Network Assurance Model for Configuration Consistency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network configurations in large data center networks are complex and prone to errors, leading to inconsistencies that can cause significant issues, as the configurations defined by a centralized controller may not accurately reflect the intended behavior, due to hardware errors, software bugs, or configuration conflicts.

Innovation Solution

The implementation of network assurance models that analyze and model various aspects of the network to ensure consistency with intended configurations, performing checks without monitoring traffic or packet data, allowing for predictive, real-time identification and fixing of inconsistencies and errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network configurations are manually defined at a centralized controller, then network intent specification can be achieved, but configuration errors and inconsistencies are difficult to identify

Engineering Contradiction:
Improvenetwork configuration managementVSAvoidconfiguration consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a logical model as a copy of the intended network configuration and compares it with the actual node implementation. This copying approach allows identification of inconsistencies between intended and actual configurations without changing the manual configuration process itself.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system implements a feedback mechanism by continuously monitoring and comparing the logical model with actual node implementations, providing information about configuration inconsistencies back to operators for correction.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If network configurations become complex with multiple layers and policies, then network functionality is enhanced, but error identification becomes extremely difficult

Engineering Contradiction:
Improvenetwork functionalityVSAvoidconfiguration errors
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the complex network configuration into a structured logical model with hierarchical components (network intents, policies, rules, parameters). This segmentation makes it easier to locate and identify specific errors within the complex configuration by breaking it down into manageable, comparable units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

By creating a comprehensive logical model that copies the intended configuration structure, the system provides a reference framework that simplifies error detection in complex multi-layer configurations through systematic comparison.

Inventive Principle:
Principle #26Copying

3Ease of operation

If configurations are defined at a centralized controller, then centralized management is achieved, but inconsistencies with node implementation may occur

Engineering Contradiction:
Improvecentralized configuration managementVSAvoidconfiguration consistency
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system establishes a feedback loop that monitors the implementation of centralized configurations at individual nodes and reports inconsistencies back to the centralized controller, enabling detection of information loss or deviation during configuration deployment.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The logical model serves as a centralized copy of the intended configuration that can be compared against actual node implementations, providing a reference for detecting configuration consistency issues across the network.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3643014B1Identifying mismatches between a logical model and node implementation
Publication Date: 2024.07.31 CISCO TECHNOLOGY INC
  • EP3643014B1 patent drawingFigure 1A
  • EP3643014B1 patent drawingFigure 1B
  • EP3643014B1 patent drawingFigure 2A

AI summary

Systems, methods, and computer-readable media analyzing memory usage in a network node. A network assurance appliance may be configured to obtain reference concrete level rules for a node in the network, obtain implemented concrete level rules for the node from the node in the network, compare the reference concrete level rules with the implemented concrete level rules, and determining that the implemented concrete level rules are not appropriately configured based on the comparison.