Security Switch Flow Table Management via Exact Match Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security switches face challenges in managing high-scale flow tracking due to resource-intensive flow management processes, which can impact communication bandwidth and security, especially in detecting security attacks.

Innovation Solution

A security switch with a dedicated security processor and external memory, utilizing a flow table with a learn cache and exact match engine for hardware-based reordering and indirection, enabling high flow table scale, learn/age rates, and distributed system support, allowing for complex flow management and operation coherency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If flow tracking is performed using a large flow table, then security attack detection capability is improved, but computing resources and communication bandwidth are consumed

Engineering Contradiction:
Improvesecurity attack detection capabilityVSAvoidcomputing resources and communication bandwidth
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The flow table is segmented into multiple tables with different entry sizes and priorities. Critical flow entries are stored in smaller, faster-access tables while less critical entries are stored in larger tables, allowing the system to maintain comprehensive flow tracking while optimizing resource usage based on entry importance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the flow table are assigned different qualities and access characteristics. High-priority flow entries receive faster access paths and more resources, while lower-priority entries use standard access paths, enabling differentiated resource allocation based on local requirements of individual flow entries.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If flow management processes are made more complex to handle high-scale flows, then flow tracking accuracy is improved, but processing time and bandwidth consumption increase

Engineering Contradiction:
Improveflow tracking accuracyVSAvoidprocessing time and bandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Flow entries are pre-processed and organized into priority-based tables before actual packet processing occurs. This preliminary organization allows the system to quickly retrieve and process flow information without performing complex operations during critical packet processing time, thus maintaining accuracy while reducing processing delay.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The flow management system dynamically adjusts its behavior based on current load conditions and flow priorities. The system can adaptively allocate processing resources and adjust table access patterns to maintain high accuracy for critical flows while optimizing performance for less critical flows under varying network conditions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12028254B2Systems for and methods of flow table management
Publication Date: 2024.07.02 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US12028254B2 patent drawing
  • US12028254B2 patent drawing
  • US12028254B2 patent drawing

AI summary

A switch includes memory including a flow table. The flow table includes a flow key database and a flow policy database for flows in a network associated with the switch. The switch includes a security processor including an exact match engine. The exact match engine manages the flow table in the memory. The exact match engine includes a learn cache configured to store key entries for storage in the flow key database.