Network Device Service Data Flow Control via Label Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices, such as switches and firewalls, have low efficiency in processing service traffic due to limited capabilities in admission and application control, which hampers network performance in software-defined networks.

Innovation Solution

Implementing a method where network devices receive a service data flow with a control label, using admission and application control configuration information delivered by a controller to perform selective admission and application control based on security group information, thereby enhancing processing efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If execution point devices perform only admission control or application control on service traffic, then network security is maintained, but processing efficiency is low

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the control functions by introducing control labels that divide service traffic into different categories (admission control, application control, or both). This allows execution point devices to efficiently route different traffic types to appropriate processing paths, improving overall processing efficiency while maintaining security through selective control plane processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The controller performs preliminary action by pre-configuring control labels and control policies before traffic arrives at execution point devices. This allows the execution point devices to make rapid forwarding decisions based on pre-computed control information, significantly improving processing efficiency without compromising security validation.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If centralized control is performed on user information in the entire network, then network management is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork managementVSAvoidcontroller functionality
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts complex control logic from execution point devices and centralizes it in the controller. The controller generates control labels and policies, while execution point devices only need to perform simple label matching and forwarding decisions. This extraction reduces device complexity at execution points while maintaining centralized management capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The control label acts as an intermediary between the controller's complex policies and the execution point devices' simple forwarding logic. The label encapsulates control information that bridges the gap between centralized management requirements and distributed execution simplicity, reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3010200B1Method for controlling service data flow and network device
Publication Date: 2020.04.22 HUAWEI TECH CO LTD
  • EP3010200B1 patent drawingFigure 1
  • EP3010200B1 patent drawingFigure 2
  • EP3010200B1 patent drawingFigure 3

AI summary

Embodiments of the present invention provide a method for controlling a service data flow and a network device. The method for controlling a service data flow in the present invention includes: receiving, by a network device, a service data flow, and acquiring a control label that is carried, based on the Label Control Protocol, in the service data flow; and performing, by the network device, network access control on the service data flow according to the control label by using admission control configuration information and application control configuration information that are delivered by a controller and are based on security group information, where the network access control includes at least one of admission control and application control. According to the embodiments of the present invention, admission control and/or application control may be performed on the service data flow, so as to effectively improve efficiency of processing the service data flow by the network device.