Agentless Service Insertion in Virtual Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network service solutions in virtualized environments face challenges in scalability and dynamic provisioning due to the limitations of inline network appliances, which do not scale well with virtual machine instantiation, migration, and mobility.

Innovation Solution

A system and method for dynamically and transparently inserting virtual service nodes into virtual networks by associating interface ports with service policies, allowing data traffic to be directed as raw traffic to the service node without requiring control functions, enabling agentless service nodes that can operate without embedded agents and supporting both agentless and agent-based service nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If inline network appliances are used to provide network services, then service functionality is achieved, but scalability and adaptability to virtual machine dynamics deteriorate

Engineering Contradiction:
Improveservice scalabilityVSAvoidservice insertion complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a service gateway as an intermediary component that mediates between virtual machines and service nodes. The service gateway handles service insertion, policy enforcement, and traffic steering, allowing service nodes to be dynamically added or removed without modifying virtual machine configurations or control plane mechanisms. This intermediary approach enables scalable service deployment while maintaining simplicity in service node implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If service nodes are dynamically inserted into virtual networks, then service mobility is improved, but control plane complexity increases

Engineering Contradiction:
Improveservice mobilityVSAvoidcontrol plane complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts control plane functionality from service nodes and centralizes it in the service gateway and existing network controllers. Service nodes become simple data plane entities that forward traffic according to policies defined by the control plane, without requiring embedded agents or complex control logic. This separation enables service mobility while keeping individual service nodes simple.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If agents are embedded in service nodes for integration, then service control is improved, but service node complexity and third-party integration barriers increase

Engineering Contradiction:
Improveservice controlVSAvoidservice node complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The service gateway acts as an intermediary that provides standardized interfaces and protocols for service node integration. Instead of requiring custom agents in each service node, the gateway handles communication, authentication, and policy enforcement using standard network protocols. This approach simplifies service node implementation while maintaining effective control.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If inline network appliances are deployed for each service, then service functionality is achieved, but resource utilization and scalability deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidservice deployment complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal service gateway that can handle multiple service types and protocols through a single platform. The service gateway provides a common framework for service insertion, traffic steering, and policy enforcement that works across different service nodes and virtual machine configurations. This multi-functional approach improves resource utilization by consolidating service infrastructure while maintaining deployment simplicity through standardized interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9178828B2Architecture for agentless service insertion
Publication Date: 2015.11.03 CISCO TECHNOLOGY INC
  • US9178828B2 patent drawing
  • US9178828B2 patent drawing
  • US9178828B2 patent drawing

AI summary

An example method for service insertion in a network environment is provided in one example and includes configuring a service node by tagging one or more interface ports of a virtual switch function to which the service node is connected with one or more policy identifiers. When data traffic associated with a policy identifier is received on a virtual overlay path the virtual switch function may then terminate the virtual overlay path and direct raw data traffic to the interface port of the service node that is tagged to the policy identifier associated with the data traffic.