Virtual Switch Logical Ports for VNIC Filtering Protocol Flexibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtual networking systems are inflexible in applying different filtering protocols to traffic from multiple virtual network interface cards (VNICs), often requiring separate VNICs and wasting memory, as they cannot efficiently manage multiple filtering protocols for a single VNIC or apply the same protocol across multiple VNICs.
Innovation Solution
Implementing a virtual switch with both physical and logical switch ports, where physical switch ports forward packets to logical switch ports based on a transmit function, and logical switch ports apply filtering protocols and forward packets back to physical switch ports based on a receive function, allowing for multiple filtering protocols to be applied to a single VNIC or the same protocol to be applied across multiple VNICs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If separate VNICs are created for each filtering protocol, then multiple filtering protocols can be applied to traffic from a single VNIC, but memory usage increases and system complexity increases
Solution Approach 1:
The virtual switch is designed to apply multiple filtering protocols (SPANNING TREE PROTOCOL, 802.1X AUTHENTICATION, RADIUS AUTHENTICATION) through a single logical interface. The system allows a single VNIC to have multiple filtering protocols applied by creating logical representations of switch ports that can each apply different protocols, eliminating the need to create separate VNICs for each protocol while maintaining protocol application flexibility
Solution Approach 2:
The patent creates logical representations (copies) of physical switch ports within the virtual switch. These logical port representations allow multiple filtering protocols to be applied to traffic from a single VNIC without requiring separate physical VNICs. The logical copies enable protocol application flexibility while using the same physical network interface card, thereby reducing memory usage compared to creating separate VNICs for each protocol
2Adaptability or versatility
If separate VNICs are created for each filtering protocol, then multiple filtering protocols can be applied to traffic from a single VNIC, but device complexity increases
Solution Approach 1:
The virtual switch serves as a universal device that can apply multiple filtering protocols through a single VNIC connection. The system architecture allows one VNIC to connect to multiple logical port representations, each capable of applying different filtering protocols. This multi-functional approach eliminates the need for multiple separate VNICs and their associated configuration complexity, while still providing the ability to apply multiple protocols to traffic from a single VNIC
Solution Approach 2:
The virtual switch acts as an intermediary between the VNIC and the network, providing a layer where multiple filtering protocols can be applied without requiring changes to the VNIC itself or the underlying physical network infrastructure. This intermediary approach simplifies the system by centralizing protocol application logic in the virtual switch, rather than requiring complex configurations across multiple VNICs and network devices
3Adaptability or versatility
If multiple logical switch ports are implemented, then multiple filtering protocols can be applied to a single VNIC, but virtual switch complexity increases
Solution Approach 1:
The virtual switch is segmented into multiple logical port representations, where each logical port can apply a specific filtering protocol. This segmentation allows the virtual switch to handle different protocols independently through separate logical interfaces, while all logical ports share the same physical VNIC connection. The segmentation approach enables multiple filtering protocols to be applied to a single VNIC without creating a monolithic complex structure, as each logical port operates semi-independently
Solution Approach 2:
The patent introduces a logical dimension to the virtual switch architecture, creating multiple logical port representations that exist in the software layer rather than requiring separate physical hardware interfaces. This dimensional change from physical to logical port multiplication allows multiple filtering protocols to be applied to a single VNIC without proportionally increasing physical device complexity. The logical ports operate in the virtualization layer, adding protocol flexibility without linearly increasing hardware complexity
Data Source
AI summary
Aspects of the present disclosure relate to introduction of a physical switch port and logical switch port to the virtualization layer. A virtual network interface card (VNIC) can be associated with a physical switch port that routes traffic to logical switch ports based on a transmit function. The logical switch ports each are associated with a filtering protocol and route traffic to a physical switch port based on a receive function associated with that logical switch port. The logical switch ports can be associated with container running on the virtual machine (VM) connected to the VNIC. Thus, a single VNIC can be shared by multiple containers running different filtering protocols. A single logical port can also route traffic to multiple physical switch ports, each associated with a different VNIC. Thus, a same filtering protocol can be shared by multiple VNICs.


