Verifiable Address Rights Transfer in Data Center Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data center networks, the migration of virtual resources from one physical server to another leads to difficulties in routing communications, and there is no validation of the addresses exchanged between hosts, resources, and devices.

Innovation Solution

A method where a network controller determines a device's request to communicate on an address, signs a token indicating authorization, and sends it to the device, allowing the device to communicate using the signed token, thereby validating and managing address rights in the data center network fabric.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual resources are migrated from one physical server to another, then resource utilization is optimized and scalability is improved, but routing communication becomes difficult and address validation is lost

Engineering Contradiction:
ImprovescalabilityVSAvoidaddress validation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by announcing address migrations to the network fabric before the actual migration occurs. The migration announcement message is sent in advance to switches and other devices, allowing them to update their forwarding tables and prepare for the address movement, thus maintaining reliable communication throughout the migration process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where switches and network devices monitor and detect address migrations by processing migration announcement messages. This feedback loop ensures that all network participants are aware of address movements and can adjust their routing accordingly, maintaining communication reliability during virtual resource migration.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If address migration is announced to the network fabric, then routing is improved and communication is maintained, but there is no validation of the addresses exchanged

Engineering Contradiction:
ImproveroutingVSAvoidaddress validation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces an intermediary verification process where migration announcement messages are processed and validated by network switches and the network controller. This intermediary layer verifies that address migrations are legitimate and properly formatted before propagating the information throughout the network fabric, ensuring both ease of routing and reliability of address validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If virtual resources are deployed on physical servers, then computing resource needs are met, but migration leads to routing difficulties

Engineering Contradiction:
Improveresource allocationVSAvoidrouting complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system simplifies routing during migration by performing preliminary actions - sending migration announcement messages before the actual address change occurs. This allows network switches to proactively update their forwarding tables and prepare routing paths, reducing the complexity of real-time routing adjustments when virtual resources migrate between physical servers.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12316632B2Transferring verifiable address rights between devices of a data center (DC) network
Publication Date: 2025.05.27 CISCO TECHNOLOGY INC
  • US12316632B2 patent drawing
  • US12316632B2 patent drawing
  • US12316632B2 patent drawing

AI summary

Techniques for transferring address rights (e.g., internet protocol address(es), media access control address(es), etc.) amongst devices in a data center network fabric. A data center (DC) authority (e.g., network controller and/or a service controller) of a data center network fabric may determine that a device in the network is to communicate on an address in the network. The DC authority may create and sign a token that indicates a verifiable authorization to communicate on the address. The token may allow any device that posses the token to communicate on the address, following verification from an associated network switch. Additionally, the token may be signed by a device in the network in possession of the token, and delegated to another device in the data center network fabric following a migration of a service from one server to another, for example.