Hardware-Assisted Service Insertion in Multi-Site Data Center Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current networking technologies face challenges in efficiently managing bi-directional traffic across multiple data centers with inter-site service insertion, particularly in ensuring symmetric routing and policy enforcement for disaster recovery and security across geographically dispersed sites.

Innovation Solution

The implementation of hardware-assisted network devices with high-speed memory and logic circuitry, such as ASICs, that use arithmetic or bitwise operators to deterministically route packets through insertable services like DPI, LB, IPS, and firewalls based on policies and contracts, ensuring symmetric bi-directional traffic and service insertion across multiple sites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service insertion is performed in a chain through multiple services (firewall, IPS, malware protection), then security and policy enforcement are improved, but device complexity and processing time increase

Engineering Contradiction:
Improvesecurity enforcementVSAvoidservice chain complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the service chain processing by introducing service insertion points at specific locations in the network fabric (e.g., between spine and leaf switches). This allows security services to be inserted at optimal points without requiring all services to be chained sequentially through a single complex device, thereby reducing overall system complexity while maintaining security effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as service gateway switches and service insertion points that mediate between the core network fabric and security services. These intermediaries simplify the integration of multiple security services by providing standardized interfaces and handling the complexity of service chaining, allowing firewall, IPS, and malware protection to work together without direct complex interconnections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If hardware-assisted routing with ASICs is implemented, then routing speed and determinism are improved, but device complexity and cost increase

Engineering Contradiction:
Improverouting speedVSAvoidhardware complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements multi-functional network devices that can operate in different modes (e.g., as fabric switches, service gateway switches, or edge switches) depending on configuration. The ASICs are designed to handle multiple functions including standard routing, service insertion, and policy enforcement, reducing the need for specialized hardware for each function and optimizing the complexity-performance ratio.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies hardware-assisted routing with ASICs selectively at critical points in the network where high-speed deterministic routing is most beneficial (e.g., at service insertion points and gateway switches), rather than throughout the entire network fabric. This partial application of complex hardware provides the necessary speed and determinism where needed while keeping overall device complexity manageable.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If symmetric routing is enforced for bi-directional traffic, then policy consistency and security are improved, but routing flexibility and complexity increase

Engineering Contradiction:
Improvepolicy consistencyVSAvoidrouting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary configuration of symmetric routing policies at service gateway switches and fabric interconnects. By pre-configuring the routing symmetry requirements and service insertion points, the system ensures consistent policy enforcement for bi-directional traffic without requiring complex real-time calculations. The symmetric paths are established in advance through configuration protocols and policy definitions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where service gateway switches monitor and track the application of policies to bi-directional traffic flows. This feedback ensures that symmetric routing is maintained and policies are consistently enforced in both directions, allowing for automated detection and correction of any asymmetries without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240056386A1Hardware-Assisted Scheme for Macro-Segment Based Distributed Service Insertion in Multi-Site Data Center Switches
Publication Date: 2024.02.15 CISCO TECHNOLOGY INC
  • US20240056386A1 patent drawing
  • US20240056386A1 patent drawing
  • US20240056386A1 patent drawing

AI summary

An embodiment of the present disclosure is directed a set of data centers and associated controls in which the data centers include network fabric comprises network routing devices configured to route bi-directional traffic symmetrically through insertable service, e.g., via the associated inter-site and intra-site controls, for a given set of policies or contracts using an ASIC or circuit-assisted arithmetic logic, enforcing such policies at the local network devices, to deterministically select the insertable services.