Context-Filtering Node for Attribute-Based Service Tagging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing middlebox solutions do not effectively utilize rich-contextual data for data message flows due to the lack of an efficient, distributed scheme for filtering contextual attributes, which limits their ability to process service rules defined by smaller sets of attributes.

Innovation Solution

A method is introduced to configure service nodes on a host to perform context-rich, attribute-based services by using a context-filtering node to collect and compare attributes from service rules and data message flows, generating a service tag that identifies relevant attributes for processing attribute-based service rules, and utilizing an attribute-resolving engine to map service tags to attribute subsets for service operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional hardware appliances are used for middlebox services, then service processing is reliable and stable, but flexibility and control are limited

Engineering Contradiction:
Improveflexibility and controlVSAvoidservice processing reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces traditional hardware appliances with software-based middlebox services running on general-purpose hosts. The service tag generation and attribute filtering mechanisms enable software to achieve the reliability previously requiring dedicated hardware, while gaining the flexibility of software-defined networking and virtualization.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If all captured contextual attributes are processed for each data message flow, then complete service rule matching is achieved, but processing efficiency deteriorates due to the large volume of attributes

Engineering Contradiction:
Improveservice rule processing efficiencyVSAvoidcontextual attribute completeness
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The context-filtering node extracts only the relevant subset of attributes needed for service rule matching, rather than processing all captured contextual attributes. This extraction mechanism generates service tags that contain precisely the attributes required for efficient service rule evaluation, eliminating unnecessary processing overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the attribute processing task into two stages: first, the context-filtering node filters and generates compact service tags; second, service nodes use these tags for efficient rule matching. This segmentation divides the large set of contextual attributes into a manageable subset for each service node.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If service nodes process all attributes from multiple data message flows, then accurate service rules are applied, but the complexity of attribute management increases significantly

Engineering Contradiction:
Improveservice rule matching accuracyVSAvoidattribute management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The context-filtering node acts as an intermediary between data message flows and service nodes. It generates service tags that serve as simplified representations of complex attribute sets, allowing service nodes to match rules accurately without directly managing the full complexity of all contextual attributes.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Use of energy by moving object

If existing middlebox solutions are implemented on hosts, then hardware resource utilization improves, but the ability to utilize rich-contextual data for service processing is reduced

Engineering Contradiction:
Improvehardware resource utilizationVSAvoidcontextual data utilization
Core Design Contradiction:
Use of energy by moving objectVSLoss of information

Solution Approach 1:

The context-filtering node performs preliminary filtering and generates service tags before data messages reach service nodes. This preliminary action prepares the contextual data in advance, enabling service nodes to efficiently utilize rich-contextual information without incurring processing overhead during actual service operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3549015B1Performing context-rich attribute-based services on a host
Publication Date: 2021.10.27 NICIRA INC
  • EP3549015B1 patent drawingFigure 1
  • EP3549015B1 patent drawingFigure 2
  • EP3549015B1 patent drawingFigure 3

AI summary

Some embodiments provide a novel method for configuring a set of service one or more nodes on a host to perform context-rich, attribute-based services on the host computer, which executes several data compute nodes (DCNs) in addition to the set of service nodes. The method uses a context-filtering node on the host to collect a first set of attributes associated with service rules processed by the set of service nodes on the host computer. The context filter also collects a second set of attributes associated with at least one data message flow of a DCN (e.g., of a virtual machine (VM) or container) executing on the host. After collecting the first and second sets of attributes, the context filtering node on the host compares the first and second sets of attributes to generate a service tag to represent a subset of the first set of attributes associated with the data message flow. The method associates this service tag with the data message flow. This service tag can then be used to identify the subset of attributes associated with the data message flow when a service node needs to process its attribute-based service rules for the data message flow.