Virtual Switching Overlay for Cloud Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise data centers face challenges with security, reliability, and visibility in cloud computing environments due to the lack of control and inconsistent interfaces with virtual private clouds, which hinder adoption of cloud computing services.

Innovation Solution

Implementing a virtual switching overlay within the cloud infrastructure, allowing network administrators to regain control over the network access layer, providing secure communication and full visibility through a virtual switch that operates as an access layer switch, creating a secure communication channel between virtual machines and external networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises use cloud computing services through virtual private clouds, then access to shared computing resources is enabled, but control over network access layer and visibility into infrastructure is lost

Engineering Contradiction:
Improveaccess to computing resourcesVSAvoidcontrol over network access layer
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the network infrastructure control by introducing a virtual switch that separates the external network interface from the virtual machine network. This allows enterprises to maintain control over the network access layer while still utilizing cloud computing resources, resolving the contradiction between resource accessibility and operational control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual switch acts as an intermediary component between the external network and virtual machines within the cloud environment. It provides a control point that enables enterprises to monitor and manage network traffic, maintaining visibility and control while accessing shared computing resources through virtual private clouds.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud providers maintain internal infrastructure as competitive advantage, then service quality is improved, but enterprise visibility and verification capability is reduced

Engineering Contradiction:
Improveservice qualityVSAvoidvisibility into infrastructure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The virtual switch serves as a transparent intermediary that allows enterprises to observe and verify infrastructure operations without interfering with cloud provider's internal management. It provides visibility into network traffic and infrastructure behavior while maintaining the cloud provider's ability to manage services quality, resolving the information asymmetry.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual switching overlay provides feedback mechanisms that allow enterprises to monitor infrastructure performance and behavior. This enables verification of service quality and reliability claims while maintaining the cloud provider's operational autonomy, addressing the visibility challenge.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If virtual private clouds are implemented, then cloud computing adoption is enabled, but security and compliance assurance is reduced

Engineering Contradiction:
Improvecloud service adoptionVSAvoidsecurity assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The virtual switch acts as a security intermediary that enables enterprises to implement security policies and compliance measures at the network access layer. It provides a control point for monitoring and enforcing security requirements while still enabling cloud service adoption through virtual private clouds.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual switching overlay is established beforehand to create a secure network environment before cloud services are deployed. This preliminary security infrastructure ensures that security and compliance requirements are met from the outset, enabling confident cloud adoption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUSRE49663E1Virtual switching overlay for cloud computing
Publication Date: 2023.09.19 CISCO TECHNOLOGY INC
  • USRE49663E1 patent drawing
  • USRE49663E1 patent drawing
  • USRE49663E1 patent drawing

AI summary

In one embodiment, a method includes receiving data at a virtual switch located at a network device in a cloud network. The data is received from an external network and destined for one or more virtual machines located in the cloud network and associated with the external network. The method further includes transmitting the data from the virtual switch to the virtual machines. The virtual switch operates as an access layer switch for the external network and creates a virtual switching overlay for secure communication between the virtual machines and the external network. Logic and an apparatus are also disclosed.