Context Export from Access Point to Fabric Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Enterprise Fabric Environments, context information such as session information is not available on the switching infrastructure, making it difficult to apply policies and manage roaming efficiently, as data packets directly go from an access point to the fabric without necessary context.

Innovation Solution

The method involves an access point encapsulating data packets with context information, which is then decapsulated by an autonomous system to apply client-specific policies and forward packets to the next hop in the network, and also exports this context information for analytics and policy download during roaming.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If data packets are transmitted directly from access point to fabric without encapsulation, then transmission speed is improved, but context information becomes unavailable on switching infrastructure

Engineering Contradiction:
Improvetransmission speedVSAvoidcontext information availability
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent implements packet encapsulation where the original data packet is nested within an outer packet header that contains context information. The access point encapsulates the inner packet (original data) with an outer header containing context information such as client ID, session ID, and policy information. This nested structure allows context information to be carried along with the data packet through the fabric infrastructure without interfering with the original data transmission, thus resolving the contradiction between maintaining transmission speed and preserving context information availability.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces an intermediary packet header structure that mediates between the data packet and the switching infrastructure. The outer packet header acts as an intermediary carrier that contains context information needed by the switching infrastructure, while the inner packet carries the actual data. This intermediary structure enables the switching infrastructure to access context information without requiring changes to the underlying data transmission protocol, thus maintaining transmission speed while providing context information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If context information is encapsulated with every packet, then policy application capability is improved, but device complexity increases

Engineering Contradiction:
Improvepolicy application capabilityVSAvoidencapsulation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the packet structure into distinct functional components: an outer header containing context information and policy-related fields, and an inner packet containing the actual data. This segmentation allows the switching infrastructure to process only the outer header for policy decisions without needing to parse or understand the inner packet content. The segmented structure improves policy application capability while managing device complexity by clearly defining the boundaries and purposes of each packet component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making different parts of the packet serve different functions with appropriate levels of detail. The outer header contains only the specific context information needed for policy application (client ID, session ID, service type), while the inner packet maintains its original structure and content. This localized approach to information inclusion improves policy application capability by providing exactly the right information at the right level, without unnecessarily increasing overall device complexity through redundant or excessive data inclusion.

Inventive Principle:
Principle #3Local quality

3Productivity

If context information is made available throughout the network, then roaming efficiency is improved, but information security risks increase

Engineering Contradiction:
Improveroaming efficiencyVSAvoidinformation security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential context information needed for roaming operations from the complete set of available data. The outer packet header contains specifically extracted fields such as client ID, session ID, and service type that are sufficient for roaming decisions. By extracting only the necessary information rather than transmitting all available context data, the patent improves roaming efficiency while minimizing information security risks associated with exposing sensitive information across the network.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary encapsulation of context information at the access point before packets enter the fabric infrastructure. This preliminary action ensures that context information is already prepared and organized in the outer header when packets reach switching infrastructure elements. For roaming scenarios, this means context information is already available at the new access point when a client roams, enabling fast roaming without requiring real-time information exchange during the roaming event. This preliminary preparation improves roaming efficiency while maintaining security by controlling where and how context information is exposed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10298717B2Context export from an access point to a fabric infrastructure
Publication Date: 2019.05.21 CISCO TECHNOLOGY INC
  • US10298717B2 patent drawing
  • US10298717B2 patent drawing
  • US10298717B2 patent drawing

AI summary

Aspects of the embodiments are directed to a network element that is configured for receiving, from an access point, a data packet originating from a client, the data packet comprising a packet header that comprises a packet header augmented with context information; decapsulating the packet header to identify the context information; applying a client-specific policy on the packet based, at least in part, on the context information; and forwarding the packet to a next hop in the network. The network element can be part of a network, such as a datacenter fabric architecture.