Virtual NIC for Non-Native App Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, maximizing the number of application instances on shared compute resources is challenging due to conflicts between the need for compute power and the complexity and cost of adding multiple OS instances, which can lead to inefficiencies in hosting non-native applications without requiring additional virtual servers.

Innovation Solution

The implementation of virtual containers with dynamic virtual internet protocol addresses (DVIPAs) and virtual network interface cards (VNICs) that translate network communication, allowing non-native applications to run without additional virtual machines, thereby extending network virtualization capabilities and isolating IP addresses for efficient resource utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple OS instances are added to host non-native applications, then application hosting capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveapplication hosting capabilityVSAvoidOS instance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual container as an intermediary layer between the host OS and non-native applications. This virtual container provides a customized OS environment for non-native applications without requiring separate physical or virtual server instances, thereby resolving the contradiction by enabling application hosting capability while avoiding the complexity of multiple OS instances

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the OS functionality into a base OS and multiple virtual containers. Each virtual container can be independently configured and managed, allowing the system to host different types of applications (native and non-native) on a single server without requiring separate OS instances for each application type, thus reducing overall system complexity

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If additional virtual servers are deployed for non-native applications, then application compatibility is improved, but resource efficiency deteriorates

Engineering Contradiction:
Improveapplication compatibilityVSAvoidresource efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The virtual container system provides universal functionality by enabling a single server to host both native and non-native applications through shared compute resources. The virtual container acts as a multi-functional platform that can accommodate different application types without requiring separate dedicated servers, thereby improving resource efficiency while maintaining application compatibility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The virtual container serves as an intermediary that enables non-native applications to run on the host OS without requiring separate virtual servers. This intermediary layer provides the necessary OS compatibility and isolation, allowing diverse applications to share physical hardware resources efficiently, thus resolving the contradiction between application compatibility and resource efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If virtual containers with VNICs are created for non-native applications, then network virtualization capability is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork virtualization capabilityVSAvoidnetwork interface complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The virtual NIC (VNIC) acts as an intermediary between the virtual container and the physical network infrastructure. It provides network virtualization capabilities by enabling communication between virtual containers and external networks while abstracting the underlying physical hardware complexity, thus improving network virtualization capability without proportionally increasing observable system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates virtual copies of network interface functionality within the virtual container environment. Instead of requiring physical network hardware for each application, the system uses virtualized network interfaces that replicate necessary network functions, thereby enhancing network virtualization capability while reducing physical device complexity

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11301279B2Associating virtual IP address of virtual server with appropriate operating system in server cluster
Publication Date: 2022.04.12 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11301279B2 patent drawing
  • US11301279B2 patent drawing
  • US11301279B2 patent drawing

AI summary

According to one or more embodiments, a computer implemented method includes receiving, by an operating system of a computer server, a request to execute an instance of a computer application. The method further includes deploying a virtual container for the instance of the computer application, the virtual container is allocated a dynamic virtual interne protocol address (DVIPA). The method further includes instantiating an application instance of the computer application in the virtual container. The method further includes, based on a determination that the computer application is a non-native application for the operating system, creating for the virtual container, a virtual network interface card (NIC) that translates network communication between the application instance and a physical NIC of the computer server. The method further includes selecting, by the virtual NIC, a communication protocol stack, from multiple communication protocol stacks, to bind the application instance for transferring the network communication.