Virtual Switches for Private Allocated Network Traffic Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing private allocated networks (PANs) in a virtual infrastructure is challenging, especially when virtual machines are distributed across multiple physical networks, as broadcast messages may reach unintended hosts and not all hosts can receive them due to layer 2 network limitations, and VLANs are not easily programmable by a centralized virtual infrastructure manager.

Innovation Solution

Creating virtual switches in hosts with ports associated with PANs, defining addressing mode tables to route intranet traffic, and using layer 2 address translation and layer 3 encapsulation to ensure traffic isolation and routing between virtual switches, allowing PANs to share the same physical media without visibility to non-connected nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VLANs are used to implement distributed networks, then network isolation and broadcast domain integrity are improved, but programmability by centralized virtual infrastructure manager and flexibility are worsened

Engineering Contradiction:
Improvenetwork isolationVSAvoidprogrammability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a virtual switch as an intermediary component between virtual machines and physical networks. The virtual switch maintains VLAN isolation properties while being programmable through a centralized virtual infrastructure manager (vSphere/ESXi). It provides a software-based abstraction layer that translates centralized management commands into appropriate network configurations, resolving the contradiction between reliable isolation and ease of programmability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional hardware-based VLAN configuration mechanisms with software-based virtual switching. Instead of requiring manual configuration of physical switches and routers, the system uses virtual switches that can be programmatically controlled through APIs and automated workflows, enabling centralized management while maintaining network isolation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Area of stationary object

If broadcast messages are sent in a private network across multiple physical networks, then communication coverage is improved, but unintended hosts receive messages and scalability is worsened

Engineering Contradiction:
Improvecommunication coverageVSAvoidunintended traffic reception
Core Design Contradiction:
Area of stationary objectVSObject-generated harmful factors

Solution Approach 1:

The patent segments the network into multiple isolated private networks (VLANs) that can span across multiple physical networks. Each VLAN creates a separate broadcast domain, allowing broadcast messages to be confined to specific logical networks while physically distributed across multiple infrastructures. This segmentation enables wide communication coverage without unintended reception by hosts outside the specific VLAN.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a logical dimension (VLAN tagging) to the physical network infrastructure. By introducing 802.1Q VLAN tags as an additional addressing dimension, the system can distinguish between different private networks traversing the same physical medium, enabling broad communication coverage while preventing cross-contamination of broadcast traffic between different logical networks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If virtual machines are distributed across multiple physical networks, then resource utilization and flexibility are improved, but network configuration complexity and traffic routing are worsened

Engineering Contradiction:
Improvedistribution flexibilityVSAvoidnetwork configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal virtual switching platform that can handle multiple network functions across distributed physical networks. The virtual switch provides unified configuration, traffic management, and isolation policies that work consistently regardless of the underlying physical network topology, reducing configuration complexity while maintaining distribution flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The virtual switch acts as an intermediary that abstracts the complexity of distributed physical network configuration. It provides a standardized interface for configuring private networks, handling traffic routing, and managing isolation policies, thereby simplifying the overall system complexity while enabling flexible distribution of virtual machines across heterogeneous physical infrastructures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11917044B2Private allocated networks over shared communications infrastructure
Publication Date: 2024.02.27 VMWARE INC
  • US11917044B2 patent drawing
  • US11917044B2 patent drawing
  • US11917044B2 patent drawing

AI summary

Methods and systems for implementing private allocated networks in a virtual infrastructure are presented. One method operation creates virtual switches in one or more hosts in the virtual infrastructure. Each port in the virtual switches is associated with a private allocated network (PAN) from a group of possible PANs. In one embodiment, one or more PANs share the same physical media for data transmission. The intranet traffic within each PAN is not visible to nodes that are not connected to the each PAN. In another operation, the method defines addressing mode tables for the intranet traffic within each PAN. The entries in the addressing mode tables define addressing functions for routing the intranet traffic between the virtual switches, and different types of addressing functions are supported by the virtual switches.