VMAC Address Segmentation for Network Path Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intermediary devices, such as Application Delivery Controllers (ADCs), are unable to effectively segregate network traffic or configure traffic domains using information that does not identify a specific traffic domain identifier, making it difficult to maintain network path isolation between different applications or tenants in multi-tenant virtualized data centers.
Innovation Solution
The use of virtual Media Access Control (vMAC) addresses to segment network traffic by generating multiple vMAC addresses for different traffic domains, allowing for the selection and use of appropriate vMAC addresses in responses to Address Resolution Protocol (ARP) requests to isolate traffic domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical separation of network service devices is used, then network path isolation is achieved, but device complexity and resource utilization increase
Solution Approach 1:
The patent segments network traffic into different traffic domains based on traffic domain identifiers extracted from data packets. Each traffic domain is assigned a unique vMAC address, allowing the intermediary device to segment and isolate traffic at the MAC address level without requiring physical separation of network service devices.
Solution Approach 2:
The patent introduces an intermediary device positioned between clients and servers that acts as a mediator to implement traffic domain isolation. This device generates vMAC addresses, responds to ARP requests with domain-specific vMAC addresses, and directs traffic to appropriate traffic domains, eliminating the need for multiple physical network service devices.
2Reliability
If multiple physical network service devices are deployed for each tenant, then traffic isolation is maintained, but loss of substance and resource efficiency worsen
Solution Approach 1:
The patent makes a single intermediary device universal by enabling it to handle multiple traffic domains simultaneously. The device generates multiple vMAC addresses corresponding to different traffic domains and can direct traffic from multiple tenants through the same physical infrastructure, making one device serve multiple functions that previously required separate devices.
Solution Approach 2:
The patent creates virtual copies of MAC addresses (vMAC addresses) for different traffic domains without requiring physical copies of network service devices. These virtual MAC addresses allow the system to simulate multiple independent network service devices using a single physical device, improving resource efficiency while maintaining traffic isolation.
3Reliability
If vMAC addresses are generated and used in ARP responses, then network path isolation is enhanced, but device complexity increases
Solution Approach 1:
The patent changes the MAC address parameter dynamically based on the traffic domain identifier extracted from incoming data packets. When the intermediary device receives a packet, it extracts the traffic domain identifier, selects or generates the corresponding vMAC address, and uses that MAC address in ARP responses, allowing flexible traffic domain isolation without complex manual configuration.
Data Source
AI summary
Systems and methods for segmenting network traffic using virtual media access control (vMAC) addresses are disclosed. An intermediary device establishes a plurality of traffic domains to segment network traffic. The device generates a plurality of vMAC addresses to assign to the traffic domains. Each of the vMAC addresses includes an identifier of a traffic domain corresponding to the traffic domain to which the vMAC address is assigned. The device receives, from a second device, an ARP request to determine a MAC address to transmit data packets. The device selects, from the plurality of virtual MAC addresses, the virtual MAC address to use as the MAC address in a response based on an IP address identified via the ARP request. The device transmits, to the second device, a response to the request identifying, as the MAC address, the selected vMAC address of a traffic domain.


