Virtual Switch Controller for VM Traffic Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualization in data centers complicates network traffic visibility, troubleshooting, and resource management due to blended traffic from multiple virtual machines, lack of transparency, and challenges in isolating specific VM traffic, which hinders efficient resource utilization and live migration.

Innovation Solution

Collecting real-time statistics for VM-to-VM network traffic using a virtual switch controller and virtual Ethernet modules to distribute and learn network address information, enabling the differentiation and analysis of intra-server, inter-server, and inter-domain traffic patterns, and providing these statistics for VM placement and migration decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network virtualization is implemented using encapsulation techniques to create virtual overlays, then resource utilization and scalability are improved, but network traffic visibility and troubleshooting capability deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidnetwork traffic visibility
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces virtual switch controllers and virtual Ethernet modules as intermediary components between virtual machines and physical network infrastructure. These intermediaries capture, process, and forward network traffic while maintaining visibility into VM-to-VM communication patterns, thus resolving the contradiction between virtualization benefits and traffic observability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments network traffic monitoring by creating separate virtual Ethernet modules for different virtual machines and organizing them into virtual switch domains. This segmentation enables granular visibility into individual VM traffic patterns while maintaining overall network oversight, addressing the visibility challenge without sacrificing virtualization scalability

Inventive Principle:
Principle #1Segmentation

2Productivity

If multiple virtual machines share a single physical server, then hardware utilization improves, but network traffic isolation and analysis become more difficult

Engineering Contradiction:
Improvehardware utilizationVSAvoidtraffic isolation
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent divides the physical network infrastructure into multiple virtual Ethernet modules, each associated with specific virtual machines. This segmentation allows traffic from individual VMs to be tracked and analyzed separately, maintaining hardware consolidation benefits while enabling precise traffic isolation and monitoring

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a virtualization layer with virtual switches and controllers that operates above the physical hardware layer. This dimensional addition enables simultaneous access to both consolidated hardware resources and granular traffic control/visibility, resolving the contradiction between resource efficiency and traffic analyzability

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If virtual switch controllers collect statistics from multiple virtual Ethernet modules, then traffic analysis capability improves, but system complexity increases

Engineering Contradiction:
Improvetraffic analysis capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent designs virtual switch controllers with multi-functional capabilities to perform statistics collection, traffic analysis, and VM placement optimization in a single integrated component. This universality reduces the need for separate specialized tools, thereby improving traffic analysis capability while minimizing the increase in system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10659358B2Method and apparatus for advanced statistics collection
Publication Date: 2020.05.19 CISCO TECHNOLOGY INC
  • US10659358B2 patent drawing
  • US10659358B2 patent drawing
  • US10659358B2 patent drawing

AI summary

Systems, methods, and computer-readable media provide for collection of statistics relating to network traffic between virtual machines (VMs) in a network. In an example embodiment, a virtual switch hosted on a physical server provides network address information of VMs deployed on the physical server to a virtual switch controller. The controller collects this network address information from each virtual switch under its control, and distributes the aggregate address information to each switch. In this manner, the controller and each switch within the controller's domain can learn the network address information of each VM deployed on physical servers hosting switches under the controller's control. Each virtual switch can determine a classification of a frame passing through the switch (e.g., intra-server, inter-server and intra-domain, or inter-domain traffic), and statistics relating to the traffic. In an example embodiment, the virtual switch controller can collect the statistics from each switch within its domain.