Virtual Switch Address Translation for Cloud Load Balancing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The stability and security risks associated with the Tunnel Through Module (TTM) in public cloud load balance products hinder the evolution of computing node topologies and introduce security vulnerabilities, affecting the integrity and performance of the kernel.
Innovation Solution
A method and apparatus for translating virtual MAC and IP addresses to real MAC and IP addresses using a pre-configured address mapping relationship, allowing data packets to be processed by a virtual switch without relying on the TTM, thereby facilitating the evolution of computing node topologies and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TTM module is used for address translation in data plane, then source address information can be made visible to users, but stability risks increase and topology evolution is hindered
Solution Approach 1:
The patent extracts the address translation function from the TTM module and relocates it to the virtual switch. This separation removes the harmful dependency on TTM while preserving the essential address translation capability, thereby improving system stability without hindering topology evolution.
Solution Approach 2:
The virtual switch serves as an intermediary component that performs address translation between virtual and physical addresses. This mediator approach eliminates the need for TTM's custom TCP/IP option processing while maintaining the address visibility function, resolving the contradiction between stability and adaptability.
2Adaptability or versatility
If TTM module processes custom TCP/IP options for address translation, then load balance functionality is achieved, but security risks increase due to external attack vulnerabilities
Solution Approach 1:
The patent extracts the address translation logic from TTM's custom TCP/IP option processing and implements it directly in the virtual switch's data plane. This eliminates the security vulnerability associated with custom option processing while preserving load balance functionality through standard packet forwarding mechanisms.
Solution Approach 2:
The patent replaces TTM's software-based custom option processing with a more secure implementation in the virtual switch that uses standard networking mechanisms. This substitution eliminates the security risks of custom TCP/IP options while maintaining the essential load balance capability.
3Reliability
If TTM module is integrated into kernel state, then address translation is performed, but kernel performance decreases and system exceptions may occur
Solution Approach 1:
The patent extracts the address translation function from the kernel state TTM module and implements it in the virtual switch's data plane. This extraction removes the performance overhead from the kernel path while preserving address translation capability, thereby improving kernel performance without sacrificing reliability.
Solution Approach 2:
The patent segments the address translation function from the kernel core operations and places it in the virtual switch's data plane. This segmentation isolates the translation capability from kernel performance-critical paths, preventing performance degradation and system exceptions while maintaining the translation function.
Data Source
AI summary
A method, apparatus and system for transmitting data. The system includes: the load balance gate wall translating a virtual MAC address of the virtual server in a destination address of a data packet from a client to a real MAC address of the real server according to a pre-configured address mapping relationship between a real server and a virtual server; the load balance gate wall sending a modified data packet to the virtual switch; the virtual switch determining a data packet flowing into the real server after receiving the data packet from the load balance gate wall, then translating a virtual IP and a virtual port of the virtual server in the destination address in the determined data packet to a real IP and a real port of the real server; and the virtual switch sending the modified data packet to the real server.


