Domain Identifier Access Policy Control for Network Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for controlling accessibility between multiple data centers are burdensome, requiring extensive configuration and numerous host entries, as they often accept all routes for specified Level 3 ISIDs from all domains, leading to inefficient resource utilization and lack of granular control.
Innovation Solution
Assigning unique domain IDs to network devices and using domain ID-based accept policies to selectively accept or deny routes, allowing for more precise control over which data centers share routes, thereby reducing hardware and configuration requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If ADV-RTR and ISID based accept policies are used to control route acceptance from multiple data centers, then route accessibility control is achieved, but configuration complexity and number of host entries increase significantly
Solution Approach 1:
The patent segments the control mechanism by introducing domain IDs that group data centers into domains. Instead of controlling each data center individually through numerous host entries, routes are controlled at the domain level. Each domain is assigned a unique domain ID, and accept policies reference domain IDs rather than individual host entries, significantly reducing configuration complexity while maintaining granular control over route acceptance from different data centers.
2Adaptability or versatility
If all routes for specified Level 3 ISIDs are accepted from all domains, then route diversity is maximized, but hardware resource utilization increases and granular control is lost
Solution Approach 1:
The patent implements partial action by allowing selective acceptance of routes based on domain ID matching accept policies. Instead of accepting all routes from all domains (excessive action), the system accepts only those routes from domains that match the configured accept policies. This partial acceptance approach maintains necessary route diversity while avoiding the hardware resource consumption associated with processing and storing all possible routes from every domain.
3Measurement precision
If numerous host entries are programmed into data paths to control accessibility, then access control precision is improved, but configuration time and operational burden increase
Solution Approach 1:
The patent introduces domain IDs as an intermediary layer between the control policy and individual host entries. Instead of directly programming numerous specific host entries into data paths (which is time-consuming and operationally burdensome), the system uses domain IDs as mediators. The accept policies reference domain IDs, and the system automatically applies the appropriate control actions to all routes from matching domains. This intermediary approach maintains precise access control while dramatically reducing configuration time and operational burden.
Data Source
AI summary
Methods, systems and computer readable media for domain identifier (ID) based access policy control are described.


