Hardware-Based Forwarding Table for Private VLAN Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional private VLAN implementations face scalability issues due to the need for separate forwarding databases for each port, leading to increased complexity and inefficiency in packet forwarding, particularly because software-driven learning rates are much lower than hardware-driven rates, causing unnecessary replication and waste of hardware space.
Innovation Solution
A network switch with a hardware-based forwarding table that consolidates all forwarding entries for a private VLAN domain, using a network processor and gatekeeper to enforce packet forwarding rules based on privacy levels, preventing packet forwarding between isolated ports and optimizing hardware usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate forwarding databases are used for each port in traditional private VLAN implementations, then packet forwarding rules can be enforced, but device complexity and the number of forwarding entries increase significantly
Solution Approach 1:
The patent merges multiple separate forwarding databases (one for each port) into a single unified forwarding database that serves the entire private VLAN domain. This consolidation reduces device complexity by eliminating redundant database structures while maintaining the ability to enforce packet forwarding rules through a unified lookup mechanism that considers both ingress and egress ports.
2Adaptability or versatility
If software-driven learning is used to maintain forwarding databases, then forwarding entries can be learned and updated, but the learning rate is limited to about 5,000 entries per second
Solution Approach 1:
The patent replaces software-driven learning mechanisms with hardware-driven learning mechanisms. This substitution increases the learning rate from approximately 5,000 entries per second (software) to over 100,000 entries per second (hardware), significantly improving productivity while maintaining the adaptability to learn and update forwarding entries dynamically.
3Reliability
If forwarding database entries are replicated for each port, then all forwarding scenarios are covered, but hardware space is wasted and cost effectiveness decreases
Solution Approach 1:
The patent creates a universal forwarding database that serves multiple ports simultaneously rather than having dedicated databases for each port. This single database structure can handle all forwarding scenarios by performing lookups based on both ingress and egress ports, eliminating the need for replication and optimizing hardware space utilization while maintaining complete forwarding scenario coverage.
Data Source
AI summary
A network switch includes a plurality of isolated ports, each associated with a private domain. The switch also includes a network port associated with the private domain. A memory in the switch maintains a hardware-based forwarding table for the private domain. Processing logic in the network switch prevents forwarding of packets between isolated ports within the private domain based at least in part on a privacy level associated with each entry in the hardware-based forwarding table for the private domain.


