Virtual Switch Routing for Legacy Network Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy applications face challenges in running as virtualized or containerized network functions due to requirements similar to those needed when running on hardware, and difficulties in adapting from single-tenant to multi-tenant environments.
Innovation Solution
A system that intercepts and routes Layer-2 traffic from different virtual machines or containers, associating unique namespaces and MAC addresses with each instance, allowing for policy application and steering of traffic based on the instance sending the traffic, enabling legacy applications to run without underlying modifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If legacy applications are migrated to virtualized or containerized environments, then cloud platform compatibility is improved, but the applications require significant modifications to meet new interface and ordering requirements
Solution Approach 1:
The patent introduces a virtual switch as an intermediary component between the legacy application and the virtualized environment. This virtual switch translates and adapts traffic between different network interfaces, allowing the legacy application to communicate in its original format while the virtual switch handles the conversion to meet virtualized environment requirements. This mediator approach resolves the contradiction by maintaining application compatibility without requiring application modifications.
Solution Approach 2:
The patent segments the network function into separate components: the legacy application layer and the virtualization adapter layer. The virtualization adapter sits between them and handles all interface translations, ordering requirements, and protocol conversions. This segmentation allows the legacy application to remain unchanged while the adapter layer absorbs all the adaptation requirements of the virtualized environment.
2Productivity
If single-tenant applications are deployed in multi-tenant environments, then resource utilization is improved, but traffic isolation and routing become significantly more complex
Solution Approach 1:
The patent extracts the traffic isolation and routing logic from the application layer and places it in a dedicated virtual switch component. This virtual switch maintains separate forwarding tables and routing rules for different tenants, effectively isolating their traffic streams. By taking out this complexity from the applications and centralizing it in the virtual switch, multiple tenants can share the same infrastructure with proper isolation.
Solution Approach 2:
The patent implements local quality by providing each tenant with customized routing rules, interface configurations, and traffic handling policies specific to their requirements. The virtual switch maintains separate configuration sets for different tenants, allowing each to have optimized traffic routing while sharing the same physical infrastructure. This enables multi-tenant deployment with proper isolation while maintaining simplicity for each individual tenant.
3Adaptability or versatility
If legacy applications run in containerized environments, then deployment flexibility is improved, but container-specific configuration requirements increase complexity
Solution Approach 1:
The patent introduces a container adapter as an intermediary layer between the legacy application and the containerized environment. This adapter handles all container-specific configuration requirements, including interface mappings, network namespace management, and resource allocation. The legacy application communicates through standardized interfaces that the adapter translates into container-specific configurations, providing deployment flexibility without exposing configuration complexity to the application.
Data Source
AI summary
A system receives a first request from a first instance of a network function associated with a first address. The system may determine the first address and, based at least in part on the first address, may identify a second address with which to respond to the first request. The system may then send, to the first instance of the network function, a response to the first request specifying the second address. The system may also receive a second request from a second instance of the network function associated with a third address. The system may determine a fourth address with which to respond to the second request, and may thereafter send a response to the second request to the second instance of the network function, with the response specifying the fourth address.


