Dynamic Network Service Insertion via Policy Extension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern enterprise networks face challenges in dynamically adapting to changing conditions due to the complexity of managing and deploying virtualized network services, which lack flexibility in applying different services to network flows and require cumbersome management systems.

Innovation Solution

A system utilizing Kubernetes container management and a policy extension with declarative programming to dynamically insert, manage, and configure network services, allowing for micro-segmentation, flexible policy application, and resource allocation without bringing services down, using Open vSwitch and standard encapsulations like NSH, VLAN, and DiffServ.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network services are implemented as separate dedicated network appliances, then each service performs its functions independently and reliably, but the enterprise cannot rapidly adapt to changing network conditions and the system lacks flexibility

Engineering Contradiction:
Improveservice function reliabilityVSAvoidnetwork adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments network services into virtualized service functions that can be independently deployed, managed, and routed. Each service function is separated into a modular unit that can be dynamically inserted or removed from network paths without affecting other services, enabling both reliability through isolation and adaptability through flexible reconfiguration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic service insertion and removal capabilities where network services can be added, removed, or reconfigured in real-time based on changing network conditions. The system allows dynamic modification of service chains and policy rules without requiring physical reconfiguration or service downtime, enabling rapid adaptation while maintaining service reliability.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If network appliances are virtualized as independent virtual machines, then physical restrictions are removed and deployment flexibility improves, but complex deployment and management systems are required and resource management becomes very complex

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidmanagement system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple virtualized network service functions into a unified platform managed through a single policy-driven control system. Instead of requiring separate management systems for each virtual machine, the invention provides centralized service chain management, resource allocation, and policy enforcement that simplifies the overall management architecture while maintaining deployment flexibility.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal management platform that handles diverse network service functions through a common interface and control mechanism. The system provides multi-functional capabilities including service deployment, resource management, policy enforcement, and dynamic reconfiguration through a single unified system, reducing the need for multiple specialized management tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If all traffic is forwarded from a network port to a service without classification, then deployment is simple, but the operator cannot segment access to critical resources and control over traffic routing is insufficient

Engineering Contradiction:
Improvedeployment simplicityVSAvoidtraffic control capability
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent applies local quality by enabling different service treatments for different traffic flows based on their specific requirements. The system can classify traffic and apply specific service chains, policies, and routing rules to different flows locally, while maintaining simple overall deployment. Each traffic flow receives customized service treatment appropriate to its needs without complicating the deployment process.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If standards-based management ecosystems like ETSI/MANO are used, then the system offers services through standardized interfaces, but the standards are too complex to efficiently implement and manage

Engineering Contradiction:
Improvestandardization compatibilityVSAvoidimplementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential management functions from complex standards frameworks and implements a simplified policy-driven control system that provides standardized interfaces without the full complexity of standards like ETSI/MANO. The invention takes out only the necessary elements for service management, resource allocation, and policy enforcement, creating a leaner implementation that maintains standardization benefits while reducing implementation and operational complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240205144A1Policy Driven Traffic Routing Through Dynamically Inserted Network Services
Publication Date: 2024.06.20 CERTES NETWORKS INC
  • US20240205144A1 patent drawing
  • US20240205144A1 patent drawing
  • US20240205144A1 patent drawing

AI summary

A method of managing and deploying network resources, comprising employing a container management tool in a network that implements resources through one or more containers, and engaging a policy extension with the container management tool. The policy extension may be configured to define and enforce user intent in a forwarding plane of the network. The method may comprise using a declarative programming language to convey the intent of the user to the policy extension. The container management tool may be Kubernetes, and the policy extension may define policy as a Custom Resource Definition. The container may comprise a microservice packaged along with associated dependencies and configurations. The method may further comprise defining, by the user, (i) at least one network resource, (ii) at least one service, (iii) at least one policy, and (iv) delivering network data traffic to the at least one service according to the at least one policy.