Hardware-Based Forwarding Table for Private VLAN Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional private VLAN implementations face scalability issues due to the need for separate forwarding databases for each port, leading to increased complexity and inefficiency in packet forwarding, particularly because software-driven learning rates are much lower than hardware-driven rates, causing unnecessary replication and waste of hardware space.

Innovation Solution

A network switch with a hardware-based forwarding table that consolidates all forwarding entries for a private VLAN domain, using a network processor and gatekeeper to enforce packet forwarding rules based on privacy levels, preventing packet forwarding between isolated ports and optimizing hardware usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate forwarding databases are used for each port in traditional private VLAN implementations, then packet forwarding rules can be enforced, but device complexity and the number of forwarding entries increase significantly

Engineering Contradiction:
Improvepacket forwarding rule enforcementVSAvoidforwarding database structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate forwarding databases (one for each port) into a single unified forwarding database that serves the entire private VLAN domain. This consolidation reduces device complexity by eliminating redundant database structures while maintaining the ability to enforce packet forwarding rules through a unified lookup mechanism that considers both ingress and egress ports.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If software-driven learning is used to maintain forwarding databases, then forwarding entries can be learned and updated, but the learning rate is limited to about 5,000 entries per second

Engineering Contradiction:
Improveforwarding database learning capabilityVSAvoidlearning rate
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent replaces software-driven learning mechanisms with hardware-driven learning mechanisms. This substitution increases the learning rate from approximately 5,000 entries per second (software) to over 100,000 entries per second (hardware), significantly improving productivity while maintaining the adaptability to learn and update forwarding entries dynamically.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If forwarding database entries are replicated for each port, then all forwarding scenarios are covered, but hardware space is wasted and cost effectiveness decreases

Engineering Contradiction:
Improveforwarding scenario coverageVSAvoidhardware space utilization
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent creates a universal forwarding database that serves multiple ports simultaneously rather than having dedicated databases for each port. This single database structure can handle all forwarding scenarios by performing lookups based on both ingress and egress ports, eliminating the need for replication and optimizing hardware space utilization while maintaining complete forwarding scenario coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8369344B1Customer isolation using a common forwarding database with hardware learning support
Publication Date: 2013.02.05 EXTREME NETWORKS INC
  • US8369344B1 patent drawing
  • US8369344B1 patent drawing
  • US8369344B1 patent drawing

AI summary

A network switch includes a plurality of isolated ports, each associated with a private domain. The switch also includes a network port associated with the private domain. A memory in the switch maintains a hardware-based forwarding table for the private domain. Processing logic in the network switch prevents forwarding of packets between isolated ports within the private domain based at least in part on a privacy level associated with each entry in the hardware-based forwarding table for the private domain.