Virtual Switch Segmentation for Control Plane Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual server sets are vulnerable to Denial-of-Service (DoS) attacks, which overwhelm the system, making it difficult to manage and regain control as the control plane, bearer plane, and signaling plane are often handled by a single virtual switch, leading to system overload and potential shutdown.

Innovation Solution

Implementing a second virtual switch specifically for the control plane, separate from the first virtual switch handling the bearer and signaling planes, allows for continued management and operation even during a DoS attack, ensuring the control plane remains functional and enables quicker recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single virtual switch handles control plane, bearer plane, and signaling plane, then device complexity is reduced, but system reliability deteriorates under DoS attack

Engineering Contradiction:
Improvevirtual switch configurationVSAvoidcontrol plane availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the virtual switch functionality into separate components: a control plane virtual switch and a data plane virtual switch. This segmentation isolates the control plane from DoS attacks targeting the data plane, ensuring control functions remain available even when bearer and signaling planes are overwhelmed.

Inventive Principle:
Principle #1Segmentation

2Reliability

If control plane and data plane are separated into different virtual switches, then control plane reliability is improved during DoS attack, but device complexity increases

Engineering Contradiction:
Improvecontrol plane availabilityVSAvoidvirtual switch architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements segmentation by creating separate control plane and data plane virtual switches, allowing independent management and protection of control functions while maintaining clear architectural boundaries that simplify operational understanding despite increased component count.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9544330B1Method of securing management interfaces of virtual machines
Publication Date: 2017.01.10 T MOBILE INNOVATIONS LLC
  • US9544330B1 patent drawing
  • US9544330B1 patent drawing
  • US9544330B1 patent drawing

AI summary

A virtual server set is disclosed, comprising one or more virtual servers for processing user requests, the virtual server set comprising, at least a first processor and a second processor, a memory, a first switch running on the first processor, the first switch to manage a control plane, and, a second switch running on the second processor, to manage a signaling plane and a bearer plane.