Virtual Switch Namespace for Cloud Packet Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing services face difficulties in managing communications between virtual machines and services that operate outside their overlay network, as they are unable to identify and process packets in the overlay network format, leading to cumbersome networking operations.

Innovation Solution

The implementation of a virtual switch namespace that identifies and modifies packet addressing to support communication with services outside the overlay network, using underlay operations to translate and encapsulate packets as needed, ensuring seamless interaction between virtual machines and cloud services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud computing services operate outside the overlay network, then service functionality is provided, but the services are incapable of identifying packets in the overlay network format

Engineering Contradiction:
Improveservice functionalityVSAvoidpacket identification capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a namespace virtual switch as an intermediary component that sits between the overlay network and services operating in the underlay network. This virtual switch performs packet translation, converting overlay network packets into a format that services can understand and process, thereby enabling communication without requiring services to natively support overlay network formats

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If overlay network is defined for virtual machines, then virtual machine networking is established, but services cannot identify packets corresponding to this overlay network

Engineering Contradiction:
Improvevirtual machine networkingVSAvoidpacket identification
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The namespace virtual switch acts as a mediator that receives packets from the overlay network, translates them into underlay network format, and forwards them to services. This allows virtual machines to maintain their overlay network configuration while services operate in the underlay network without needing to understand overlay network protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If services operate outside the overlay network, then additional service capabilities are provided, but networking operations become difficult and cumbersome to manage

Engineering Contradiction:
Improveservice capabilitiesVSAvoidnetworking management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

By positioning the namespace virtual switch as an intermediary, the system automatically handles packet translation and routing between overlay and underlay networks. This automation eliminates the need for manual networking configuration and management, making it easy for services to operate outside the overlay network while maintaining seamless connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual switch automatically performs packet translation and routing decisions based on configured rules, enabling services to operate independently without requiring manual networking management. The system self-manages the complexity of inter-network communication, allowing services to focus on their core functionality

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3669532B1Managing network connectivity between cloud computing service endpoints and virtual machines
Publication Date: 2022.10.26 NICIRA INC
  • EP3669532B1 patent drawingFigure 1
  • EP3669532B1 patent drawingFigure 2
  • EP3669532B1 patent drawingFigure 3

AI summary

Described herein are systems, methods, and software to enhance connectivity between cloud computing service endpoints and virtual machines. In one implementation, a method of managing data packet addressing in a first namespace includes receiving a data packet at a first interface for the first namespace, wherein the first interface is paired with a second interface of a second namespace. The method also includes identifying if the packet is destined for a service node in an underlay network outside of an overlay network for the second namespace, and if destined for a service node outside of an overlay network for the second namespace, modifying addressing in the data packet to support the underlay network and transferring the data packet over a virtual network interface for the virtual machine.