Virtual Network Interface Controller Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualization architectures face security challenges in managing network traffic between multiple virtual machines and a host operating system, as conventional firewall solutions either impose performance penalties or increase management burdens, and fail to provide adequate protection against security breaches.

Innovation Solution

A virtualization framework with a network interface controller driver and virtual network interface controllers that include programmable packet filters, allowing each virtual machine to manage network communications securely and independently, with coordinated packet filter configurations to ensure security and efficient resource use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a platform firewall application is implemented to protect the physical computer system, then security protection is provided, but performance degradation occurs and management burden increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the firewall functionality into separate virtual machine-specific packet filters that are integrated into the virtualization framework. Each virtual machine has its own packet filter instance that operates independently at the virtual network interface controller level, eliminating the need for a single platform-wide firewall that degrades overall system performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtual network interface controller as an intermediary layer between the virtual machines and the physical network interface controller. This intermediary contains the packet filter functionality and manages network traffic selectively, providing security without requiring a separate platform firewall application that would impact host performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a platform firewall application is implemented, then security protection is provided, but management complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidmanagement burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each virtual machine is equipped with its own packet filter instance that is automatically managed through the virtualization framework. The framework handles the configuration and coordination of packet filters across virtual machines, eliminating the need for manual management of a separate platform firewall application and reducing administrative burden.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The virtualization framework provides universal packet filtering functionality that serves all virtual machines through a common architecture. The same virtual network interface controller and packet filter mechanisms are used across all virtual machines, providing consistent security management rather than requiring separate firewall configurations for each virtual machine or the host.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If packet filters are implemented in each virtual machine, then security isolation is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the packet filter functionality directly into the virtual network interface controller that is already part of each virtual machine's hardware emulation. This integration means that while each virtual machine has security filtering capability, the implementation does not add separate complex components but rather enhances the existing virtual network interface controller with programmable packet filter functionality.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8166474B1System and methods for implementing network traffic management for virtual and physical machines
Publication Date: 2012.04.24 VMWARE INC
  • US8166474B1 patent drawing
  • US8166474B1 patent drawing
  • US8166474B1 patent drawing

AI summary

A virtualization framework provides security between multiple virtual machines with respect to network communications between the virtual machines and between the virtual machines and a physical network coupled to the underlying physical computer platform. The virtualization framework includes a network interface controller driver that provides an interface to the platform network interface controller and supports execution of a plurality of virtual machines. Each virtual machine includes a virtual network interface controller that provides a network communications path between the virtual machines and to the network interface controller driver. Each virtual network interface controller further contains a programmable network packet filter that controls the selective transfer of network packets with respect to a corresponding virtual machine.