VM Address Association for Dynamic Security Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtualization technologies lack a program product that supports network awareness and automatic security control for minicomputers, making it difficult to manage and secure virtualized data centers effectively as VMs migrate across physical servers.
Innovation Solution
A packet processing method and device that utilize a control device to manage VM addresses and security strategies by associating VM address information with access switch ports, enabling centralized control and filtering of packets, and maintaining network security during VM migration through layer 2 and layer 3 packet interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If VMs are migrated across physical servers to improve resource utilization, then productivity increases, but network security control becomes more difficult
Solution Approach 1:
The control device continuously monitors VM migration status and dynamically updates security strategies based on real-time location information. When a VM migrates to a new physical server, the control device receives notification, updates the VM's access location in the database, and automatically adjusts security policies to maintain consistent network security control across the distributed environment.
Solution Approach 2:
A centralized control device acts as an intermediary between virtualized resources and physical infrastructure. This control device maintains a database mapping VM addresses to physical server locations and coordinates security strategy enforcement across multiple physical servers, enabling unified security management despite VM mobility across different hardware platforms.
2Ease of operation
If centralized control is implemented to improve security management, then ease of operation increases, but device complexity increases
Solution Approach 1:
The control device performs multiple functions including maintaining VM location databases, enforcing security policies, and coordinating with virtualized resources across different physical servers. By consolidating these diverse functions into a single multi-functional control system, the patent achieves centralized security management without requiring separate specialized systems for each function.
Data Source
AI summary
Various examples of the present disclosure may provide a packet processing method. A control device may receive a packet from an access switch. If VM address information in the packet is not associated with a port on the access switch for receiving the packet, the control device may send an instruction to the access switch instructing the access switch to associate the VM address information with the port on the access switch for receiving the packet, so that the access switch associates the VM address information with the port on the access switch for receiving the packet. The VM address information may comprise: a VLAN ID, an IP address and an MAC address.


