Virtual Switch Multicast IP Mapping for Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face challenges in managing large numbers of virtual machines and virtual local area networks, particularly in supporting a large number of MAC addresses and transporting traffic over routed infrastructure, which complicates multicast routing in virtualized network environments.

Innovation Solution

The implementation of a method for providing multicast addressing in an overlay network using a first hypervisor managing a virtual switch that maps customer-specific multicast IP addresses to global multicast IP addresses, allowing for efficient packet transmission and reception across multiple virtual machines and tenants, with virtual switches encapsulating packets with global multicast IP addresses for transmission over the physical network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VLANs are used to separate tenants in virtualized networks, then network segmentation and tenant isolation are improved, but managing large VLANs becomes difficult and the network cannot efficiently support a large number of MAC addresses

Engineering Contradiction:
Improvetenant isolationVSAvoidVLAN management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network addressing space by introducing a hierarchical structure with customer-specific multicast IP addresses (local scope) and global multicast IP addresses (network-wide scope). This segmentation allows multiple tenants to have isolated multicast address spaces while enabling efficient routing across the network without requiring large VLANs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds an addressing dimension by mapping customer-specific addresses to global addresses through a translation mechanism. This dimensional transformation enables multicast traffic to be routed efficiently across the network while maintaining tenant isolation, solving the scalability problem without increasing VLAN management complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If a large number of virtual machines are deployed to support many tenants, then network capacity and service coverage are improved, but the number of MAC addresses increases making traffic transport and multicast routing difficult

Engineering Contradiction:
Improvenetwork capacityVSAvoidmulticast routing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces global multicast IP addresses as intermediaries between customer-specific multicast addresses and the underlying network infrastructure. This intermediary layer simplifies multicast routing by providing a unified addressing scheme that works across multiple tenants and virtual machines without requiring complex per-VM routing configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The global multicast IP address space serves multiple functions simultaneously: it provides unique identification for multicast groups across the entire network, enables efficient routing through standard IP multicast mechanisms, and maintains tenant isolation through the mapping relationship with customer-specific addresses. This universal addressing scheme supports arbitrary numbers of VMs without increasing routing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If customer-specific multicast IP addresses are used for each tenant, then tenant isolation and security are improved, but routing efficiency decreases due to address translation requirements

Engineering Contradiction:
Improvetenant isolationVSAvoidrouting efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs address mapping in advance by establishing the relationship between customer-specific multicast IP addresses and global multicast IP addresses before multicast traffic flows. This preliminary configuration allows the network to route multicast traffic efficiently using global addresses while maintaining tenant isolation, eliminating the need for real-time address translation during packet forwarding.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9698995B2Systems and methods for providing multicast routing in an overlay network
Publication Date: 2017.07.04 DELL PROD LP
  • US9698995B2 patent drawing
  • US9698995B2 patent drawing
  • US9698995B2 patent drawing

AI summary

An information handling system is provided. The information handling system includes a first hypervisor running on a first host and a second hypervisor running on a second host. The first hypervisor managing a first virtual switch, and the second hypervisor managing a second virtual switch. The information handling system also includes a plurality of virtual machines (VMs), including a first VM, which is part of a first tenant, running on the first host, and a second VM, part of a second tenant, running on the second host. The first virtual switch has a mapping in memory that maps a customer-specific multicast IP address, used by the plurality of VMs to indicate a multicast group that includes VMs on the first and second tenants, to a global multicast IP address used by the first and second hosts.