Hybrid Services Insertion via ACL Traffic Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service chaining technologies require hardware changes and lack efficient methods for selective traffic redirection and hybrid services insertion without additional packet headers, limiting their flexibility and performance.

Innovation Solution

The implementation of service chaining techniques that allow switches to redirect network traffic based on Access Control List (ACL) configurations, enabling selective traffic redirection and hybrid services insertion by configuring switches and applications in different modes (L2 and L3) without modifying packet headers, using existing ASICs and linecards for wire-speed performance and health monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service chaining is implemented using traditional hardware-based methods, then network service functionality is provided, but hardware changes are required and flexibility is reduced

Engineering Contradiction:
Improveservice chaining flexibilityVSAvoidhardware configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional hardware-based service chaining mechanisms with a software-based approach using Access Control Lists (ACLs) on network switches. Instead of requiring physical hardware changes or specialized service chaining hardware, the invention uses software-configurable ACL rules to redirect traffic to service appliances, thereby eliminating the need for hardware changes while maintaining service chaining functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The invention changes the configuration parameters from hardware-level settings to software-based ACL parameters. By using ACL match criteria (such as source/destination IP addresses, ports, protocols) and associated actions (redirect to specific service appliances), the system achieves flexible service chaining through parameter-based control rather than fixed hardware configurations.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If service chaining requires additional packet headers, then traffic can be redirected to services, but packet header overhead increases and performance decreases

Engineering Contradiction:
Improvenetwork throughputVSAvoidpacket header overhead
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts the service chaining functionality from the packet data plane by implementing redirection at the network layer using ACLs. Instead of embedding service chaining information within packet headers (which would increase overhead), the invention separates the redirection logic into switch-based ACL rules that operate independently of the actual data packets, thereby eliminating additional packet header requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If selective traffic redirection is implemented without ACL configurations, then service insertion is simplified, but traffic selection capability is reduced

Engineering Contradiction:
Improvetraffic selection capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal ACL functionality already present in modern network switches to achieve service chaining. By utilizing the existing multi-functional ACL capability (which can already perform traffic filtering, routing, and policy-based forwarding), the invention adds service insertion functionality without requiring dedicated service chaining hardware or complex proprietary configuration systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If health monitoring is not implemented, then system complexity is reduced, but failure handling capability is weakened

Engineering Contradiction:
Improvefailure handling capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service health monitoring mechanism where the system automatically detects and responds to service appliance failures. The switch monitors the health of connected service appliances through ACL rule evaluations and automatically redirects traffic away from failed appliances without requiring external monitoring systems or complex manual intervention, thereby achieving reliable failure handling with minimal additional complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10965596B2Hybrid services insertion
Publication Date: 2021.03.30 CISCO TECHNOLOGY INC
  • US10965596B2 patent drawing
  • US10965596B2 patent drawing
  • US10965596B2 patent drawing

AI summary

In an embodiment, a method is provided. The method includes: storing, in at least one hardware module of a network device having a plurality of ports, attributes for at least one access control list and associated actions that cause network packets received at one of the plurality of ports that match the attributes for the at least one access control list, to be directed into a service chain that includes at least a first network processing application specified according to a port and a second network processing application specified according to an internet protocol (IP) address; and directing a received network packet that matches the attributes for the at least one access control list into the service chain.