Forwarding Plane Device Policy Authentication for Service Flow Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network architectures with separated control and forwarding planes, multiple control plane network elements can lead to malicious control of service flows, resulting in incorrect reachability between peer ends due to limitations in controller range and network management.

Innovation Solution

A processing method and apparatus that determine, based on a correspondence between control domain identifiers and service flow identifiers, whether to allow a control domain to operate a service flow processing policy, ensuring that only authorized domains manage service flows by receiving operation requests, obtaining identifiers, and authenticating control domain permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple control plane network elements are deployed to handle service flows, then the network can process more service flows, but the risk of malicious control increases and service flow reachability cannot be guaranteed

Engineering Contradiction:
Improveservice flow processing capacityVSAvoidservice flow reachability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the control plane into multiple control domains, where each control domain is assigned to manage specific service flows. This segmentation prevents any single control domain from having unrestricted access to all service flows, thereby reducing the risk of malicious control while maintaining the ability to handle multiple service flows simultaneously. The forwarding plane device maintains a mapping between service flows and their authorized control domains, ensuring that only permitted control domains can modify or manage particular service flows.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If control plane and forwarding plane are separated, then network flexibility and programmability are improved, but the complexity of managing multiple control plane elements increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidcontrol plane management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism in the form of a forwarding plane device that acts as a mediator between multiple control domains and the service flows. This intermediary maintains authorization information and mapping relationships, simplifying the management complexity by centralizing the coordination function. Control domains interact with the forwarding plane device rather than directly managing service flows, which reduces the overall system complexity while preserving network flexibility and adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If any control domain can operate any service flow processing policy, then system operation is simplified, but unauthorized modifications and malicious control occur

Engineering Contradiction:
Improvepolicy operation simplicityVSAvoidunauthorized policy modification
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-establishing authorization relationships between control domains and service flows before any policy operations occur. The forwarding plane device stores mapping information that identifies which control domains are authorized to manage which service flows. When a control domain attempts to operate a service flow processing policy, the forwarding plane device first verifies the authorization based on pre-stored mapping information. This preliminary authorization check simplifies operation for authorized domains while preventing unauthorized modifications by malicious domains.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3337105B1Processing method and apparatus for service flow processing policy
Publication Date: 2021.04.07 HUAWEI TECH CO LTD
  • EP3337105B1 patent drawingFigure 1~2a
  • EP3337105B1 patent drawingFigure 2b~3
  • EP3337105B1 patent drawingFigure 4A

AI summary

The present invention provides processing method, apparatus, and system for a service flow processing policy. The method includes: receiving, by a forwarding plane device, an operation request of a service flow processing policy from a first control domain, where the operation request of the service flow processing policy includes a service flow identifier corresponding to a to-be-processed policy; obtaining an identifier of the first control domain according to the operation request of the service flow processing policy; determining whether to allow the first control domain to operate the to-be-processed policy; and if the forwarding plane device determines to allow the first control domain to operate the to-be-processed policy, operating the to-be-processed policy according to the operation request of the service flow processing policy. Authentication is performed on a control domain that sends an operation request, and a corresponding operation is performed when the control domain is allowed to perform an operation. This prevents a service flow from being maliciously controlled, and ensures that the service flow correctly reaches a peer end.