Edge Network Device Shielding Layer 2 Host Addresses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ethernet networks face scalability limitations due to the limited storage capacity of forwarding tables in switches, exacerbated by the proliferation of host addresses from shared links and virtual machines, which leads to network congestion and inability to accommodate all connected hosts.

Innovation Solution

Implementing edge network devices that shield Layer 2 host addresses by replacing them with substitute addresses from communication channels, reducing the number of entries needed in switch forwarding tables and improving network scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If Ethernet switches store all host addresses in forwarding tables, then packet forwarding accuracy is improved, but forwarding table capacity is exceeded and network scalability deteriorates

Engineering Contradiction:
Improvepacket forwarding accuracyVSAvoidforwarding table capacity
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent introduces a border component as an intermediary device between hosts and the Ethernet network. This border component performs address translation, replacing host Layer 2 addresses with border component addresses in packets forwarded to the network. Consequently, switches only need to store border component addresses rather than all host addresses, resolving the contradiction between forwarding accuracy and table capacity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple hosts share a single link, then link utilization is improved, but the number of host addresses increases and forwarding table overflow worsens

Engineering Contradiction:
Improvelink utilizationVSAvoidnumber of host addresses
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent merges multiple host addresses into a single border component address. When multiple hosts share a link, the border component aggregates their traffic and presents a unified address to the network. This combining approach allows high link utilization while preventing forwarding table overflow, as switches only store the single border component address rather than individual addresses for each host.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If virtual machines are deployed, then computing resource flexibility is improved, but host address proliferation increases and network scalability worsens

Engineering Contradiction:
Improvecomputing resource flexibilityVSAvoidhost address proliferation
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The border component serves as an intermediary that abstracts virtual machine addresses from the network. Virtual machines can be dynamically created and destroyed with flexible addressing, but the border component translates these to stable network-facing addresses. This maintains computing flexibility while preventing address proliferation from reaching the network switches.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If broadcast flooding is used for packet forwarding, then loop-free network operation is maintained, but network congestion increases when many hosts are present

Engineering Contradiction:
Improveloop-free operationVSAvoidnetwork congestion
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple host communication paths through the border component, reducing the number of broadcast domains. Instead of switches performing broadcast flooding across all hosts, the border component consolidates traffic handling. This maintains reliable loop-free operation while reducing network congestion by limiting broadcast scope and improving forwarding efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9948576B2Mechanism for enabling layer two host addresses to be shielded from the switches in a network
Publication Date: 2018.04.17 FORTINET INC
  • US9948576B2 patent drawing
  • US9948576B2 patent drawing
  • US9948576B2 patent drawing

AI summary

Methods and systems for shielding layer two host addresses (e.g., MAC addresses) from a network are provided. An edge network device interposed between a network of switches and multiple local hosts receives from a first local host a first packet destined for a first destination host. The first local host has a first layer 2 (L2) address and a first layer 3 (L3) address associated therewith. The first packet includes the first L2 address as a source L2 address of the first packet, and includes the first L3 address as a source L3 address of the first packet. The edge network device shields the first L2 address from the network of switches by replacing the source L2 address for the first packet with a first substitute L2 address of a first communication channel of the edge network device before sending the first packet to the network of switches.