Flexible Lookup Key Generation in Network Switches
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network switches have fixed, static lookup keys that do not allow for dynamic configuration of security and routing policies at runtime, limiting flexibility and scalability in managing network traffic.
Innovation Solution
A network switch with a control CPU and switching logic circuitry that supports flexible lookup key generation, enabling users to dynamically select and configure a subset of fields to form lookup keys for table searches, allowing for runtime changes in security and routing policies without rebooting the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If fixed static fields are used for lookup keys, then device complexity is reduced and ease of manufacture is improved, but adaptability and versatility deteriorate as users cannot dynamically configure security policies
Solution Approach 1:
The patent implements dynamic lookup key generation by allowing users to select from multiple predefined fields at runtime. The control CPU dynamically constructs lookup keys by combining selected fields according to user-defined policies, transforming the static key generation process into a dynamic one that adapts to changing security requirements without requiring system reboot or hardware changes.
Solution Approach 2:
The patent creates a universal field selection mechanism where a single set of predefined fields can serve multiple security policies and protocols (ACL, OpenFlow, etc.). Users can configure different combinations of the same fields for different security policies, making the system multi-functional and adaptable to various networking scenarios without requiring separate hardware for each policy type.
2Adaptability or versatility
If fixed static fields are used for lookup keys, then device complexity is reduced, but adaptability deteriorates as security policies cannot change at runtime
Solution Approach 1:
The system enables runtime reconfiguration of security policies through dynamic field selection. Users can modify which fields are included in lookup keys and how they are combined, allowing security policies to adapt to changing network requirements without hardware modifications or system reboots, achieving policy flexibility through software-based dynamic configuration.
Solution Approach 2:
The patent changes the parameters of the lookup key by allowing users to select different fields and their combinations at runtime. This parameter change capability enables the same hardware to support multiple security policies with different field requirements, achieving policy flexibility through parameter reconfiguration rather than hardware changes.
3Adaptability or versatility
If all possible fields are included in lookup key, then adaptability is improved, but table size increases and memory utilization deteriorates
Solution Approach 1:
The patent extracts only the necessary fields for each specific security policy from the complete set of available fields. Users can select a subset of fields relevant to their policy requirements, excluding unnecessary fields from the lookup key. This extraction approach maintains policy coverage for selected fields while reducing the effective table size and memory requirements compared to including all possible fields.
Solution Approach 2:
The system implements partial action by allowing users to include only the minimum necessary fields for each security policy rather than all possible fields. This partial inclusion approach provides sufficient policy coverage for each use case while minimizing table size and memory consumption, avoiding the excessive resource usage that would result from including every possible field in all lookup keys.
Data Source
AI summary
A network switch to support flexible lookup key generation comprises a control CPU configured to run a network switch control stack. The network switch control stacks is configured to manage and control operations of a switching logic circuitry, provide a flexible key having a plurality of possible fields that constitute part of a lookup key to a table, and enable a user to dynamically select at deployment or runtime a subset of the fields in the flexible key to form the lookup key and thus define a lookup key format for the table. The switching logic circuitry provisioned and controlled by the network switch control stack is configured to maintain said table to be searched via the lookup key in a memory cluster and process a received data packet based on search result of the table using the lookup key generated from the dynamically selected fields in the flexible key.


