Flexible Lookup Key Generation in Network Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network switches have fixed, static lookup keys that do not allow for dynamic configuration of security and routing policies at runtime, limiting flexibility and scalability in managing network traffic.

Innovation Solution

A network switch with a control CPU and switching logic circuitry that supports flexible lookup key generation, enabling users to dynamically select and configure a subset of fields to form lookup keys for table searches, allowing for runtime changes in security and routing policies without rebooting the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If fixed static fields are used for lookup keys, then device complexity is reduced and ease of manufacture is improved, but adaptability and versatility deteriorate as users cannot dynamically configure security policies

Engineering Contradiction:
Improvelookup key configurabilityVSAvoidkey generation mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic lookup key generation by allowing users to select from multiple predefined fields at runtime. The control CPU dynamically constructs lookup keys by combining selected fields according to user-defined policies, transforming the static key generation process into a dynamic one that adapts to changing security requirements without requiring system reboot or hardware changes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal field selection mechanism where a single set of predefined fields can serve multiple security policies and protocols (ACL, OpenFlow, etc.). Users can configure different combinations of the same fields for different security policies, making the system multi-functional and adaptable to various networking scenarios without requiring separate hardware for each policy type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If fixed static fields are used for lookup keys, then device complexity is reduced, but adaptability deteriorates as security policies cannot change at runtime

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidfield selection mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system enables runtime reconfiguration of security policies through dynamic field selection. Users can modify which fields are included in lookup keys and how they are combined, allowing security policies to adapt to changing network requirements without hardware modifications or system reboots, achieving policy flexibility through software-based dynamic configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of the lookup key by allowing users to select different fields and their combinations at runtime. This parameter change capability enables the same hardware to support multiple security policies with different field requirements, achieving policy flexibility through parameter reconfiguration rather than hardware changes.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If all possible fields are included in lookup key, then adaptability is improved, but table size increases and memory utilization deteriorates

Engineering Contradiction:
Improvepolicy coverageVSAvoidtable size
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the necessary fields for each specific security policy from the complete set of available fields. Users can select a subset of fields relevant to their policy requirements, excluding unnecessary fields from the lookup key. This extraction approach maintains policy coverage for selected fields while reducing the effective table size and memory requirements compared to including all possible fields.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements partial action by allowing users to include only the minimum necessary fields for each security policy rather than all possible fields. This partial inclusion approach provides sufficient policy coverage for each use case while minimizing table size and memory consumption, avoiding the excessive resource usage that would result from including every possible field in all lookup keys.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9948482B2Apparatus and method for enabling flexible key in a network switch
Publication Date: 2018.04.17 MARVELL ASIA PTE LTD
  • US9948482B2 patent drawing
  • US9948482B2 patent drawing
  • US9948482B2 patent drawing

AI summary

A network switch to support flexible lookup key generation comprises a control CPU configured to run a network switch control stack. The network switch control stacks is configured to manage and control operations of a switching logic circuitry, provide a flexible key having a plurality of possible fields that constitute part of a lookup key to a table, and enable a user to dynamically select at deployment or runtime a subset of the fields in the flexible key to form the lookup key and thus define a lookup key format for the table. The switching logic circuitry provisioned and controlled by the network switch control stack is configured to maintain said table to be searched via the lookup key in a memory cluster and process a received data packet based on search result of the table using the lookup key generated from the dynamically selected fields in the flexible key.