Virtual NIC for Non-Native App Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, maximizing the number of application instances on shared compute resources is challenging due to conflicts between the need for compute power and the complexity and cost of adding multiple OS instances, which can lead to inefficiencies in hosting non-native applications without requiring additional virtual servers.
Innovation Solution
The implementation of virtual containers with dynamic virtual internet protocol addresses (DVIPAs) and virtual network interface cards (VNICs) that translate network communication, allowing non-native applications to run without additional virtual machines, thereby extending network virtualization capabilities and isolating IP addresses for efficient resource utilization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple OS instances are added to host non-native applications, then application hosting capability is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces a virtual container as an intermediary layer between the host OS and non-native applications. This virtual container provides a customized OS environment for non-native applications without requiring separate physical or virtual server instances, thereby resolving the contradiction by enabling application hosting capability while avoiding the complexity of multiple OS instances
Solution Approach 2:
The patent segments the OS functionality into a base OS and multiple virtual containers. Each virtual container can be independently configured and managed, allowing the system to host different types of applications (native and non-native) on a single server without requiring separate OS instances for each application type, thus reducing overall system complexity
2Adaptability or versatility
If additional virtual servers are deployed for non-native applications, then application compatibility is improved, but resource efficiency deteriorates
Solution Approach 1:
The virtual container system provides universal functionality by enabling a single server to host both native and non-native applications through shared compute resources. The virtual container acts as a multi-functional platform that can accommodate different application types without requiring separate dedicated servers, thereby improving resource efficiency while maintaining application compatibility
Solution Approach 2:
The virtual container serves as an intermediary that enables non-native applications to run on the host OS without requiring separate virtual servers. This intermediary layer provides the necessary OS compatibility and isolation, allowing diverse applications to share physical hardware resources efficiently, thus resolving the contradiction between application compatibility and resource efficiency
3Adaptability or versatility
If virtual containers with VNICs are created for non-native applications, then network virtualization capability is improved, but device complexity increases
Solution Approach 1:
The virtual NIC (VNIC) acts as an intermediary between the virtual container and the physical network infrastructure. It provides network virtualization capabilities by enabling communication between virtual containers and external networks while abstracting the underlying physical hardware complexity, thus improving network virtualization capability without proportionally increasing observable system complexity
Solution Approach 2:
The system creates virtual copies of network interface functionality within the virtual container environment. Instead of requiring physical network hardware for each application, the system uses virtualized network interfaces that replicate necessary network functions, thereby enhancing network virtualization capability while reducing physical device complexity
Data Source
AI summary
According to one or more embodiments, a computer implemented method includes receiving, by an operating system of a computer server, a request to execute an instance of a computer application. The method further includes deploying a virtual container for the instance of the computer application, the virtual container is allocated a dynamic virtual interne protocol address (DVIPA). The method further includes instantiating an application instance of the computer application in the virtual container. The method further includes, based on a determination that the computer application is a non-native application for the operating system, creating for the virtual container, a virtual network interface card (NIC) that translates network communication between the application instance and a physical NIC of the computer server. The method further includes selecting, by the virtual NIC, a communication protocol stack, from multiple communication protocol stacks, to bind the application instance for transferring the network communication.


