Virtual Partition Isolation for Secure Data Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data transfer technologies lack secure and reliable methods for guaranteed bandwidth and latency in virtual networks, especially for sensitive information, and are vulnerable to attacks and resource overflows.
Innovation Solution
A system and method utilizing virtual partitions with switch/router devices configured to provide secure, deterministic connections using OpenFlow SDN protocol, ensuring secure prioritization, routing, and bandwidth control, with separate buffers and VLANs to isolate and protect virtual partition traffic from other traffic, preventing resource overflows and maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If shared network infrastructure is used to provide multiple wireless service providers access, then network resource utilization is improved, but security and reliability of data transfer deteriorates
Solution Approach 1:
The patent segments the shared network infrastructure into isolated virtual networks using VLANs and virtual partitions. Each service provider gets a dedicated virtual network segment that is logically separated from others, ensuring that while physical resources are shared, security and reliability are maintained through virtual isolation boundaries that prevent cross-contamination of traffic and attacks.
Solution Approach 2:
The patent introduces intermediary control mechanisms including OpenFlow SDN controllers and policy enforcement points that mediate between the shared physical infrastructure and multiple service providers. These intermediaries enforce security policies, control traffic flow, and manage resource allocation, thereby maintaining security and reliability while enabling shared resource utilization.
2Reliability
If bandwidth and latency guarantees are provided for secure connections, then service reliability is improved, but network complexity and resource management difficulty worsens
Solution Approach 1:
The patent implements universal resource management mechanisms through OpenFlow SDN controllers that can serve multiple service providers simultaneously with a single centralized control system. The same control infrastructure provides bandwidth guarantees, latency control, and security policies across all virtual networks, reducing overall complexity compared to managing separate systems for each provider while maintaining service reliability guarantees.
Solution Approach 2:
The patent changes network parameters dynamically through SDN control, allowing bandwidth allocations, latency constraints, and routing policies to be adjusted programmatically without manual reconfiguration. This enables reliable service guarantees to be implemented through software-controlled parameter changes rather than complex hardware configurations, simplifying resource management while maintaining service quality.
3Reliability
If virtual partitions with separate buffers and VLANs are implemented, then security and isolation are improved, but device complexity and configuration difficulty worsens
Solution Approach 1:
The patent implements self-service automation where the OpenFlow SDN controllers automatically configure VLANs, virtual partitions, and buffer allocations based on service provider requirements. The system performs self-provisioning and auto-configuration, reducing manual configuration complexity while maintaining strong security isolation. The controllers automatically generate the necessary network policies and enforce them across the infrastructure without requiring manual intervention for each virtual network setup.
Data Source
Figure 1
AI summary
A data transfer system includes a set of switch and/or router devices (104B, 104E, 104F), each said device in the set being a layer 1, 2 and/or 3 device of OSI seven-layer model and being configured, in use, to transfer data, directly or indirectly, between a plurality of computing devices (102A, 102B). Each said switch or router device in the set is configured to provide a virtual partition (VP), wherein only data designated as virtual partition data is transferrable to another said device in the set via the virtual partition.