Classification and Forwarding Node for Disparate Headend Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Building cloud-scale, distributed software as a service (SaaS) offerings faces challenges in segregating tenants at the network layer, securely scaling services, and integrating disparate headend traffic ingress services with backend services while minimizing performance impact.

Innovation Solution

A classification and forwarding node that classifies and forwards packets across multiple data centers, supports various encapsulation protocols, and adds identification metadata to ensure secure and efficient traffic routing between networked computing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple headend services with different encapsulation protocols are integrated with backend services, then service integration capability is improved, but packet processing complexity increases due to protocol conversion requirements

Engineering Contradiction:
Improveservice integration capabilityVSAvoidpacket processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a classification and forwarding node as an intermediary component between headend services and backend services. This node receives packets from headend services using various encapsulation protocols, classifies them based on destination service, and forwards them to appropriate backend services after necessary protocol conversions. The intermediary handles the complexity of protocol translation centrally, allowing headend and backend services to operate independently with different encapsulation protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into distinct functional components: headend services, classification and forwarding nodes, and backend services. Each segment operates with its own encapsulation protocol preferences, while the classification and forwarding nodes handle the integration between segments. This segmentation allows independent service deployment and protocol optimization in each segment without requiring end-to-end protocol compatibility.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If traffic is steered across multiple data centers for service routing, then service flexibility is improved, but network path complexity increases due to multi-hop routing requirements

Engineering Contradiction:
Improveservice flexibilityVSAvoidnetwork path complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where classification and forwarding nodes receive routing information from a centralized controller that tracks service locations and data center operational status. Based on this feedback, the controller dynamically determines optimal traffic paths across data centers, allowing services to be routed flexibly based on real-time conditions without requiring complex routing logic at individual nodes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary actions by having the centralized controller pre-compute and program routing decisions in classification and forwarding nodes before traffic needs to be routed. The controller maintains inventory information about service locations and proactively determines optimal paths, so when traffic arrives, the forwarding nodes can execute pre-programmed routing decisions rather than making real-time routing computations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption and decryption services are applied to customer traffic, then security is improved, but processing time increases due to cryptographic operations

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing encryption and decryption operations at the headend services before traffic enters the classification and forwarding nodes. This allows security operations to be completed in advance, so that when traffic reaches the forwarding infrastructure, the cryptographic processing is already done, minimizing the impact on overall traffic processing time through the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the security processing function from the core network forwarding path by placing encryption and decryption services at the headend before traffic enters the classification and forwarding infrastructure. This separation allows the forwarding nodes to focus purely on routing and classification functions without the computational overhead of cryptographic operations, while security is maintained through the headend services.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11888740B2Classification and forwarding node for integrating disparate headend traffic ingress services with disparate backend services
Publication Date: 2024.01.30 CISCO TECHNOLOGY INC
  • US11888740B2 patent drawing
  • US11888740B2 patent drawing
  • US11888740B2 patent drawing

AI summary

Techniques for integrating disparate headend traffic ingress services with disparate backend services are disclosed herein. The techniques may include receiving, at a classification and forwarding node of a networked computing environment, a data packet encapsulated according to a first encapsulation protocol that is supported by the classification and forwarding node. The techniques may also include determining, by the classification and forwarding node, that the data packet is to be sent to a service from among a group of services associated with the networked computing environment. The classification and forwarding node may also determine whether the first encapsulation protocol is supported by the service. Based at least in part on determining that the service supports a second encapsulation protocol different than the first encapsulation protocol, the classification and forwarding node may encapsulate the data packet according to the second encapsulation protocol and send the data packet to the service.