Network Controller Address Grouping for Distributed Firewall Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined data centers with virtualized networks, efficiently implementing distributed firewall rules across a large number of network devices is challenging due to the need for numerous firewall rules, which requires optimized configuration and minimization of rule changes to reduce resource usage and churn.

Innovation Solution

A network controller optimizes configuration data for flow-based managed forwarding elements by assigning priorities to distributed service rules, using non-overlapping address sets, and employing conjunctive matching techniques to minimize the number of flow entries, while also normalizing address sets to reduce the complexity of rule implementation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distributed firewall rules are implemented across many network devices, then network security coverage is improved, but the number of flow entries and configuration complexity increases significantly

Engineering Contradiction:
Improvenetwork security coverageVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the large set of distributed service rules into multiple rule sets organized by priority levels. Each rule set contains rules with similar characteristics or priority ranges, allowing the network controller to manage and push configurations in smaller, organized batches rather than handling all rules simultaneously, thereby reducing configuration complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of organization by grouping rules into priority-based rule sets and using flattened priority lists. This transforms the flat, unstructured set of firewall rules into a multi-dimensional structure with priority levels and rule set groupings, enabling more efficient management and reduction of flow entries without compromising security coverage

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If service rules are added or modified in the distributed firewall, then security policy flexibility is improved, but churn and resource usage increase due to re-assignment of priorities

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidresource usage
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent performs preliminary organization of service rules into priority-based rule sets before they are added to the distributed firewall. By pre-flattening the rule priorities and establishing the priority structure in advance, the system minimizes the need for re-assignment when new rules are added or modified, thereby reducing churn and resource usage while maintaining security policy flexibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic priority assignment mechanism where rules are organized into flexible rule sets that can be easily updated. When service rules are added or modified, the system can dynamically adjust the flattened priority list within the existing rule set structure, allowing security policies to be flexible and adaptive without causing significant churn or resource consumption

Inventive Principle:
Principle #15Dynamics

3Productivity

If priority values are assigned to service rules for flow entry generation, then rule processing efficiency is improved, but the priority space allocation and management complexity increase

Engineering Contradiction:
Improverule processing efficiencyVSAvoidpriority space allocation
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the 16-bit priority space into multiple rule sets, with each rule set containing a flattened list of priorities. This segmentation allows the system to assign priority values in an organized manner across different rule sets, improving rule processing efficiency while managing priority space allocation in a structured way that reduces management complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter organization by transforming service rules into a flattened priority list structure. This parameter transformation optimizes the priority space utilization and simplifies the assignment process, thereby improving rule processing efficiency while reducing the complexity of priority space management through systematic reorganization

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10135727B2Address grouping for distributed service rules
Publication Date: 2018.11.20 VMWARE INC
  • US10135727B2 patent drawing
  • US10135727B2 patent drawing
  • US10135727B2 patent drawing

AI summary

Some embodiments provide a method for a network controller that manages a flow-based managed forwarding element (MFE). The method receives multiple service rules for implementation by the MFE. Each service rule matches over a set of network addresses. At least one network address is in the set of network addresses for at least two service rules. The method groups the network addresses into non-overlapping groups of network addresses, each of which addresses that are all matched by only a same set of service rules. The method generates flow entries that match over the groups of network addresses for the MFE to use to implement the service rules.