Hardware-Assisted Service Insertion in Multi-Site Data Center Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current networking technologies face challenges in efficiently managing bi-directional traffic across multiple data centers with inter-site service insertion, particularly in ensuring symmetric routing and policy enforcement for disaster recovery and security across geographically dispersed sites.
Innovation Solution
The implementation of hardware-assisted network devices with high-speed memory and logic circuitry, such as ASICs, that use arithmetic or bitwise operators to deterministically route packets through insertable services like DPI, LB, IPS, and firewalls based on policies and contracts, ensuring symmetric bi-directional traffic and service insertion across multiple sites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service insertion is performed in a chain through multiple services (firewall, IPS, malware protection), then security and policy enforcement are improved, but device complexity and processing time increase
Solution Approach 1:
The patent segments the service chain processing by introducing service insertion points at specific locations in the network fabric (e.g., between spine and leaf switches). This allows security services to be inserted at optimal points without requiring all services to be chained sequentially through a single complex device, thereby reducing overall system complexity while maintaining security effectiveness.
Solution Approach 2:
The patent introduces intermediary components such as service gateway switches and service insertion points that mediate between the core network fabric and security services. These intermediaries simplify the integration of multiple security services by providing standardized interfaces and handling the complexity of service chaining, allowing firewall, IPS, and malware protection to work together without direct complex interconnections.
2Speed
If hardware-assisted routing with ASICs is implemented, then routing speed and determinism are improved, but device complexity and cost increase
Solution Approach 1:
The patent implements multi-functional network devices that can operate in different modes (e.g., as fabric switches, service gateway switches, or edge switches) depending on configuration. The ASICs are designed to handle multiple functions including standard routing, service insertion, and policy enforcement, reducing the need for specialized hardware for each function and optimizing the complexity-performance ratio.
Solution Approach 2:
The patent applies hardware-assisted routing with ASICs selectively at critical points in the network where high-speed deterministic routing is most beneficial (e.g., at service insertion points and gateway switches), rather than throughout the entire network fabric. This partial application of complex hardware provides the necessary speed and determinism where needed while keeping overall device complexity manageable.
3Reliability
If symmetric routing is enforced for bi-directional traffic, then policy consistency and security are improved, but routing flexibility and complexity increase
Solution Approach 1:
The patent implements preliminary configuration of symmetric routing policies at service gateway switches and fabric interconnects. By pre-configuring the routing symmetry requirements and service insertion points, the system ensures consistent policy enforcement for bi-directional traffic without requiring complex real-time calculations. The symmetric paths are established in advance through configuration protocols and policy definitions.
Solution Approach 2:
The patent incorporates feedback mechanisms where service gateway switches monitor and track the application of policies to bi-directional traffic flows. This feedback ensures that symmetric routing is maintained and policies are consistently enforced in both directions, allowing for automated detection and correction of any asymmetries without manual intervention.
Data Source
AI summary
An embodiment of the present disclosure is directed a set of data centers and associated controls in which the data centers include network fabric comprises network routing devices configured to route bi-directional traffic symmetrically through insertable service, e.g., via the associated inter-site and intra-site controls, for a given set of policies or contracts using an ASIC or circuit-assisted arithmetic logic, enforcing such policies at the local network devices, to deterministically select the insertable services.


