Network Device Data Plane Sandboxes for Third-Party Packet Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network devices lack effective mechanisms for securely and efficiently managing third-party access to internal packet forwarding paths, leading to potential misconfiguration and security risks due to the integration of external controllers and applications with native forwarding logic.

Innovation Solution

The implementation of 'sandboxes' within the network device's data plane, which provide isolated, parallel, and asynchronous forwarding path logic, allowing third-party applications to configure and control packet processing operations while maintaining isolation and resource constraints to prevent misuse or malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party applications are integrated with native forwarding logic, then functionality and adaptability are improved, but security and reliability deteriorate due to potential misconfiguration and malicious attacks

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the forwarding logic into separate sandboxes that isolate third-party applications from native forwarding logic. Each sandbox operates as an independent container with its own configuration space, preventing third-party applications from directly accessing or modifying native forwarding structures. This segmentation maintains functionality while enhancing security by containing potential malicious actions within sandbox boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces sandboxes as intermediary layers between third-party applications and the native forwarding logic. These sandboxes act as mediators that allow third-party applications to configure and control packet processing operations without directly accessing native forwarding structures. The sandbox interface provides controlled access points, enabling functionality while preventing unauthorized modifications to core forwarding logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If third-party applications have direct access to forwarding path, then ease of operation is improved, but device complexity increases due to configuration dependencies and potential conflicts

Engineering Contradiction:
ImproveaccessibilityVSAvoidconfiguration dependencies
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent divides the forwarding path configuration into separate sandbox containers, each managing its own configuration independently. This segmentation eliminates configuration dependencies between third-party applications and native logic, as each sandbox operates autonomously within its designated space. Third-party applications can easily configure their operations without affecting or being affected by other configurations, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts third-party application configurations from the native forwarding logic into separate sandbox containers. This extraction removes configuration dependencies and potential conflicts between third-party and native operations. Third-party applications gain easy access to forwarding path functionality through their dedicated sandboxes without introducing complexity to the core native forwarding structures.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If third-party applications control packet forwarding, then adaptability is improved, but resource exhaustion risks increase due to lack of constraints

Engineering Contradiction:
Improvecontrol capabilityVSAvoidresource exhaustion prevention
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by providing each third-party application with a dedicated sandbox environment that has specific resource constraints and permissions tailored to its needs. Each sandbox operates with localized resource allocation, preventing any single third-party application from exhausting global forwarding resources. This approach maintains adaptability by allowing each application full control within its sandbox while preventing resource exhaustion through localized constraints.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The sandbox acts as an intermediary that mediates between third-party applications and shared forwarding resources. It provides third-party applications with control capability over packet forwarding within their designated space while simultaneously enforcing resource constraints. The sandbox interface allows applications to utilize forwarding resources without direct access to the underlying resource management mechanisms, preventing resource exhaustion through controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3429144B1Network device data plane sandboxes for third-party controlled packet forwarding paths
Publication Date: 2020.02.19 JUNIPER NETWORKS INC
  • EP3429144B1 patent drawingFigure 1
  • EP3429144B1 patent drawingFigure 2
  • EP3429144B1 patent drawingFigure 3

AI summary

In some examples, a network device comprises a first application and a second application; a forwarding unit comprising an interface card to receive a packet; a packet processor; an internal forwarding path of the forwarding unit; a forwarding unit processor; a first interface; and a second interface. The first application is configured to configure, via the first interface, the internal forwarding path to include a sandbox that comprises a container for instructions to be configured inline within the internal forwarding path. The second application is configured to configure, via the second interface, the sandbox with second instructions that determine processing of packets within the sandbox. The packet processor is configured to process, in response to determining a packet received by the forwarding unit is associated with a packet flow controlled at least in part by the second application, the packet by executing the second instructions configured for the sandbox.