Virtual NIC Bypass for OpenFlow Switch Data Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When an Open Flow switch (OFS) is connected to a network interface, it intercepts all data, preventing other services or software from receiving and processing data, leading to normal operation disruptions.

Innovation Solution

A communication path switching apparatus that connects the OFS to a virtual NIC, allowing the OFS to forward packets based on flow entries set by the Open Flow controller (OFC), with the virtual NIC forwarding data to services or software through sockets, thereby bypassing the OFS's direct connection to the network interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If an Open Flow switch (OFS) is connected to a network interface to intercept and control all data, then path control and load distribution capabilities are improved, but other services or software cannot receive and process data, causing operation disruptions

Engineering Contradiction:
Improvepath control capabilityVSAvoidservice operation continuity
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent segments the network interface into multiple virtual interfaces (virtual NICs), each dedicated to specific services or software. This allows the OFS to control traffic to certain virtual interfaces while other virtual interfaces remain accessible to services that should not be intercepted, thus resolving the contradiction between automation and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtual network interface card (virtual NIC) as an intermediary between the physical network interface and the services/software. The virtual NIC acts as a mediator that can be selectively connected to the OFS, allowing controlled traffic interception while maintaining direct access paths for services that should bypass the OFS, thereby preserving service operation continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the OFS is connected directly to the network interface to perform centralized control, then network optimization and cost reduction are improved, but services or software that previously accessed the network interface directly cannot operate normally

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidservice compatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent divides the network interface functionality into multiple virtual interfaces, allowing different services to be assigned to different virtual NICs. This segmentation enables the system to maintain high network efficiency through OFS control for some services while preserving direct access for others, thus achieving both productivity and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual network interface card serves multiple functions: it can be connected to the OFS for controlled services, or disconnected to provide direct access for services requiring bypass. This multi-functionality allows a single virtual NIC design to accommodate both centralized control needs and direct access requirements, resolving the contradiction between network efficiency and service compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3224997B1Communication path switching apparatus, method for controlling communication path switching apparatus, and computer program product
Publication Date: 2020.02.05 RICOH CO LTD
  • EP3224997B1 patent drawingFigure 1~2A
  • EP3224997B1 patent drawingFigure 2B~3
  • EP3224997B1 patent drawingFigure 4

AI summary

A communication path switching apparatus includes an application unit that executes a certain function of performing wireless communication with another communication apparatus, a data switching unit that forwards data for causing the application unit to execute the certain function, a control unit that makes the setting for causing the data switching unit to forward the data, and a virtual device unit that forwards the data forwarded from the data switching unit to the application unit based on the setting made by the control unit.