L7 Proxy Demultiplexing for L3 Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques struggle to demultiplex Layer 7 (L7) flows into multiple subflows for Layer 3 (L3) policy enforcement without modifying the underlying L3 network, particularly in microservice environments where multiple microservices are accessed through the same hostname or IP address.
Innovation Solution
The use of proxies with overprovisioned IP addresses to demultiplex L7 flows into multiple subflows, allowing for L3 policy enforcement without modifying the underlying L3 network. These proxies are placed at the entry and exit points of the L3 network and are configured with attributes to identify subflows, such as URLs or HTTP headers, enabling the use of extra IP addresses to distinguish between subflows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple microservices are accessed through the same hostname or IP address using L7 load-balancing, then service accessibility and scalability are improved, but L3 policy enforcement becomes difficult because traffic appears identical at Layer 3
Solution Approach 1:
The patent introduces L7 proxy nodes as intermediary devices positioned between clients and microservices. These proxies perform L7 demultiplexing by examining application-layer attributes (URLs, HTTP headers) to identify distinct subflows, then assign unique L3 identifiers (virtual subnet masks, virtual network interface cards) to each subflow. This allows L3 network infrastructure to differentiate and enforce policies on what would otherwise appear as identical traffic, resolving the contradiction between L7 service versatility and L3 detectability.
2Productivity
If L7 demultiplexing is performed to enable L3 policy enforcement, then per-flow optimizations are enabled, but network infrastructure complexity increases due to additional proxy nodes and identifier management
Solution Approach 1:
The patent segments L7 traffic into distinct subflows at the proxy nodes, each assigned a unique L3 identifier (virtual subnet mask or virtual NIC). This segmentation allows the L3 network infrastructure to treat each subflow independently for policy enforcement and optimization. The segmentation is performed at the proxy layer, keeping the core L3 network simple while enabling sophisticated per-flow control.
Solution Approach 2:
The patent creates virtual copies of network interface cards and subnet masks for each subflow. Instead of modifying physical network infrastructure, virtual NICs and subnet masks are instantiated for each demultiplexed subflow, allowing L3 policy enforcement without hardware changes. This virtualization approach reduces physical complexity while enabling advanced traffic management.
3Difficulty of detecting and measuring
If L3 network infrastructure is modified to support subflow differentiation, then L3 policy enforcement is enabled, but backward compatibility and ease of deployment are reduced
Solution Approach 1:
The patent places L7 proxy nodes as intermediaries at the edges of the network, between clients and microservices. These proxies handle the complex L7 demultiplexing and L3 identifier assignment locally, so the core L3 network infrastructure remains unchanged and backward compatible. Existing L3 devices can continue operating without modification while still enabling sophisticated subflow differentiation through the proxy layer.
Data Source
AI summary
Techniques for using proxies with overprovisioned IP addresses to demultiplex data flows, which may otherwise look the same at L7, into multiple subflows for L3 policy enforcement without having to modify an underlying L3 network. The techniques may include establishing a subflow through a network between a first proxy and a second proxy, the subflow associated with a specific policy. In some examples, the first proxy node may receive an encrypted packet that is to be sent through the network and determine, based at least in part on accessing an encrypted application layer of the packet, a specific application to which the packet is to be sent. The first proxy node may then alter an IP address included in the packet to cause the packet to be sent through the network via the subflow such that the packet is handled according to the specific policy.


