Dynamic Network Service Insertion via Policy Extension
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern enterprise networks face challenges in dynamically adapting to changing conditions due to the complexity of managing and deploying virtualized network services, which lack flexibility in applying different services to network flows and require cumbersome management systems.
Innovation Solution
A system utilizing Kubernetes container management and a policy extension with declarative programming to dynamically insert, manage, and configure network services, allowing for micro-segmentation, flexible policy application, and resource allocation without bringing services down, using Open vSwitch and standard encapsulations like NSH, VLAN, and DiffServ.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network services are implemented as separate dedicated network appliances, then each service performs its functions independently and reliably, but the enterprise cannot rapidly adapt to changing network conditions and the system lacks flexibility
Solution Approach 1:
The patent segments network services into virtualized service functions that can be independently deployed, managed, and routed. Each service function is separated into a modular unit that can be dynamically inserted or removed from network paths without affecting other services, enabling both reliability through isolation and adaptability through flexible reconfiguration.
Solution Approach 2:
The patent implements dynamic service insertion and removal capabilities where network services can be added, removed, or reconfigured in real-time based on changing network conditions. The system allows dynamic modification of service chains and policy rules without requiring physical reconfiguration or service downtime, enabling rapid adaptation while maintaining service reliability.
2Adaptability or versatility
If network appliances are virtualized as independent virtual machines, then physical restrictions are removed and deployment flexibility improves, but complex deployment and management systems are required and resource management becomes very complex
Solution Approach 1:
The patent merges multiple virtualized network service functions into a unified platform managed through a single policy-driven control system. Instead of requiring separate management systems for each virtual machine, the invention provides centralized service chain management, resource allocation, and policy enforcement that simplifies the overall management architecture while maintaining deployment flexibility.
Solution Approach 2:
The patent creates a universal management platform that handles diverse network service functions through a common interface and control mechanism. The system provides multi-functional capabilities including service deployment, resource management, policy enforcement, and dynamic reconfiguration through a single unified system, reducing the need for multiple specialized management tools.
3Ease of manufacture
If all traffic is forwarded from a network port to a service without classification, then deployment is simple, but the operator cannot segment access to critical resources and control over traffic routing is insufficient
Solution Approach 1:
The patent applies local quality by enabling different service treatments for different traffic flows based on their specific requirements. The system can classify traffic and apply specific service chains, policies, and routing rules to different flows locally, while maintaining simple overall deployment. Each traffic flow receives customized service treatment appropriate to its needs without complicating the deployment process.
4Adaptability or versatility
If standards-based management ecosystems like ETSI/MANO are used, then the system offers services through standardized interfaces, but the standards are too complex to efficiently implement and manage
Solution Approach 1:
The patent extracts the essential management functions from complex standards frameworks and implements a simplified policy-driven control system that provides standardized interfaces without the full complexity of standards like ETSI/MANO. The invention takes out only the necessary elements for service management, resource allocation, and policy enforcement, creating a leaner implementation that maintains standardization benefits while reducing implementation and operational complexity.
Data Source
AI summary
A method of managing and deploying network resources, comprising employing a container management tool in a network that implements resources through one or more containers, and engaging a policy extension with the container management tool. The policy extension may be configured to define and enforce user intent in a forwarding plane of the network. The method may comprise using a declarative programming language to convey the intent of the user to the policy extension. The container management tool may be Kubernetes, and the policy extension may define policy as a Custom Resource Definition. The container may comprise a microservice packaged along with associated dependencies and configurations. The method may further comprise defining, by the user, (i) at least one network resource, (ii) at least one service, (iii) at least one policy, and (iv) delivering network data traffic to the at least one service according to the at least one policy.


