Virtualization Management Module for Secure Network Topology

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized systems, each virtual machine requires a unique IP address for external connectivity, leading to increased costs and security risks due to direct exposure to the internet, which complicates malware and virus management.

Innovation Solution

A virtualization management module is deployed to generate an internal network among virtual machines, translating traffic between internal and external IP addresses, decoupling from external threats, and providing remote administration and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If each virtual machine is assigned a unique IP address for external connectivity, then external network access is enabled, but cost and maintenance increase

Engineering Contradiction:
Improveexternal network accessVSAvoidcost and maintenance
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtualization management module as an intermediary between virtual machines and the external network. This module performs IP address translation, allowing multiple virtual machines to share a single external IP address while maintaining individual network identity through internal addressing. The intermediary layer enables external connectivity without requiring unique external IP addresses for each virtual machine, thereby reducing cost and maintenance complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If each virtual machine connects externally with its own IP address, then network connectivity is achieved, but security risk increases due to direct internet exposure

Engineering Contradiction:
Improvenetwork connectivityVSAvoidmalware/virus risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The virtualization management module serves as a security intermediary that sits between virtual machines and the external network. It performs address translation and acts as a gateway, preventing direct exposure of virtual machines to the internet. The module can detect security threats and decouple compromised virtual machines from the external network while maintaining connectivity for secure virtual machines, thereby reducing malware and virus risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into an internal network (isolated from direct internet exposure) and an external network. Virtual machines reside in the internal network and communicate with the external network only through the virtualization management module. This segmentation creates a security boundary that protects virtual machines from direct internet threats while maintaining necessary connectivity.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If multiple virtual machines require unique IP addresses, then individual external access is enabled, but the number of IP addresses and management complexity increases

Engineering Contradiction:
Improveindividual external accessVSAvoidnumber of IP addresses
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The virtualization management module acts as an intermediary that handles IP address translation between internal and external networks. It maintains a mapping between internal IP addresses of virtual machines and external IP addresses, enabling individual external access for each virtual machine while using a single or limited number of external IP addresses. This eliminates the need for each virtual machine to have a unique external IP address.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtualization management module provides multi-functionality by serving as both a network gateway and an address translation service. It enables multiple virtual machines to share external network resources and IP addresses while maintaining individual connectivity and security. This universal approach allows the system to support individual external access without requiring a proportional increase in external IP addresses.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8813223B2Secure network topology on a virtualized server
Publication Date: 2014.08.19 INTEL CORP
  • US8813223B2 patent drawing
  • US8813223B2 patent drawing
  • US8813223B2 patent drawing

AI summary

Generally, this disclosure describes a secure network topology on a virtualized server (and methods thereof). A virtualization management module is deployed as part of a software layer of a virtualized server system. The virtualization management module generates an internal network among the virtual machines and controls access to the network. The virtualization management module translates incoming and outgoing traffic between the virtual machines and an external internet IP address, thus keeping the virtual machines indirectly coupled to the external network. The virtualization management module also provides remote administration and control over each virtual machine (or collection of virtual machines).