Distributed Flow Enforcement for Data Center Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network flow policy enforcement systems face inefficiencies, complexities, and increased costs due to conflicts between multiple administrative domains in large-scale data center networks, leading to suboptimal resource utilization and management challenges.

Innovation Solution

Distributed flow enforcement manages heterogeneous sets of flow enforcement policies through a flow manager that receives packet flow rules, generates unified rule sets, splits them into subsets, and installs them on enforcement devices, while also integrating new rules and resolving conflicts to ensure efficient operation across multiple administrative scopes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple flow enforcement policies from multiple administrative scopes are implemented, then policy enforcement capability is improved, but network resource utilization efficiency deteriorates

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidnetwork resource utilization efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments the flow enforcement system into multiple independent flow enforcement devices distributed at different network locations, each capable of enforcing policies from multiple administrative scopes. This segmentation allows parallel processing of policies across different devices, improving resource utilization efficiency while maintaining comprehensive policy enforcement capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic rule set management where flow enforcement devices can receive, process, and install updated rule sets from flow managers. The system dynamically adapts to changing policies across different administrative scopes, optimizing resource allocation in real-time while maintaining versatile policy enforcement.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If multiple flow enforcement policies from multiple administrative scopes are managed, then policy coverage is improved, but management complexity increases

Engineering Contradiction:
Improvepolicy coverageVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces flow managers as intermediary components that centralize the management of flow enforcement policies across multiple administrative scopes. Flow managers receive policies from various sources, resolve conflicts, and distribute simplified rule sets to flow enforcement devices, thereby reducing management complexity while maintaining comprehensive policy coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent divides the management function into separate flow managers that handle specific administrative scopes independently. Each flow manager manages its own rule set and communicates only necessary information to flow enforcement devices, segmenting the management complexity while maintaining broad policy coverage across multiple domains.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple flow enforcement policies from multiple administrative scopes are implemented, then enforcement comprehensiveness is improved, but operational cost increases

Engineering Contradiction:
Improveenforcement comprehensivenessVSAvoidoperational cost
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent segments flow enforcement across multiple distributed devices, each processing only the policies relevant to its location and administrative scope. This segmentation reduces the processing burden on individual devices and enables more efficient resource utilization, lowering operational costs while maintaining comprehensive enforcement capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic rule set updates where flow managers can push updated policies to flow enforcement devices only when necessary. This dynamic approach ensures comprehensive policy enforcement while minimizing unnecessary processing and communication overhead, thereby reducing operational costs.

Inventive Principle:
Principle #15Dynamics

4Reliability

If flow rules are integrated and conflicts resolved, then rule set consistency is improved, but processing time increases

Engineering Contradiction:
Improverule set consistencyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs conflict resolution and rule set consistency checks in advance during the rule installation process. Flow managers pre-process received policies, resolve conflicts before distribution, and validate rule set consistency, thereby ensuring reliability while minimizing processing time during actual packet forwarding operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service mechanisms where flow enforcement devices autonomously install and update rule sets from flow managers without requiring manual intervention. The devices automatically handle rule installation, conflict resolution, and consistency validation, improving reliability while reducing processing time through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7512071B2Distributed flow enforcement
Publication Date: 2009.03.31 ORACLE AMERICAN INC
  • US7512071B2 patent drawing
  • US7512071B2 patent drawing
  • US7512071B2 patent drawing

AI summary

A flow manager may receive packet flow rules from one or more network services and may generate a unified rule set according to the received packet flow rules. A flow manager may additionally split the unified rule set into subsets for enforcement by one or more flow enforcement devices and may install the rule subsets onto the flow enforcement devices. When splitting the unified rule set into subsets, a flow manager may analyze a network topology connecting the flow enforcement devices. A flow manager may also receive additional packet flow rules, integrate them into the unified rule set, update the rule subsets according to the additional rules, and install the updated subsets onto the flow enforcement devices.