Virtual Service Layer Separating Identity and Locator IPs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current networking solutions face challenges in providing scalable and secure connectivity and security for distributed applications across data centers, clouds, and edge networks, as they rely on complex configurations and rule-based systems that are difficult to manage and scale with the increasing number of endpoints and applications.
Innovation Solution
The implementation of a Virtual Service Layer (VSL) that separates application intelligence from physical networks, using an end-to-end approach to provide contextual reachability and visibility, eliminating the need for traditional middleboxes and enabling zero configuration by moving network functions and intelligence to the edge, thereby simplifying security and connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional middleboxes and rule-based systems are used to provide security and connectivity for distributed applications, then security and connectivity can be established, but device complexity and configuration complexity increase significantly
Solution Approach 1:
The patent extracts the intelligence and control functions from traditional network middleboxes (firewalls, load balancers, service meshes) and consolidates them into a centralized control plane. This extraction eliminates the need for complex local configurations on each network device while maintaining security and connectivity functions through centralized policy management and automated rule generation.
Solution Approach 2:
The patent introduces a centralized control plane as an intermediary between applications and the physical network infrastructure. This control plane automatically generates and manages network policies, service topologies, and security rules, acting as a mediator that simplifies the interaction between applications and complex network devices without requiring manual configuration on each device.
2Reliability
If more middleboxes and service topologies are deployed to manage distributed applications, then security and connectivity coverage improves, but ease of operation and management deteriorates
Solution Approach 1:
The patent implements self-service capabilities where the centralized control plane automatically discovers applications, generates appropriate network policies, and configures network devices without human intervention. The system autonomously manages service topologies, security rules, and connectivity configurations, eliminating the need for manual management of multiple middleboxes while maintaining comprehensive security and connectivity coverage.
Solution Approach 2:
The patent incorporates feedback mechanisms where the control plane continuously monitors application behavior, network traffic patterns, and security events to dynamically adjust and optimize network policies. This feedback loop enables automated management of security and connectivity coverage without requiring manual intervention, as the system adapts to changing conditions based on real-time information.
3Reliability
If application intelligence is maintained at network edges with multiple middleboxes, then contextual security and connectivity can be provided, but productivity and operational efficiency decrease
Solution Approach 1:
The patent segments the network intelligence into two distinct parts: a centralized control plane that handles policy generation, rule management, and high-level decision-making, and lightweight network devices that execute specific policies and provide local enforcement. This segmentation maintains contextual security and connectivity capabilities while improving operational efficiency by eliminating the need to manage complex intelligence at every network edge.
Solution Approach 2:
The centralized control plane serves multiple functions simultaneously: it acts as a service mesh manager, firewall policy generator, load balancer controller, and security event analyzer. This multi-functional approach consolidates what would otherwise require multiple separate middleboxes and management systems, improving productivity by providing comprehensive contextual security and connectivity through a single universal management platform.
Data Source
AI summary
A method of separating identity IPs for identification of applications from the locator IPs for identifying the route is provided. A virtual service layer (VSL) protocol stack uses the IP addresses assigned by network administrators to the application endpoints to support the TCP/IP stack as the identity IP addresses that are not published to the underlay network for routing. On the other hand, the VSL stack uses the IP addresses assigned by the underlay network to the VSL enabled endpoints and VSL enabled routers as the locator IP addresses for routing packets. The VSL stack formats application flow packets with identity headers as identity packet and encapsulates identity packet with the locator header to route the packet. The separation of the identity and locator identifications are used to eliminate the network middleboxes and provide firewall, load balancing, connectivity, SD-WAN, and WAN-optimization, as a part of the communication protocol.


