Border Router Flow Cache for Asymmetric Application Recognition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In datacenter networks, existing application recognition processes struggle with asymmetric flows, where packets travel through different routers in different directions, leading to incomplete observation of application flows and inefficient resource utilization due to unnecessary recognition on multiple border routers.
Innovation Solution
Implementing a method where the LAN-Side border router observes all packets of an application flow from both directions by using flags (is_LSB and is_WSB) to determine its role and redirect WAN-to-LAN packets through tunnels, ensuring only the LAN-Side border router performs application recognition, thereby reducing unnecessary recognition on other border routers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If application recognition is performed on multiple border routers to handle asymmetric flows, then complete observation of application flows is attempted, but resource utilization deteriorates due to unnecessary recognition on routers that do not need to perform it
Solution Approach 1:
The patent assigns different functional roles to different border routers based on their position in the network topology. The LAN-side border router is designated as the sole application recognition device, while WAN-side border routers perform only packet forwarding. This local differentiation eliminates redundant application recognition operations on WAN-side routers, reducing system resource consumption while maintaining complete flow observation through the LAN-side router's full-duplex monitoring capability.
2Speed
If WAN-to-LAN packets are forwarded directly through WAN-side border router, then forwarding speed is improved, but application recognition accuracy deteriorates because the router cannot observe all flow packets
Solution Approach 1:
The patent introduces a tunnel mechanism as an intermediary between the WAN-side border router and the LAN-side border router. WAN-to-LAN packets are encapsulated in tunnels and forwarded to the LAN-side border router, which then redirects them back to the WAN-side border router for final delivery. This intermediary tunneling approach allows the LAN-side router to observe all packets for accurate application recognition while maintaining efficient packet forwarding through the WAN-side router.
Data Source
AI summary
Techniques whereby a LAN-side border router observes all packets of an application flow from both directions so that the application recognition performed on the LAN-side border router functions properly. A border router may implement flags in a flow cache to indicate whether the border router is the LAN-side border router and/or a WAN-side border router for an application flow. As packets are received at a border router at either the LAN interface or WAN interface, the flags associated with packet's application flows are examined to determine if the border router is the LAN-side border router for the application flow. If so, then application recognition and routing control may be performed. If not, the packet may be redirected to another border router that may be the LAN-side border router or the WAN-side border router for the application flow to insure that border router observes the packet.


