Per-Input Port Control Plane Policing via Virtual Output Queues

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network elements, such as routers and switches, are vulnerable to denial of service attacks that flood control plane processors with innocuous control plane network data, leading to resource exhaustion and disruption of legitimate traffic processing.

Innovation Solution

Implementing per-input port, per-control plane network data traffic class policing using virtual output queues (VOQs) that classify and manage control plane network data based on traffic classes, applying policer tests to isolate and drop excessive traffic, thereby protecting the control plane processor from resource exhaustion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If control plane network data is processed without classification and policing, then all control plane traffic is handled uniformly, but denial of service attacks can exhaust control plane processor resources

Engineering Contradiction:
Improvecontrol plane processor availabilityVSAvoidtraffic management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments control plane network data into multiple classes based on traffic characteristics, creating separate output queues for each class. This segmentation allows differential policing strategies to be applied to different traffic types, protecting the control plane processor from resource exhaustion by attack traffic while maintaining proper handling of legitimate control plane data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual output queues (VOQs) as an intermediary mechanism between the input ports and the control plane processor. These VOQs act as buffers and classification points that enable policing of excessive traffic before it reaches the control plane processor, thereby protecting the processor without requiring direct modification of the processing logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If per-input port, per-class policing is implemented, then excessive attack traffic can be isolated and dropped, but the network element requires more complex queue management

Engineering Contradiction:
Improveimpact of denial of service attacksVSAvoidqueue management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a matrix of virtual output queues where each queue corresponds to a specific combination of input port and traffic class. This segmentation enables precise policing at the intersection of port and class dimensions, allowing attack traffic from specific ports to be isolated without affecting other ports or traffic classes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different policing parameters and thresholds to different virtual output queues based on their specific input port and traffic class characteristics. This local quality approach allows the system to be highly selective in dropping only the excessive attack traffic while maintaining lenient policies for legitimate traffic classes.

Inventive Principle:
Principle #3Local quality

3Productivity

If control plane network data is queued without classification, then queue management is simpler, but legitimate traffic may be disrupted by attack traffic in the same queue

Engineering Contradiction:
Improvelegitimate control plane traffic processingVSAvoidtraffic class classification complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments control plane network data into distinct traffic classes based on characteristics such as protocol type, source/destination addresses, or other identifying features. Each class receives dedicated virtual output queues, ensuring that legitimate traffic in one class cannot be disrupted by attack traffic in another class.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The policing mechanism monitors the rate of traffic arrival at each virtual output queue and provides feedback by dropping packets that exceed configured thresholds. This feedback loop prevents any single traffic class from monopolizing control plane processor resources, thereby protecting legitimate traffic processing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11165887B2Per-input port, per-control plane network data traffic class control plane policing
Publication Date: 2021.11.02 ARISTA NETWORKS INC
  • US11165887B2 patent drawing
  • US11165887B2 patent drawing
  • US11165887B2 patent drawing

AI summary

Methods and systems for per-input port, per-control plane network data traffic class control plane policing in a network element are described. In one embodiment, the method comprises receiving control plane network data at an input port of a network element, wherein the control plane network data is data that is processed by the control plane. The method may also include classifying the control plane network data based on characteristics of the control plane network data. Furthermore, the method may include storing the control plane network data in one of a plurality of output queues for the input port based on a class of the control plane network data, and forwarding control plane network data from a selected one of the plurality of output queues to a control plane of the network element.