Virtual Service Layer Separating Identity and Locator IPs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current networking solutions face challenges in providing scalable and secure connectivity and security for distributed applications across data centers, clouds, and edge networks, as they rely on complex configurations and rule-based systems that are difficult to manage and scale with the increasing number of endpoints and applications.

Innovation Solution

The implementation of a Virtual Service Layer (VSL) that separates application intelligence from physical networks, using an end-to-end approach to provide contextual reachability and visibility, eliminating the need for traditional middleboxes and enabling zero configuration by moving network functions and intelligence to the edge, thereby simplifying security and connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional middleboxes and rule-based systems are used to provide security and connectivity for distributed applications, then security and connectivity can be established, but device complexity and configuration complexity increase significantly

Engineering Contradiction:
Improvesecurity and connectivityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the intelligence and control functions from traditional network middleboxes (firewalls, load balancers, service meshes) and consolidates them into a centralized control plane. This extraction eliminates the need for complex local configurations on each network device while maintaining security and connectivity functions through centralized policy management and automated rule generation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a centralized control plane as an intermediary between applications and the physical network infrastructure. This control plane automatically generates and manages network policies, service topologies, and security rules, acting as a mediator that simplifies the interaction between applications and complex network devices without requiring manual configuration on each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If more middleboxes and service topologies are deployed to manage distributed applications, then security and connectivity coverage improves, but ease of operation and management deteriorates

Engineering Contradiction:
Improvesecurity and connectivity coverageVSAvoidmanagement ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service capabilities where the centralized control plane automatically discovers applications, generates appropriate network policies, and configures network devices without human intervention. The system autonomously manages service topologies, security rules, and connectivity configurations, eliminating the need for manual management of multiple middleboxes while maintaining comprehensive security and connectivity coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the control plane continuously monitors application behavior, network traffic patterns, and security events to dynamically adjust and optimize network policies. This feedback loop enables automated management of security and connectivity coverage without requiring manual intervention, as the system adapts to changing conditions based on real-time information.

Inventive Principle:
Principle #23Feedback

3Reliability

If application intelligence is maintained at network edges with multiple middleboxes, then contextual security and connectivity can be provided, but productivity and operational efficiency decrease

Engineering Contradiction:
Improvecontextual security and connectivityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network intelligence into two distinct parts: a centralized control plane that handles policy generation, rule management, and high-level decision-making, and lightweight network devices that execute specific policies and provide local enforcement. This segmentation maintains contextual security and connectivity capabilities while improving operational efficiency by eliminating the need to manage complex intelligence at every network edge.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The centralized control plane serves multiple functions simultaneously: it acts as a service mesh manager, firewall policy generator, load balancer controller, and security event analyzer. This multi-functional approach consolidates what would otherwise require multiple separate middleboxes and management systems, improving productivity by providing comprehensive contextual security and connectivity through a single universal management platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12101296B2Intelligent service layer for separating application from physical networks and extending service layer intelligence over IP across the internet, cloud, and edge networks
Publication Date: 2024.09.24 VEMULPALI SRI RAM KISHORE
  • US12101296B2 patent drawing
  • US12101296B2 patent drawing
  • US12101296B2 patent drawing

AI summary

A method of separating identity IPs for identification of applications from the locator IPs for identifying the route is provided. A virtual service layer (VSL) protocol stack uses the IP addresses assigned by network administrators to the application endpoints to support the TCP/IP stack as the identity IP addresses that are not published to the underlay network for routing. On the other hand, the VSL stack uses the IP addresses assigned by the underlay network to the VSL enabled endpoints and VSL enabled routers as the locator IP addresses for routing packets. The VSL stack formats application flow packets with identity headers as identity packet and encapsulates identity packet with the locator header to route the packet. The separation of the identity and locator identifications are used to eliminate the network middleboxes and provide firewall, load balancing, connectivity, SD-WAN, and WAN-optimization, as a part of the communication protocol.