Aggregation Device Flowtag Routing for Virtualized Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network switches require resource-intensive processing for MAC address lookups and management in large data centers, especially in virtualized environments, which increases hardware demands and exposes MAC addresses to spoofing risks.

Innovation Solution

An aggregation device generates a flowtag with a port identifier mapped to a destination MAC address, allowing software-based routing instead of hardware-intensive CAM table lookups, and validates credentials to secure data transfers, reducing the need for MAC address exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network switches use hardware-intensive CAM table lookups for MAC address routing, then routing accuracy is maintained, but hardware processing requirements and resource consumption increase significantly

Engineering Contradiction:
Improverouting accuracyVSAvoidhardware processing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a credential validation mechanism as an intermediary layer between MAC address reception and routing decision. Instead of directly using MAC addresses for routing lookups, the system validates credentials first, then uses the validated credential information to determine routing actions. This mediator approach maintains routing accuracy while reducing hardware processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical hardware-intensive CAM table lookup system with a software-based credential validation and routing determination system. By substituting the traditional hardware switching mechanism with a software-based authentication and routing process, the system reduces hardware processing requirements while maintaining routing functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If network switches expose MAC addresses for routing lookups, then data forwarding is enabled, but security risks from MAC address spoofing increase

Engineering Contradiction:
Improvedata forwarding capabilityVSAvoidMAC address spoofing risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the MAC address information from the routing decision process and replaces it with validated credential information. By taking out the exposed MAC address and substituting it with authenticated credentials, the system enables data forwarding capability while eliminating the security vulnerability associated with MAC address exposure and spoofing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary credential validation before routing decisions are made. This preliminary anti-action prevents MAC address spoofing attacks by authenticating the source credentials before allowing any routing operations, thereby protecting against harmful factors while maintaining legitimate data forwarding operations.

Inventive Principle:
Principle #9Preliminary anti-action

3Adaptability or versatility

If network switches perform MAC address lookups in virtualized environments, then virtual machine connectivity is maintained, but resource consumption and processing overhead increase

Engineering Contradiction:
Improvevirtual machine connectivityVSAvoidresource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary credential validation and routing determination before actual data forwarding operations. By pre-validating credentials and determining routing paths in virtualized environments, the system maintains virtual machine connectivity while reducing resource consumption during high-volume data transfer operations, as the intensive validation occurs less frequently.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2920940B1Method and device for data flow processing
Publication Date: 2018.12.26 ADVANCED MICRO DEVICES INC
  • EP2920940B1 patent drawingFigure 1
  • EP2920940B1 patent drawingFigure 2
  • EP2920940B1 patent drawingFigure 3

AI summary

Described are a system and method for managing a data exchange in a network environment. A flowtag is assigned to a data packet at a source device 112-1). The flowtag includes a port identification corresponding to a port (Port 2) at an aggregation device (200). A destination device (112-2) is in communication with the port at the aggregation device. The data packet is authenticated at the aggregation device. The data packet is output from the source device to the destination device via the aggregation device according to the port identification in the flowtag of the authenticated data packet.