ACL Table Generation for Data Center Network Expansion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing two-level full mesh architecture in data centers faces challenges in expanding network capacity due to the requirement for hyperscale TCAM, which cannot be produced with current technology, making it difficult to manage large ACL tables effectively.

Innovation Solution

A method and apparatus for generating an ACL table by determining port types, selecting target ports, generating corresponding ACL entries, and adding them to the ACL table, reducing the number of entries and lowering TCAM resource requirements, thereby facilitating network expansion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a two-level full mesh architecture is implemented to meet rapid data growth requirements, then network connectivity and communication capability are improved, but the size of ACL tables increases significantly, requiring hyperscale TCAM which cannot be produced with current technology

Engineering Contradiction:
Improvenetwork connectivityVSAvoidACL table size
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent segments the ACL table into multiple smaller ACL tables, each stored in a different network device within the mesh architecture. Instead of requiring one large hyperscale TCAM in a single device, the ACL enforcement functionality is distributed across multiple devices, allowing each device to have a manageable TCAM size while collectively providing comprehensive ACL coverage for the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to ACL table management by utilizing the network topology itself as a storage dimension. Rather than expanding the capacity of a single TCAM device, the solution distributes ACL entries across multiple devices in the mesh network, effectively using the network's spatial structure to accommodate the large ACL table requirements.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If ACL entries are configured for each flow through each port to ensure precise access control, then security and access control precision are improved, but the quantity of ACL entries increases, making it difficult to manage and requiring larger TCAM capacity

Engineering Contradiction:
Improveaccess control precisionVSAvoidACL table management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments both the ACL table and the network devices, distributing the management complexity across multiple devices. Each device manages a portion of the ACL entries relevant to its local traffic, reducing the complexity burden on any single device while maintaining comprehensive access control precision across the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial action by configuring ACL entries only where needed in the network rather than duplicating full ACL tables across all devices. Each network device receives and enforces only the subset of ACL rules relevant to its local traffic flows, reducing overall complexity while maintaining necessary security precision.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If a large number of ACL entries are stored in a single switch to handle all network traffic, then comprehensive access control is achieved, but the requirement on TCAM resource specifications increases to hyperscale levels which are not currently manufacturable

Engineering Contradiction:
Improveaccess control coverageVSAvoidTCAM production feasibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the large ACL table into multiple smaller tables distributed across multiple network devices. This segmentation allows each device to use standard, manufacturable TCAM components rather than requiring unproven hyperscale TCAM technology, while the collective system maintains comprehensive access control coverage through coordinated enforcement across the mesh network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a controller as an intermediary that manages the distribution and coordination of ACL entries across the mesh network. The controller receives ACL policies, distributes appropriate subsets to relevant network devices, and coordinates their enforcement, enabling comprehensive access control without requiring any single device to have hyperscale TCAM capacity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11032198B2Method and apparatus for generating ACL table
Publication Date: 2021.06.08 HUAWEI TECH CO LTD
  • US11032198B2 patent drawing
  • US11032198B2 patent drawing
  • US11032198B2 patent drawing

AI summary

A method and an apparatus are disclosed for generating an ACL table. A controller obtains a port type of each port of a first network device, and selects, based on the port type of each port, a target port whose port type is a preset type from all ports of the first network device. The controller generates a corresponding first-type access control list ACL entry for each target port, and generates one second-type ACL entry corresponding to a routing table of the first network device, where an action of the second-type ACL entry is redirecting to the routing table. The controller adds the second-type ACL entry and each first-type ACL entry to an ACL table of the first network device.