Dynamic Service Device Insertion in Data Center Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy data center designs face challenges in scaling service devices like firewalls and implementing network-level security policies between hosts within the same layer-2 domain, limiting flexibility and scalability in service device deployment and security policy enforcement.

Innovation Solution

The dynamic insertion of network service devices into the network, allowing service devices to be coupled to any network element and providing services independently of physical location, with a network management system that discovers service policies using native APIs and automatically configures network elements to implement these policies, enabling flexible and scalable service deployment and security policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service devices are deployed physically at the network boundary in historic legacy designs, then network traffic for specific VLANs can be routed through configured service devices, but the system lacks scalability to add more firewall capacity and cannot implement network level security policies between hosts within the same layer-2 domain

Engineering Contradiction:
Improveservice device deployment flexibilityVSAvoidnetwork topology configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic service insertion that allows service devices to be inserted into the network path dynamically without manual reconfiguration. The system automatically discovers service devices, determines their service policies, and configures network elements to implement these policies in real-time, transforming the static network boundary deployment model into a dynamic one that adapts to changing service requirements

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a service policy module as an intermediary that mediates between service devices and network elements. This module automatically discovers service policies from service devices using native APIs and translates them into network configuration changes, eliminating the need for manual configuration and enabling seamless integration of service devices anywhere in the network

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service devices are fixed at the network perimeter in historic designs, then security policies can be enforced at the boundary, but the system cannot scale out service devices or implement security policies between hosts within the same layer-2 domain

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidservice device location independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes service devices universal by enabling them to provide security services regardless of their physical location in the network. The dynamic service insertion mechanism allows the same service device to serve multiple functions and protect multiple VLANs or host groups by dynamically configuring network elements to redirect traffic to the service device based on service policies rather than fixed perimeter locations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The service policy module continuously monitors service policies and automatically configures network elements in response to changes. This feedback mechanism ensures that security policies are consistently enforced by detecting policy changes from service devices and automatically translating them into appropriate network configurations, maintaining reliability while enabling location independence

Inventive Principle:
Principle #23Feedback

3Reliability

If manual configuration is used for service device integration in historic designs, then network elements can be configured to route traffic through service devices, but the process is time-consuming and lacks real-time responsiveness to service policy changes

Engineering Contradiction:
Improveservice policy implementationVSAvoidservice device integration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service by enabling service devices to automatically register themselves with the service policy module and have their service policies automatically discovered and implemented. The service policy module autonomously monitors for new service devices, discovers their policies using native APIs, and automatically generates and distributes network configuration changes without human intervention, dramatically reducing integration time from manual processes to automatic real-time operations

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11729059B2Dynamic service device integration
Publication Date: 2023.08.15 ARISTA NETWORKS INC
  • US11729059B2 patent drawing
  • US11729059B2 patent drawing
  • US11729059B2 patent drawing

AI summary

Various embodiments are described herein to enable physical topology independent dynamic insertion of a service device into a network. One embodiment provides for a network system comprising a set of network elements to interconnect a set of host devices, the set of network elements having a physical topology defined by the physical links between network elements in the set of network elements and a logical topology defined by a flow of network data between a network service device and a client of the network service device, wherein the physical topology differs from the logical topology, and a network management device including a service policy module to monitor a service policy of the network service device and automatically configure the logical topology of the network elements based on a change in the service policy.