Dynamic VM Path Reordering for Identity Masking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication methods fail to provide the ability to route communications through intermediate locations to mask the source or identity, limiting control over routing within and across commercial clouds.
Innovation Solution
The implementation of a method that defines and modifies data unit paths using virtual machines across multiple networks, allowing for dynamic reordering of virtual machine paths to change the routing of data units, coupled with the use of a virtualization platform like Nicira Network Virtualization Platform (NVP) to create secure, identity-protected networks and VPNs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If routing is performed at the network layer based on external IP address, then communication efficiency is improved, but the ability to mask source identity is lost
Solution Approach 1:
The patent introduces virtual machines as intermediary nodes between the source device and destination. These VMs receive data units, forward them to the destination, and simultaneously mask the source identity. The intermediary VMs break the direct routing path, allowing identity protection while maintaining communication efficiency through automated forwarding.
Solution Approach 2:
The patent segments the traditional single-path routing into multiple hops through virtual machines. Instead of direct source-to-destination routing, data units are divided into segments passed through intermediate VMs, each handling a portion of the transmission. This segmentation enables identity masking at each hop while preserving overall communication efficiency.
2Device complexity
If fixed routing paths are used, then network simplicity is maintained, but control over routing is limited
Solution Approach 1:
The patent implements dynamic routing where the system can modify data unit paths based on requirements. Virtual machines can be added, removed, or repositioned in the routing path dynamically. The network controller can adjust routing configurations in real-time, providing adaptability while maintaining operational simplicity through automated management.
Solution Approach 2:
The virtual machine infrastructure provides multi-functionality, serving both as simple forwarding nodes and as controllable routing intermediaries. The same VM infrastructure can operate in straightforward modes for simple cases or be configured for complex routing scenarios, providing versatility without requiring separate systems.
3Length of moving object
If direct routing is implemented, then path length is minimized, but identity protection capability is reduced
Solution Approach 1:
Virtual machines are positioned as intermediaries in the data unit path, adding necessary hops for identity protection. The intermediaries process and forward data units, extending the path length minimally while effectively masking source identity through multiple forwarding points.
Solution Approach 2:
The system allows data units to rush through the network efficiently by using high-speed forwarding in virtual machines. While additional hops are introduced for identity protection, the forwarding operations are optimized to minimize actual transmission time, effectively skipping delays despite increased path length.
Data Source
AI summary
In some embodiments, a method includes sending a first data unit, received from a source device, to a destination device via a first data unit path. The first data unit path includes (1) a first virtual machine and a second virtual machine that are included in a first network, and (2) a third virtual machine that is included in a second network. Furthermore, the first data unit path includes the first virtual machine, the second virtual machine, and the third virtual machine in a first order. The method includes sending a second data unit, received from the source device, to the destination device via a second data unit path from the source device to the destination device. The second data unit path includes each of the first virtual machine, the second virtual machine, and the third virtual machine in a second order different from the first order.


