Flow Virtualization via IPv6 and MPLS Labels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern computer networks face complexity and fragility in flow-based security enforcement due to the dual role of IP addresses as identifiers and reachability information, leading to loss of visibility and increased complexity in managing data paths, which complicates policy enforcement and requires additional network hops and appliances.
Innovation Solution
Decoupling host/interface identity information from reachability information by using IPv6 addresses as cookies within packets, which are then forwarded using MPLS labels, allowing policy engines to manage and enforce policies based on these labels without relying solely on IP addresses, thereby enabling flow-based access control and visibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IP addresses are used for both endpoint identification and routing reachability, then networking is simplified, but flow-based policy enforcement becomes complex and visibility is lost
Solution Approach 1:
The patent segments the dual role of IP addresses by introducing a new identifier format that separates identification functions from routing functions. The identifier is divided into a static portion (for identification) and a dynamic portion (for reachability), allowing independent handling of each function.
Solution Approach 2:
The patent introduces an intermediary identifier structure that acts as a mediator between endpoint identification and routing reachability. This identifier includes both a static identification component and a dynamic reachability component, enabling policy enforcement without interfering with standard routing operations.
2Adaptability or versatility
If IP addresses are reassigned upon interface connection, then network flexibility is improved, but flow-based security policies become fragile and compute intensive
Solution Approach 1:
The identifier is segmented into a static portion that remains constant for policy identification and a dynamic portion that changes with network conditions. This segmentation allows policies to be reliably associated with flows even when reachability information changes.
Solution Approach 2:
The patent changes the parameter structure of the identifier to include both static and dynamic components. The static portion provides stable policy anchoring while the dynamic portion adapts to network changes, resolving the conflict between flexibility and reliability.
3Loss of information
If dedicated appliances are added for policy enforcement, then security visibility is improved, but execution path complexity increases
Solution Approach 1:
The patent makes existing network elements universal by enabling them to perform both standard routing functions and flow-based policy enforcement using the new identifier format. This eliminates the need for dedicated policy enforcement appliances while maintaining security visibility.
Solution Approach 2:
The new identifier format enables network elements to self-configure for policy enforcement without requiring additional dedicated appliances. The identifier carries sufficient information for nodes to autonomously apply appropriate policies, reducing execution path complexity.
Data Source
AI summary
Identity information is decoupled from reachability information in packets transferred between hosts of a computer network by replacing forwarding information within said packets with an identifier having a format of the forwarding information, and applying forwarding labels, derived from the identifiers, which are then used in lieu of the forwarding information for conveying the packets within the network. During such conveyance, the packets are treated according to one or more policies prescribed on a basis of the identifier, which may be an IPv6 address. The forwarding labels may be MPLS labels.


