Virtual Switch Controller for VM Traffic Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtualization in data centers complicates network traffic visibility, troubleshooting, and resource management due to blended traffic from multiple virtual machines, lack of transparency, and challenges in isolating specific VM traffic, which hinders efficient resource utilization and live migration.
Innovation Solution
Collecting real-time statistics for VM-to-VM network traffic using a virtual switch controller and virtual Ethernet modules to distribute and learn network address information, enabling the differentiation and analysis of intra-server, inter-server, and inter-domain traffic patterns, and providing these statistics for VM placement and migration decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network virtualization is implemented using encapsulation techniques to create virtual overlays, then resource utilization and scalability are improved, but network traffic visibility and troubleshooting capability deteriorate
Solution Approach 1:
The patent introduces virtual switch controllers and virtual Ethernet modules as intermediary components between virtual machines and physical network infrastructure. These intermediaries capture, process, and forward network traffic while maintaining visibility into VM-to-VM communication patterns, thus resolving the contradiction between virtualization benefits and traffic observability
Solution Approach 2:
The patent segments network traffic monitoring by creating separate virtual Ethernet modules for different virtual machines and organizing them into virtual switch domains. This segmentation enables granular visibility into individual VM traffic patterns while maintaining overall network oversight, addressing the visibility challenge without sacrificing virtualization scalability
2Productivity
If multiple virtual machines share a single physical server, then hardware utilization improves, but network traffic isolation and analysis become more difficult
Solution Approach 1:
The patent divides the physical network infrastructure into multiple virtual Ethernet modules, each associated with specific virtual machines. This segmentation allows traffic from individual VMs to be tracked and analyzed separately, maintaining hardware consolidation benefits while enabling precise traffic isolation and monitoring
Solution Approach 2:
The patent adds a virtualization layer with virtual switches and controllers that operates above the physical hardware layer. This dimensional addition enables simultaneous access to both consolidated hardware resources and granular traffic control/visibility, resolving the contradiction between resource efficiency and traffic analyzability
3Measurement precision
If virtual switch controllers collect statistics from multiple virtual Ethernet modules, then traffic analysis capability improves, but system complexity increases
Solution Approach 1:
The patent designs virtual switch controllers with multi-functional capabilities to perform statistics collection, traffic analysis, and VM placement optimization in a single integrated component. This universality reduces the need for separate specialized tools, thereby improving traffic analysis capability while minimizing the increase in system complexity
Data Source
AI summary
Systems, methods, and computer-readable media provide for collection of statistics relating to network traffic between virtual machines (VMs) in a network. In an example embodiment, a virtual switch hosted on a physical server provides network address information of VMs deployed on the physical server to a virtual switch controller. The controller collects this network address information from each virtual switch under its control, and distributes the aggregate address information to each switch. In this manner, the controller and each switch within the controller's domain can learn the network address information of each VM deployed on physical servers hosting switches under the controller's control. Each virtual switch can determine a classification of a frame passing through the switch (e.g., intra-server, inter-server and intra-domain, or inter-domain traffic), and statistics relating to the traffic. In an example embodiment, the virtual switch controller can collect the statistics from each switch within its domain.


