Client Modeling in Forwarding Plane for Scalable Policy Application
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Layer 2 forwarding engines face limitations in scalability and impact client roam rate due to VLAN-based forwarding, which restricts effective policy application in wireless applications.
Innovation Solution
A method and apparatus that model a client node in the forwarding plane using a logical entity table, allowing policies to be applied based on client identity, enabling separate representation and management of client nodes, thereby improving policy application and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If VLAN-based forwarding is used in conventional Layer 2 forwarding engines, then policy application is simplified through VLAN grouping, but scalability is limited and client roam rate is impacted
Solution Approach 1:
The patent segments the forwarding decision process by introducing client identity as a separate lookup dimension alongside VLAN. The forwarding engine now performs two-stage lookup: first VLAN-based forwarding for basic routing, then client identity-based policy application for精细化 control. This segmentation allows independent optimization of each layer without mutual constraint.
Solution Approach 2:
The patent adds a new dimension to the forwarding table by incorporating client identity (such as device ID, MAC address, or subscriber identifier) as an additional lookup key beyond traditional VLAN membership. This dimensional expansion transforms the forwarding table from a two-dimensional VLAN-policy structure to a multi-dimensional (VLAN + Client Identity) structure, enabling finer-grained policy control without sacrificing roaming performance.
2Adaptability or versatility
If VLAN-based forwarding is used, then network segmentation is achieved, but scalability is limited
Solution Approach 1:
The patent segments the forwarding decision process by introducing client identity as a separate lookup dimension alongside VLAN. The forwarding engine now performs two-stage lookup: first VLAN-based forwarding for basic routing, then client identity-based policy application for精细化 control. This segmentation allows independent optimization of each layer without mutual constraint.
Solution Approach 2:
The patent creates a universal client identity model that can represent diverse client types (wireless devices, wired hosts, mobile users) through a common identification framework. This universal model allows the same forwarding infrastructure to handle multiple client types and scenarios, significantly improving scalability while maintaining network segmentation capabilities.
3Ease of operation
If policies are configured on VLANs, then policy management is simplified, but precise client-specific policy application becomes difficult
Solution Approach 1:
The patent segments the forwarding decision process by introducing client identity as a separate lookup dimension alongside VLAN. The forwarding engine now performs two-stage lookup: first VLAN-based forwarding for basic routing, then client identity-based policy application for精细化 control. This segmentation allows independent optimization of each layer without mutual constraint.
Solution Approach 2:
The patent enables local quality by allowing different policy precision levels for different clients within the same VLAN. Each client entry in the forwarding table can have its own specific policy set, enabling tailored policy application (such as different QoS levels, bandwidth limits, or access controls) for individual clients while maintaining the broader VLAN structure for simplified overall management.
Data Source
AI summary
In one embodiment, a method includes receiving a packet at a network device in communication with a plurality of client nodes, the packet identifying a first client node, performing a look up in a table stored at the network device to locate policies associated with the first client node, the table including an entry for each of the client nodes, each entry having a plurality of policies associated with the client node, applying the policies associated with the first client node at a forwarding engine at the network device, and forwarding the packet from the network device. An apparatus is also disclosed.


