Virtual Switch VLAN Label Redirection for VM Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing server virtualization techniques require complex modifications to the hypervisor, server network interface controller, and access switch layers to redirect packet traffic between virtual machines within a physical server for security processing, making them technically difficult and costly.
Innovation Solution
Implementing a virtual switch within the physical server that detects and modifies VLAN labels of packet traffic between virtual machines to redirect it to a network security module for security processing, allowing the virtual switch to replace labels to ensure correct routing without needing extensive modifications to other layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex modifications are made to the hypervisor, server network interface controller, and access switch layers to redirect packet traffic for security processing, then packet traffic can be redirected for security processing, but the device complexity and difficulty of implementation increase significantly
Solution Approach 1:
The patent introduces a virtual switch as an intermediary component that sits between the virtual machines and the physical network infrastructure. This virtual switch handles the packet redirection function, allowing traffic between VMs to be redirected to security processing without requiring modifications to the hypervisor, server network interface controller, or access switch layers. The virtual switch acts as a mediator that simplifies the overall system architecture while achieving the security processing goal.
2Reliability
If extensive modifications are made to multiple layers (hypervisor, server network interface controller, access switch) to enable packet redirection, then packet traffic can be redirected for security processing, but the cost and difficulty of implementation increase
Solution Approach 1:
The virtual switch serves as a standalone intermediary device that encapsulates the packet redirection and security processing functionality. By implementing this intermediate layer, the patent eliminates the need to modify multiple existing components (hypervisor, server network interface controller, access switch), thereby significantly improving implementation ease while maintaining security processing capability.
Solution Approach 2:
The patent segments the packet redirection and security processing functions into a separate virtual switch component. This segmentation allows the security processing capability to be implemented independently without requiring changes to other system layers, making the implementation process simpler and more modular.
3Reliability
If packet traffic between virtual machines is redirected to external network security modules, then security processing can be performed, but the network complexity and processing overhead increase
Solution Approach 1:
The virtual switch acts as an intermediary that manages the redirection of packet traffic to network security modules in a controlled manner. It handles the complexity of traffic routing and security processing internally, presenting a simplified interface to both the virtual machines and the security modules, thereby managing network architecture complexity while maintaining security processing capability.
Data Source
AI summary
According to an example, in a method for redirecting virtual machine traffic a virtual switch may be implemented in a physical server. In addition, a packet sent from a first virtual machine to a second virtual machine may be detected, in which the first virtual machine and the second virtual machine are in the same virtual local area network (VLAN), and in which the packet has a first VLAN label that identifies the VLAN. Moreover, the first VLAN label may be replaced with a second VLAN label in the packet, in which the second VLAN label differs from the first VLAN label, and the packet may be sent to an uplink switch, in which the uplink switch may send the packet to a network security module.


