Ethernet Switch Network Monitoring via Packet Steering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network switches complicate monitoring and evaluation of data stream transport in large-scale networks, leading to inefficiencies in network infrastructure performance assessment, security concerns, and data packet mis-routing due to limitations in existing monitoring devices and techniques.

Innovation Solution

A flexible, high-performance active network tap system utilizing modified Ethernet switching integrated circuits with a system controller for configurable data packet routing, aggregation, and filtering, enabling simultaneous monitoring and analysis across multiple ports while maintaining data integrity and bandwidth management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional Ethernet switches employ intelligent routing techniques to minimize switch transit latency and uniquely route data packets, then network data distribution efficiency is improved, but network monitoring capability deteriorates

Engineering Contradiction:
Improvenetwork data distribution efficiencyVSAvoidnetwork monitoring capability
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the switch functionality by separating data plane (packet forwarding) from monitoring plane (packet copying). Each ingress port has an associated egress port that copies packets to monitoring ports, creating independent monitoring paths that do not interfere with normal data routing operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces monitoring ports as intermediary elements that receive copies of packets from dedicated egress ports. These monitoring ports act as intermediaries between the data plane and monitoring devices, allowing packet inspection without affecting the primary data distribution paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If passive tapping of network segments is used to monitor data streams, then monitoring implementation is simple, but signal quality degrades and noise increases

Engineering Contradiction:
Improvemonitoring implementation simplicityVSAvoidsignal quality
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent uses packet copying at the protocol level rather than passive signal tapping. The switch hardware creates exact copies of data packets through buffer memory, preserving signal integrity while enabling monitoring. This copying mechanism avoids the signal degradation and noise problems of passive tapping.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/passive signal tapping approach with a digital packet copying mechanism. Instead of physically tapping cables and amplifying signals (which introduces noise and degrades quality), the system copies packets through memory buffers, maintaining digital signal integrity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Difficulty of detecting and measuring

If active tap devices are physically inserted into network segments to copy data packets, then monitoring capability is improved, but device complexity increases and aggregation/filtering capability is limited

Engineering Contradiction:
Improvemonitoring capabilityVSAvoiddevice complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent makes the network switch itself universal by enabling it to perform both data forwarding and packet monitoring functions. The switch hardware is configured to copy packets to multiple monitoring ports simultaneously, providing multi-functionality without requiring separate dedicated monitoring devices for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the monitoring function into the existing switch infrastructure by utilizing its buffer memory and packet processing capabilities. Instead of separate active tap devices, the switch's own resources are employed to copy and distribute packets to multiple monitoring destinations, reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

4Difficulty of detecting and measuring

If SPAN or MIRROR port capabilities are implemented in network switches to monitor data streams, then monitoring functionality is improved, but internal bandwidth requirements increase and network performance degrades

Engineering Contradiction:
Improvemonitoring functionalityVSAvoidnetwork performance
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of energy

Solution Approach 1:

The patent applies local quality by copying packets at the ingress port level rather than requiring full network bandwidth for monitoring. Each ingress port has a dedicated egress port that handles only the copied packets for monitoring, localizing the monitoring traffic impact to specific port pairs rather than affecting overall network bandwidth.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7792046B2Ethernet switch-based network monitoring system and methods
Publication Date: 2010.09.07 NETSCOUT SYSTEMS INC
  • US7792046B2 patent drawing
  • US7792046B2 patent drawing
  • US7792046B2 patent drawing

AI summary

A network data monitoring device provides for the flexible, programmable port-to-multi-port steering of data packet traffic between network port pairs, with tap data streams being directed to any of a plurality of monitor ports. The network data monitoring device is constructed utilizing one or more switching integrated circuits programmed to disable layer-2 routing and impose port-to-multiport data packet steering. Physical layer protocol encoding/decoding circuits enable connectivity to physical network media connectors though a system of fail-safe relays. A system controller, preferably implemented by a microprocessor, is connected to all switching integrated circuits and relays for configuration, status and control. Hardware-based logic selectively in complement to the switching integrated circuits provides for the programmable filtering, modification and programmable steering of data packets through the device.