Virtual Machine Manager Router for Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtual machine network implementations lack sufficient security and efficiency, as they often require multiple hops for message transfer between virtual machines, leading to performance issues and inadequate security for large-scale, security-critical operations.
Innovation Solution
Integrating a router within the virtual machine manager to handle message routing, eliminating the need for virtual gateways and reducing the number of hops, while maintaining security through address rewriting and filtering policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If virtual machines use traditional network routing with virtual gateways, then network connectivity is maintained, but message processing speed decreases due to multiple hops
Solution Approach 1:
The patent merges the virtual switch and virtual router functions into a single integrated component called a virtual router. This integration eliminates the need for separate virtual gateways and reduces the number of routing hops, thereby improving message processing speed while maintaining network connectivity. The virtual router combines switching (layer 2) and routing (layer 3) operations in one device.
Solution Approach 2:
The patent extracts the routing function from traditional physical network infrastructure and implements it within the virtual machine manager itself. By taking out routing capabilities from external devices and embedding them in the VMM, the system reduces the number of hops and improves processing speed while maintaining connectivity.
2Productivity
If virtual machines are hosted on shared physical machines, then resource utilization increases, but security between different virtual networks becomes inadequate
Solution Approach 1:
The patent implements network segmentation by creating separate virtual networks (VNETs) for different clients or organizations. Each virtual network is isolated from others at the hardware level, with traffic between segments requiring explicit routing through virtual routers. This segmentation maintains resource sharing efficiency while providing robust security through logical isolation.
Solution Approach 2:
The virtual router acts as an intermediary between different virtual networks. It mediates traffic flow between segments, applying security policies and routing decisions. This intermediary approach allows resource sharing across physical machines while maintaining security through controlled access between virtual networks.
3Adaptability or versatility
If traditional physical network infrastructure is used, then network stability is maintained, but adaptability to changing virtual network configurations is poor
Solution Approach 1:
The patent implements dynamic network configuration where virtual networks can be created, modified, and deleted on-demand without affecting the physical infrastructure. The virtual router dynamically adapts to changing network topologies and policies, providing high adaptability while maintaining stability through software-based control rather than hardware reconfiguration.
Data Source
AI summary
A data center can share processing resources using virtual networks. A virtual machine manager (10) hosts one or more virtual machines (11, 411), the virtual machines forming part of a segmented virtual network (34). Outgoing messages from the virtual machines have an intermediate destination address of an intermediate node in a local segment of the segmented virtual network, and the virtual machine manager has a router (18) for determining a new intermediate destination address outside the local segment, for routing the given outgoing message. By having the router as part of the virtual machine manager rather than having only a switch in the virtual machine manager, the need for virtual machines for implementing gateways is avoided. This can reduce the number of “hops” for the message between virtual entities hosted, and thus improve performance. This can help a service provider to share physical processing resources of a data center between different clients having their own virtual networks.


