IPv6 Flow Label Assignment via Network Edge Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IPv6 flow label assignment by untrusted source nodes leads to inefficient resource utilization and security risks, as intermediate nodes must maintain extensive flow states and perform intensive processing, which can result in memory and CPU exhaustion and increased vulnerability to attacks.
Innovation Solution
Implementing network nodes, such as edge devices, to apply and manage flow labels by incorporating additional information elements like QoS, subscriber identifiers, security status, and content ratings, allowing for controlled flow classification and treatment within the network, thereby reducing the burden on intermediate nodes and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If source nodes assign flow labels to packets, then flow classification is enabled, but intermediate nodes must maintain extensive flow states leading to memory and CPU exhaustion
Solution Approach 1:
The patent extracts the flow label assignment function from untrusted source nodes and relocates it to trusted network edge devices. This separation removes the burden of flow state management from intermediate nodes while preserving flow classification capabilities. The edge device becomes the sole authority for assigning flow labels, allowing intermediate nodes to simply forward packets based on these labels without maintaining extensive flow states.
Solution Approach 2:
The patent introduces network edge devices as intermediary entities between source nodes and intermediate nodes. These edge devices act as mediators that receive packets from sources, assign appropriate flow labels based on network policies, and forward labeled packets to intermediate nodes. This intermediary layer shields intermediate nodes from the complexity of flow management while maintaining efficient flow-based routing.
2Manufacturing precision
If source nodes create unique flow labels for each packet, then packet-level flow distinction is achieved, but intermediate nodes experience CPU exhaustion from processing each packet individually
Solution Approach 1:
The patent merges multiple packets belonging to the same flow under a single flow label assigned by the edge device. Instead of treating each packet individually, packets with identical flow characteristics (source, destination, service type) are grouped together and assigned the same flow label. This merging reduces the number of distinct flow states intermediate nodes must maintain and process, significantly improving processing throughput while maintaining accurate flow distinction.
Solution Approach 2:
The patent changes the granularity parameter of flow label assignment from packet-level (one label per packet) to flow-level (one label per stream of packets). By this parameter change, multiple packets are processed as a single flow unit, reducing the processing burden on intermediate nodes while preserving the ability to distinguish between different types of traffic flows for QoS management.
3Adaptability or versatility
If untrusted source nodes assign flow labels, then end devices control flow classification, but network security is compromised to attacks from rogue sources
Solution Approach 1:
The patent inverts the traditional flow label assignment model by switching the authority from source nodes to network edge devices. Instead of trusting sources to assign labels correctly, the network itself (through edge devices) assigns labels based on observed traffic patterns and network policies. This inversion places control in the hands of trusted network infrastructure rather than potentially malicious end devices, fundamentally improving security while maintaining flow classification functionality.
Solution Approach 2:
The patent introduces network edge devices as intermediary authorities that stand between untrusted source nodes and the network core. These edge devices verify and control flow label assignments, preventing rogue sources from creating malicious flow patterns. The intermediary edge device maintains end device control over their own traffic while ensuring network-wide security policies are enforced, thus resolving the security vulnerability.
4Ease of operation
If intermediate nodes maintain flow state for each flow, then flow-based QoS decisions can be made, but memory resources are exhausted
Solution Approach 1:
The patent extracts the flow state management function from intermediate nodes and consolidates it at network edge devices. Edge devices maintain the flow states and make QoS decisions, while intermediate nodes simply forward packets based on flow labels without maintaining detailed flow states. This extraction dramatically reduces the memory burden on intermediate nodes while preserving flow-based QoS capabilities through centralized flow management at edge devices.
Data Source
AI summary
Network edge devices receive IPv6 packets from source devices. These packets may or may not contain values in their flow label fields. The network edge devices apply a value to the flow label field. This value may include a flow identifier established by the network edge device. The value may also include an additional information element pertaining to QoS, security status, subscriber identity, content rating.


