Multi-Tenant Cloud VMs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud computing environments require tenants to switch between virtual networks by restarting or creating new virtual machines, which is time-consuming and disruptive, as a virtual machine is typically associated with a single virtual network.
Innovation Solution
A virtual machine is configured with a virtual network interface controller (NIC) that supports multiple network containers, allowing it to belong to multiple virtual networks, enabling dynamic switching and pre-provisioning of resources without restarting, using a 'floating' NIC that decouples virtual networking from compute operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a virtual machine is associated with a single virtual network, then network security and isolation are maintained, but tenants cannot switch between virtual networks without restarting or creating new virtual machines
Solution Approach 1:
The patent segments the networking functionality by introducing network containers that encapsulate virtual network interface controllers (VNICs) and their associated networking policies. Each network container can be independently associated with different virtual networks, allowing the virtual machine to access multiple virtual networks without compromising security or isolation. This segmentation enables tenants to switch between virtual networks by activating different network containers rather than restarting the entire virtual machine.
2Ease of operation
If tenants switch between virtual networks by restarting or creating new virtual machines, then network isolation is maintained, but operational downtime and resource waste occur
Solution Approach 1:
The patent implements preliminary action by pre-configuring multiple network containers within a single virtual machine, each associated with different virtual networks. These network containers are prepared in advance and can be activated on-demand without requiring virtual machine restarts. This allows tenants to switch between virtual networks instantly by selecting the appropriate network container, eliminating operational downtime and maintaining continuous service availability.
3Reliability
If multiple virtual machines are created to support multiple virtual networks, then network isolation is ensured, but resource utilization efficiency decreases
Solution Approach 1:
The patent applies universality by enabling a single virtual machine to perform multiple networking functions through network containers. Each network container provides a virtual network interface controller with its own networking policies and associations, allowing the virtual machine to access multiple virtual networks simultaneously. This multi-functionality maintains network isolation through policy enforcement while significantly improving resource utilization by eliminating the need for separate virtual machines for each virtual network.
4Adaptability or versatility
If network containers are introduced to enable multi-network support, then flexibility and rapid switching are improved, but system complexity increases
Solution Approach 1:
The patent introduces network containers as intermediary components between the virtual machine and virtual networks. These containers encapsulate virtual network interface controllers and their associated networking policies, acting as mediators that manage the complexity of multi-network support. The network containers provide a standardized interface for network switching while handling the underlying complexity of policy enforcement and network associations, thereby improving flexibility without significantly increasing the perceived system complexity for users.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A virtual network interface controller (NIC) associated with a virtual machine in a cloud computing network is configured to support one or more network containers that encapsulate networking configuration data and policies that are applicable to a specific discrete computing workload to thereby enable the virtual machine to simultaneously belong to multiple virtual networks using the single NIC. The network containers supported by the NIC can be associated with a single tenant to enable additional flexibility such quickly switching between virtual networks and support pre-provisioning of additional computing resources with associated networking policies for rapid deployment. The network containers can also be respectively associated with different tenants so that the single NIC can support multi-tenant services on the same virtual machine.