Ingress Device EPG Isolation via Packet Marking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data center security solutions, such as private VLANs, struggle to provide intra-Endpoint Group (EPG) isolation efficiently, especially in virtualized environments, leading to complexity and resource constraints, and do not support VxLAN-based endpoints effectively.

Innovation Solution

Implementing techniques that allow an ingress network device to mark packets with source EPG information, enabling intra-EPG isolation by incorporating security tags and QoS fields into packet headers, and using policy-based models to restrict communication within isolated EPGs, thereby preventing unauthorized traffic without the need for additional VLANs or promiscuous ports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private VLANs are used to provide intra-EPG isolation, then security between endpoints is improved, but device complexity and resource usage increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter of security enforcement from port-level (traditional VLANs) to packet-level (header marking). By marking packets with EPG identifiers in the header and enforcing policies at the network fabric level, the system achieves intra-EPG isolation without requiring complex private VLAN configurations with promiscuous ports, thereby improving security while reducing device complexity

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts the security enforcement function from the access layer switches to the network fabric core. By implementing EPG isolation policies at the fabric level using header markings, the system removes the need for complex private VLAN implementations at the edge devices, reducing their complexity while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If multiple VLANs are used to support VxLAN-based endpoints, then endpoint isolation is improved, but resource constraints worsen

Engineering Contradiction:
ImproveisolationVSAvoidresource usage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent makes the packet header fields universal by using existing QoS and security tag fields for dual purposes: traditional QoS classification and EPG identification. This multi-functionality allows VxLAN-based endpoints to be isolated without requiring additional VLAN resources, as the same header fields serve both QoS and security isolation functions

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional VLAN-based security models are used, then endpoint security is improved, but adaptability to virtualized environments worsens

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent substitutes the mechanical VLAN switching system with a software-based policy enforcement mechanism. By marking packets with EPG identifiers and using policy-based routing in the network fabric, the system replaces hardware-based VLAN isolation with a more flexible software-defined approach that adapts to virtualized environments while maintaining security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10171344B1Isolation of endpoints within an endpoint group
Publication Date: 2019.01.01 CISCO TECHNOLOGY INC
  • US10171344B1 patent drawing
  • US10171344B1 patent drawing
  • US10171344B1 patent drawing

AI summary

An ingress network device of a network fabric mark packets with source endpoint group information to enable intra-EPG isolation. The ingress network device receives an indication of endpoints associated with an isolated endpoint group that restricts network traffic among members of the isolated endpoint group. The ingress network device receives a packet from a source and detects that the source endpoint belongs to the isolated endpoint group. The ingress network device incorporates source endpoint group information into a header of the packet. The source endpoint group information indicates that the source endpoint belongs to the isolated endpoint group.