Network Assurance via Layered Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex computer networks face challenges in accurate and efficient error detection and configuration validation, leading to difficulties in troubleshooting and ensuring proper network behavior, especially due to the complexity of configuration options and potential inconsistencies across different layers.
Innovation Solution
The system and method for network assurance involve receiving global logical models, converting them into local models, and comparing software and hardware configurations to validate accuracy, generating events for inconsistencies, and storing prior configurations to identify potential flaws, thereby ensuring proper deployment and operation of network configurations across Layer 1, Layer 2, and Layer 3 environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network configuration options are expanded to provide greater flexibility and control, then network adaptability is improved, but network complexity increases
Solution Approach 1:
The patent segments the network configuration validation process into distinct layers (Layer 1 physical interface validation, Layer 2 data link validation, Layer 3 network validation). Each layer has specific validation checks that can be independently performed, allowing comprehensive validation without overwhelming complexity. The configuration is divided into global logical models, local logical models, and software models that can be validated separately and systematically.
Solution Approach 2:
The patent introduces an intermediary validation system that acts as a mediator between the network configuration and the actual network behavior. This validation system includes a validation module that compares intended configurations against actual network state, identifying discrepancies without requiring direct modification of the network infrastructure. The intermediary layer provides structured error detection and reporting mechanisms.
2Measurement precision
If network configuration validation is performed manually, then configuration accuracy can be checked, but troubleshooting time and operational difficulty increase
Solution Approach 1:
The patent implements preliminary validation actions that check network configurations before deployment and during operation. The system proactively validates configurations against known error patterns and consistency rules, identifying potential issues before they cause network failures. This prevents many errors from occurring in the first place, reducing the need for time-consuming troubleshooting.
Solution Approach 2:
The patent establishes feedback mechanisms that continuously monitor network configuration state and provide validation results. When inconsistencies are detected, the system generates error events and notifications that guide operators through troubleshooting. The feedback loop includes validation results, error identification, and corrective action guidance, significantly reducing troubleshooting time compared to manual methods.
3Measurement precision
If comprehensive network validation across all layers is implemented, then error detection accuracy is improved, but system complexity and resource requirements increase
Solution Approach 1:
The validation system is segmented into layer-specific validation modules, each responsible for validating configurations at their respective OSI layer. Layer 1 validation handles physical interface parameters, Layer 2 validation handles data link configurations, and Layer 3 validation handles network layer settings. This segmentation allows comprehensive multi-layer validation while keeping each validation module relatively simple and focused on specific validation criteria.
4Stability of the object's composition
If detailed configuration comparison between global logical model and software model is performed, then configuration consistency is improved, but processing time and computational resources increase
Solution Approach 1:
The patent extracts and compares only the critical and overlapping configuration parameters between the global logical model and the software model, rather than performing a complete field-by-field comparison of all configuration data. The validation module identifies and focuses on key parameters that have the greatest impact on network behavior and consistency, such as interface configurations, routing parameters, and policy settings. This selective extraction approach maintains configuration consistency validation while significantly reducing processing time and computational overhead.
Data Source
AI summary
Disclosed are systems, methods, and computer-readable media for assuring tenant forwarding in a network environment. Network assurance can be determined in layer 1, layer 2 and layer 3 of the networked environment including, internal-internal (e.g., inter-fabric) forwarding and internal-external (e.g., outside the fabric) forwarding in the networked environment. The network assurance can be performed using logical configurations, software configurations and/or hardware configurations.


