Virtual Switch VLAN Label Redirection for VM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing server virtualization techniques require complex modifications to the hypervisor, server network interface controller, and access switch layers to redirect packet traffic between virtual machines within a physical server for security processing, making them technically difficult and costly.

Innovation Solution

Implementing a virtual switch within the physical server that detects and modifies VLAN labels of packet traffic between virtual machines to redirect it to a network security module for security processing, allowing the virtual switch to replace labels to ensure correct routing without needing extensive modifications to other layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex modifications are made to the hypervisor, server network interface controller, and access switch layers to redirect packet traffic for security processing, then packet traffic can be redirected for security processing, but the device complexity and difficulty of implementation increase significantly

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidsystem modification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual switch as an intermediary component that sits between the virtual machines and the physical network infrastructure. This virtual switch handles the packet redirection function, allowing traffic between VMs to be redirected to security processing without requiring modifications to the hypervisor, server network interface controller, or access switch layers. The virtual switch acts as a mediator that simplifies the overall system architecture while achieving the security processing goal.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If extensive modifications are made to multiple layers (hypervisor, server network interface controller, access switch) to enable packet redirection, then packet traffic can be redirected for security processing, but the cost and difficulty of implementation increase

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The virtual switch serves as a standalone intermediary device that encapsulates the packet redirection and security processing functionality. By implementing this intermediate layer, the patent eliminates the need to modify multiple existing components (hypervisor, server network interface controller, access switch), thereby significantly improving implementation ease while maintaining security processing capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the packet redirection and security processing functions into a separate virtual switch component. This segmentation allows the security processing capability to be implemented independently without requiring changes to other system layers, making the implementation process simpler and more modular.

Inventive Principle:
Principle #1Segmentation

3Reliability

If packet traffic between virtual machines is redirected to external network security modules, then security processing can be performed, but the network complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual switch acts as an intermediary that manages the redirection of packet traffic to network security modules in a controlled manner. It handles the complexity of traffic routing and security processing internally, presenting a simplified interface to both the virtual machines and the security modules, thereby managing network architecture complexity while maintaining security processing capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9832040B2Redirecting virtual machine traffic
Publication Date: 2017.11.28 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9832040B2 patent drawing
  • US9832040B2 patent drawing
  • US9832040B2 patent drawing

AI summary

According to an example, in a method for redirecting virtual machine traffic a virtual switch may be implemented in a physical server. In addition, a packet sent from a first virtual machine to a second virtual machine may be detected, in which the first virtual machine and the second virtual machine are in the same virtual local area network (VLAN), and in which the packet has a first VLAN label that identifies the VLAN. Moreover, the first VLAN label may be replaced with a second VLAN label in the packet, in which the second VLAN label differs from the first VLAN label, and the packet may be sent to an uplink switch, in which the uplink switch may send the packet to a network security module.