FEC Filter Segmentation for Accurate Traffic Policing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional routers apply filters at a coarse interface granularity, leading to inaccurate billing and policing of packet flows, especially when dealing with traffic from virtual private networks (VPNs), as they include many unrelated packet flows and lack precise control over packet actions based on source and destination sites.

Innovation Solution

The technique involves selectively applying filters based on forwarding equivalence classes (FECs) of packets, allowing for refined actions such as dropping, prioritizing, or billing packets traveling between specific source and destination sites by associating FEC filters with incoming interface information and updating routing information to correlate FEC filters with next hops.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If filters are applied at interface granularity, then filtering coverage is comprehensive, but filtering precision is insufficient and includes unrelated packet flows

Engineering Contradiction:
Improvefiltering precisionVSAvoidfiltering granularity complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the filtering granularity from interface level to forwarding-class level. Instead of applying filters at the coarse interface level that captures all traffic from an interface, the invention divides traffic into multiple forwarding equivalence classes (FECs) based on destination, source, or other criteria. Each FEC can then have its own filter, enabling precise filtering of specific packet flows while excluding unrelated traffic, thus resolving the contradiction between comprehensive coverage and filtering precision.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If filters are applied at interface level, then implementation is simple, but billing and policing accuracy is insufficient

Engineering Contradiction:
Improvebilling accuracyVSAvoidfilter application complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments traffic into forwarding equivalence classes (FECs) that group packets with similar forwarding characteristics. By applying filters at the FEC level rather than interface level, the system can accurately bill and police specific packet flows between particular source and destination sites. This segmentation enables precise measurement and charging of individual customer traffic while maintaining manageable filter configuration through standardized FEC definitions.

Inventive Principle:
Principle #1Segmentation

3Reliability

If interface-specific filters are applied to VPN traffic, then all VPN traffic is controlled, but unrelated packet flows are erroneously included

Engineering Contradiction:
Improvetraffic control accuracyVSAvoidfilter configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments VPN traffic into distinct forwarding equivalence classes based on source site, destination site, or other identifying characteristics. Instead of applying a single interface-specific filter that captures all VPN traffic including unrelated flows, the invention creates separate FECs for different customer sites and applies filters at the FEC level. This ensures that only the intended packet flows are controlled while excluding unrelated traffic, thereby improving reliability without requiring overly complex filter configurations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7889711B1Filtering traffic based on associated forwarding equivalence classes
Publication Date: 2011.02.15 JUNIPER NETWORKS INC
  • US7889711B1 patent drawing
  • US7889711B1 patent drawing
  • US7889711B1 patent drawing

AI summary

Filters are selectively applied to packets depending on forwarding equivalence classes (FECs) of the packets. A FEC filter is defined within the network device and qualified by incoming interface information that identifies source sites of the packets. A label distribution protocol (LDP) FEC is configured such that packets of the given FEC are associated with the FEC filter. The FEC identifies a destination site of the packets received by the router and is automatically combined with incoming interface information. In this way, packet flows may be filtered based on FECs of the packets. FEC filters may be further refined to operate at forwarding class granularity. The techniques allow accurate billing of packets traveling between specific source and destination sites regardless of the number of interfaces of the network device the packets utilize. In addition, the filtering can be used to provide anti-spoofing capabilities.