Flow Virtualization via IPv6 and MPLS Labels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computer networks face complexity and fragility in flow-based security enforcement due to the dual role of IP addresses as identifiers and reachability information, leading to loss of visibility and increased complexity in managing data paths, which complicates policy enforcement and requires additional network hops and appliances.

Innovation Solution

Decoupling host/interface identity information from reachability information by using IPv6 addresses as cookies within packets, which are then forwarded using MPLS labels, allowing policy engines to manage and enforce policies based on these labels without relying solely on IP addresses, thereby enabling flow-based access control and visibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IP addresses are used for both endpoint identification and routing reachability, then networking is simplified, but flow-based policy enforcement becomes complex and visibility is lost

Engineering Contradiction:
Improvenetworking simplicityVSAvoidpolicy enforcement complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the dual role of IP addresses by introducing a new identifier format that separates identification functions from routing functions. The identifier is divided into a static portion (for identification) and a dynamic portion (for reachability), allowing independent handling of each function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary identifier structure that acts as a mediator between endpoint identification and routing reachability. This identifier includes both a static identification component and a dynamic reachability component, enabling policy enforcement without interfering with standard routing operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If IP addresses are reassigned upon interface connection, then network flexibility is improved, but flow-based security policies become fragile and compute intensive

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidpolicy enforcement reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The identifier is segmented into a static portion that remains constant for policy identification and a dynamic portion that changes with network conditions. This segmentation allows policies to be reliably associated with flows even when reachability information changes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter structure of the identifier to include both static and dynamic components. The static portion provides stable policy anchoring while the dynamic portion adapts to network changes, resolving the conflict between flexibility and reliability.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If dedicated appliances are added for policy enforcement, then security visibility is improved, but execution path complexity increases

Engineering Contradiction:
Improvesecurity visibilityVSAvoidexecution path complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent makes existing network elements universal by enabling them to perform both standard routing functions and flow-based policy enforcement using the new identifier format. This eliminates the need for dedicated policy enforcement appliances while maintaining security visibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The new identifier format enables network elements to self-configure for policy enforcement without requiring additional dedicated appliances. The identifier carries sufficient information for nodes to autonomously apply appropriate policies, reducing execution path complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11438261B2Methods and systems for flow virtualization and visibility
Publication Date: 2022.09.06 CUMULUS NETWORKS
  • US11438261B2 patent drawing
  • US11438261B2 patent drawing
  • US11438261B2 patent drawing

AI summary

Identity information is decoupled from reachability information in packets transferred between hosts of a computer network by replacing forwarding information within said packets with an identifier having a format of the forwarding information, and applying forwarding labels, derived from the identifiers, which are then used in lieu of the forwarding information for conveying the packets within the network. During such conveyance, the packets are treated according to one or more policies prescribed on a basis of the identifier, which may be an IPv6 address. The forwarding labels may be MPLS labels.