Network Access Control List Normalization for Hardware Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control list (ACL) management in routing and switching equipment is inefficient, leading to high hardware costs, power consumption, and heat generation due to the need for extensive ternary content-addressable memory (TCAM), while blanket access control rules compromise security by allowing malicious traffic.

Innovation Solution

A networking device normalizes transmission data using a predetermined algorithm to reduce the number of ACL entries, allowing a single entry to apply to multiple data transmissions, thereby minimizing hardware usage and enhancing security by enabling more precise policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If blanket access control rules are used to reduce ACL entries, then hardware costs and power consumption are reduced, but security is compromised allowing malicious traffic

Engineering Contradiction:
Improvenumber of ACL entriesVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments access control rules into hierarchical levels: global rules that apply broadly and specific rules that target particular threats. This segmentation allows the system to maintain fewer ACL entries while preserving security by applying granular control only where necessary, rather than requiring separate entries for every possible scenario.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes parameters of ACL entries dynamically based on traffic patterns and threat assessments. By modifying rule parameters such as source/destination addresses, port ranges, and protocol types based on observed traffic characteristics, the system can adapt to new threats without requiring manual creation of new ACL entries, thus maintaining security with reduced hardware requirements.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If extensive TCAM is used to maintain detailed ACL entries for security, then security is improved, but hardware costs, power consumption, and heat generation increase

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent implements universal access control rules that can handle multiple scenarios with a single ACL entry. By designing rules that apply to classes of traffic patterns rather than individual flows, the system reduces the total number of ACL entries required, thereby reducing TCAM usage and associated power consumption while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies partial action by implementing access control only for the specific portions of traffic that require security enforcement, rather than applying blanket control to all traffic. This selective approach reduces the number of ACL entries needed in TCAM, lowering power consumption while maintaining security where it is most needed.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If extensive TCAM is used to maintain detailed ACL entries, then security is improved, but device complexity and hardware costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple access control functions into unified rules that handle various traffic types and security requirements simultaneously. By combining what would traditionally require separate ACL entries into consolidated rules, the system reduces device complexity and hardware requirements while maintaining security effectiveness.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal ACL entries that serve multiple security functions with a single rule configuration. These multi-functional rules can filter different protocol types, address ranges, and traffic patterns simultaneously, reducing the overall number of ACL entries required and thereby simplifying device complexity and reducing hardware costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10432628B2Method for improving access control for TCP connections while optimizing hardware resources
Publication Date: 2019.10.01 CISCO TECHNOLOGY INC
  • US10432628B2 patent drawing
  • US10432628B2 patent drawing
  • US10432628B2 patent drawing

AI summary

Disclosed are systems, methods, and computer-readable storage media for minimizing the number of entries in network access control lists (ACLs). In some embodiments of the present technology a networking device can receive, from a first computing device, a first data transmission intended for a second computing device, the first data transmission including first transmission data. The networking device can normalize at least a subset of the first transmission data based on a predetermined normalization algorithm, yielding a first normalized data set for the first data transmission. Subsequently, the networking device can identify a first access control list entry from a set of access control list entries based on the first normalized data set, the first access control list entry identifying a first action, and implement the first action in relation to the first data transmission.