Network Access Control List Normalization for Hardware Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control list (ACL) management in routing and switching equipment is inefficient, leading to high hardware costs, power consumption, and heat generation due to the need for extensive ternary content-addressable memory (TCAM), while blanket access control rules compromise security by allowing malicious traffic.
Innovation Solution
A networking device normalizes transmission data using a predetermined algorithm to reduce the number of ACL entries, allowing a single entry to apply to multiple data transmissions, thereby minimizing hardware usage and enhancing security by enabling more precise policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If blanket access control rules are used to reduce ACL entries, then hardware costs and power consumption are reduced, but security is compromised allowing malicious traffic
Solution Approach 1:
The patent segments access control rules into hierarchical levels: global rules that apply broadly and specific rules that target particular threats. This segmentation allows the system to maintain fewer ACL entries while preserving security by applying granular control only where necessary, rather than requiring separate entries for every possible scenario.
Solution Approach 2:
The patent changes parameters of ACL entries dynamically based on traffic patterns and threat assessments. By modifying rule parameters such as source/destination addresses, port ranges, and protocol types based on observed traffic characteristics, the system can adapt to new threats without requiring manual creation of new ACL entries, thus maintaining security with reduced hardware requirements.
2Reliability
If extensive TCAM is used to maintain detailed ACL entries for security, then security is improved, but hardware costs, power consumption, and heat generation increase
Solution Approach 1:
The patent implements universal access control rules that can handle multiple scenarios with a single ACL entry. By designing rules that apply to classes of traffic patterns rather than individual flows, the system reduces the total number of ACL entries required, thereby reducing TCAM usage and associated power consumption while maintaining comprehensive security coverage.
Solution Approach 2:
The patent applies partial action by implementing access control only for the specific portions of traffic that require security enforcement, rather than applying blanket control to all traffic. This selective approach reduces the number of ACL entries needed in TCAM, lowering power consumption while maintaining security where it is most needed.
3Reliability
If extensive TCAM is used to maintain detailed ACL entries, then security is improved, but device complexity and hardware costs increase
Solution Approach 1:
The patent merges multiple access control functions into unified rules that handle various traffic types and security requirements simultaneously. By combining what would traditionally require separate ACL entries into consolidated rules, the system reduces device complexity and hardware requirements while maintaining security effectiveness.
Solution Approach 2:
The patent creates universal ACL entries that serve multiple security functions with a single rule configuration. These multi-functional rules can filter different protocol types, address ranges, and traffic patterns simultaneously, reducing the overall number of ACL entries required and thereby simplifying device complexity and reducing hardware costs.
Data Source
AI summary
Disclosed are systems, methods, and computer-readable storage media for minimizing the number of entries in network access control lists (ACLs). In some embodiments of the present technology a networking device can receive, from a first computing device, a first data transmission intended for a second computing device, the first data transmission including first transmission data. The networking device can normalize at least a subset of the first transmission data based on a predetermined normalization algorithm, yielding a first normalized data set for the first data transmission. Subsequently, the networking device can identify a first access control list entry from a set of access control list entries based on the first normalized data set, the first access control list entry identifying a first action, and implement the first action in relation to the first data transmission.


