Layer 2 Policy Control Using Shared Address Databases
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data link layer switching technologies are inefficient in implementing policy using Layer 2 data fields, leading to high memory requirements and complexity due to the reliance on ternary content-addressable memory (TCAM) and other high-capacity storage components.
Innovation Solution
A system and method that utilize Layer 2 data fields such as destination address (DA), source address (SA), and virtual local area network identification (VID) to enable policy control without requiring independent memory tables, by modifying address databases and employing programmable registers to execute policy operations like mirroring, trapping, or discarding frames, thereby reducing memory needs and processing complexity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional policy functionality is implemented using Layer 2 data fields, then sophisticated policy features can be achieved, but memory requirements become very large requiring TCAM or other high-capacity data storage components
Solution Approach 1:
The patent merges policy control functionality with existing Layer 2 switching architecture by using the same address databases and port registers that handle normal frame switching. Instead of creating separate policy storage structures, the system combines policy determination with the existing forwarding decision process, thereby eliminating the need for additional high-capacity memory components like TCAM.
Solution Approach 2:
The address databases and port registers serve dual purposes: they handle both normal Layer 2 frame forwarding and policy control operations. The same data structures used for switch lookup and frame forwarding are reused for policy determination, making the system more memory-efficient while maintaining sophisticated policy capabilities.
2Adaptability or versatility
If conventional policy strategies are used, then sophisticated policy features can be implemented, but device complexity increases due to reliance on TCAM and high-capacity storage components
Solution Approach 1:
The patent combines policy control with the existing Layer 2 switching fabric by using the same address databases and port registers for both normal forwarding and policy decisions. This integration eliminates the need for separate policy storage hardware like TCAM, thereby reducing overall device complexity while maintaining sophisticated policy features.
Solution Approach 2:
The system uses its existing switching infrastructure (address databases, port registers) to serve dual purposes: normal frame forwarding and policy control. The switching hardware serves itself by reusing its own resources for policy determination, eliminating the need for additional specialized memory components and reducing hardware complexity.
3Quantity of substance
If Layer 2 data fields are used for policy control, then memory requirements are reduced, but processing overhead may increase due to additional policy determination steps
Solution Approach 1:
The patent merges policy determination with the existing frame forwarding decision process. By using the same address databases and port registers for both normal switching and policy control, the system eliminates separate policy lookup steps, thereby reducing processing overhead while maintaining low memory requirements through shared data structures.
Solution Approach 2:
The system pre-configures port registers with policy information during initialization, so that policy decisions can be made quickly during frame processing without requiring complex real-time calculations. This preliminary preparation reduces the processing time required for policy determination during actual frame handling.
Data Source
AI summary
Exemplary embodiments of a system and method enable application of policy using Layer 2 fields for a data frame, simplified data structures, or both. In accordance with one aspect of the present invention, a policy may be based upon a destination address (DA), a source address (SA), or a virtual local area network identification (VID) associated with a data frame.


