Label-Based Policy Enforcement in MPLS WAN Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network segmentation methods, such as ACL rules and centralized solutions, are inefficient and unmanageable for enforcing policies across multiple branches and campuses in a Wide Area Network, leading to throughput issues and scalability challenges.

Innovation Solution

A distributed MPLS-based segmentation model that uses VXLAN and MPLS labels to enforce network policies across branches, allowing for the translation of labels between different network entities, enabling macro and micro-segmentation without disrupting existing configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ACL rules and centralized solutions are used for network segmentation, then policy enforcement is achieved, but throughput decreases and scalability becomes difficult

Engineering Contradiction:
Improvepolicy enforcementVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies segmentation by dividing network policies into macro-segmentation (between branches/campuses using MPLS labels) and micro-segmentation (within branches using VXLAN labels). This hierarchical segmentation allows policy enforcement at appropriate levels without centralizing all traffic, thereby maintaining throughput while achieving reliable policy enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces MPLS labels as intermediaries for macro-segmentation between branches and VXLAN labels for micro-segmentation within branches. These label-based intermediaries enable distributed policy enforcement without requiring centralized ACL rule processing, thus maintaining throughput while ensuring reliable policy compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ACL rules and centralized solutions are used for network segmentation, then policy enforcement is achieved, but device complexity and manageability increase

Engineering Contradiction:
Improvepolicy enforcementVSAvoidmanageability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments policy enforcement into distributed MPLS label-based macro-segmentation and VXLAN label-based micro-segmentation. This segmentation simplifies manageability by allowing each network entity to enforce policies locally based on label matching, rather than requiring complex centralized ACL rule management across all devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the enforcement parameter from complex ACL rules to simple label matching (MPLS and VXLAN labels). This parameter change simplifies device complexity and manageability while maintaining reliable policy enforcement, as label matching is inherently simpler and more scalable than traditional ACL processing.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If existing network configurations are modified for segmentation, then policy enforcement improves, but network disruption occurs

Engineering Contradiction:
Improvepolicy enforcementVSAvoidnetwork configuration stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent nests VXLAN label-based micro-segmentation within MPLS label-based macro-segmentation. This nested structure allows policy enforcement to be added layer by layer without disrupting existing network configurations, as each layer operates independently at its appropriate level (branch-level MPLS, device-level VXLAN).

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent enables policy enforcement to be implemented preliminarily through label assignment and translation mechanisms before full deployment. The label translation functionality allows gradual integration without disrupting existing configurations, as labels can be introduced and translated incrementally across the network.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11552824B2Label based policy enforcement
Publication Date: 2023.01.10 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11552824B2 patent drawing
  • US11552824B2 patent drawing
  • US11552824B2 patent drawing

AI summary

Examples disclosed herein relate to a method comprising receiving a data packet originating from a first device and intended for a second device, wherein the first device and the first access device belong to a first branch of a Wide Area Network (WAN) using a MPLS overlay and the second device belongs to a second branch of the WAN. The method includes encapsulating the data packet in VXLAN including a VXLAN label identifying a role type and transmitting the data packet to a first core device. The method includes determining an MPLS label corresponding to the role type and transmitting the data packet over the MPLS overlay to a second core device belonging to the second branch of the WAN. The method includes translating the MPLS label into the VXLAN label and transmitting the data packet including the VXLAN label to a second access device for an enforcement action.