Virtual Machine Network Isolation via Tunneling VPN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualized computing environments face challenges in securely isolating network traffic between virtual machines and shared software services, particularly due to limitations in VLANs, which can lead to security weaknesses and traffic isolation issues, especially when multiple applications share the same VLAN, increasing the risk of cross-contamination and malicious code transmission.

Innovation Solution

Establishing a tunneling VPN connection between virtual machines and shared software services, using secure VPN parameters and a distributed hash table to create encrypted communication paths, ensuring that each virtual machine or application has a unique and restricted VPN connection, thereby isolating its communication from others, even when co-hosted in the same environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VLANs are used to isolate network traffic between virtual machines and shared software services, then network segmentation is achieved, but security weaknesses and traffic isolation issues arise when multiple applications share the same VLAN

Engineering Contradiction:
Improvenetwork traffic isolationVSAvoidcross-contamination and malicious code transmission
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the network communication path into multiple isolated segments by establishing individual VPN tunnel connections between each virtual machine and the shared software service. This segmentation ensures that network traffic from different VMs is separated into distinct encrypted channels, preventing cross-contamination even when VMs share the same physical network infrastructure or VLAN.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces VPN tunnel connections as intermediary elements between virtual machines and the shared software service. These VPN tunnels act as secure mediators that encapsulate and encrypt network traffic, creating an additional layer of isolation that prevents direct exposure of VM traffic to the shared network environment and eliminates the security weaknesses of traditional VLAN-based isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple applications share the same VLAN, then resource utilization is improved, but the risk of cross-contamination and malicious code transmission increases

Engineering Contradiction:
Improveresource utilizationVSAvoidcommunication isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies segmentation by creating individual VPN tunnel connections for each virtual machine or application, even when they share the same VLAN. This divides the shared network resource into isolated communication channels, allowing multiple applications to utilize the same physical infrastructure while maintaining strict communication isolation through encrypted VPN segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by providing customized VPN tunnel configurations for each virtual machine or application. Each VPN connection is locally optimized and secured with unique parameters, ensuring that each application receives appropriate security isolation tailored to its specific communication needs while sharing the underlying network infrastructure.

Inventive Principle:
Principle #3Local quality

3Device complexity

If traditional network communication is used without VPN tunneling, then system complexity is reduced, but security and traffic isolation are compromised

Engineering Contradiction:
Improvecommunication infrastructureVSAvoidsecurity weaknesses
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces VPN tunnel connections as intermediary elements that encapsulate traditional network communication. This adds a security layer without fundamentally changing the underlying network infrastructure, allowing organizations to maintain their existing communication architecture while gaining enhanced security and isolation through the VPN intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a composite communication system by combining traditional network protocols with VPN encryption and tunneling mechanisms. This composite approach integrates the simplicity of standard network communication with the security benefits of encrypted tunnels, producing a communication infrastructure that maintains ease of use while eliminating security weaknesses.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS10594659B2Method and system for secure communication with shared cloud services
Publication Date: 2020.03.17 BRITISH TELECOM PLC
  • US10594659B2 patent drawing
  • US10594659B2 patent drawing
  • US10594659B2 patent drawing

AI summary

A computer implemented method of secure communication between a virtual machine in a set of virtual machines in a virtualized computing environment and a shared software service over a network, the method comprising: establishing a network connection between the virtual machine and the software service; communicating data between the virtual machine and the software service; and establishing a tunneling virtual private network (VPN) connection for communication of encrypted network traffic between the virtual machine and the software service, access to the VPN connection being restricted so as to securely separate communication between the virtual machine and the software service from communication occurring with other virtual machines in the set, and wherein data is communicated between the virtual machine and the software service via the VPN connection.