Orchestrated Network Flow Tracing With Stage-Level Rule Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network appliances struggle with tracing the application of network rules in packet processing pipelines, as existing tracing data lacks clarity on which rules are implemented, making debugging and optimization difficult.

Innovation Solution

A system and method for sending trace directives to network appliances to generate metadata indicating which processing stages apply which network rules, using configuration maps to identify specific rules, and assembling trace reports across multiple appliances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network appliances process network traffic flows by examining packet header data and applying network rules through packet processing pipelines, then network traffic can be effectively routed and controlled, but tracing the application of network rules becomes difficult and debugging optimization is hindered due to lack of clarity on which rules are implemented

Engineering Contradiction:
Improvenetwork rule application accuracyVSAvoidtracing network rule application
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary tracing mechanism that acts as a mediator between the packet processing pipeline and the tracing system. This intermediary captures metadata about which network rules are applied at each processing stage without interfering with the actual packet processing flow. The tracing system uses this intermediary to collect and report rule application information, thereby resolving the difficulty of detecting and measuring rule application while maintaining reliable network rule enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the packet processing pipeline provides information back to the tracing system about rule applications. The tracing system receives feedback metadata indicating which network rules were applied at each processing stage, processes this feedback information, and generates trace reports. This feedback loop enables effective tracing and debugging of network rule application while maintaining the reliability of the original packet processing function.

Inventive Principle:
Principle #23Feedback

2Productivity

If multiple network appliances are used to process network flows across different network segments, then network processing capacity and functionality are improved, but assembling comprehensive trace reports across multiple appliances becomes complex

Engineering Contradiction:
Improvenetwork processing capacityVSAvoidtrace report assembly complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal trace directive format and metadata structure that can be applied across multiple different network appliance types and processing stages. The tracing system uses a standardized approach that works universally across different network segments and appliances, allowing trace reports to be assembled from multiple sources without increasing complexity. The same tracing mechanisms and data structures are used regardless of which specific network appliance is processing the packet.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12368659B2Methods and systems for orchestrating network flow tracing within packet processing pipelines across multiple network appliances
Publication Date: 2025.07.22 PENSANDO SYSTEMS INC
  • US12368659B2 patent drawing
  • US12368659B2 patent drawing
  • US12368659B2 patent drawing

AI summary

An orchestrator can send trace directives to network appliances that indicate a network flow to trace. The network appliances can include packet processing pipelines that each include numerous processing stages. The network appliances implement network rules for processing network flows by configuring the pipeline's processing stages to execute specific policies for specific network packets in accordance with the network rules. The processing stages can also be configured to produce metadata indicating the policies implemented at each stage to process certain network packets in network flows indicated by trace directives. The metadata can be used to produce a trace report that indicates a network packet of the network flow, a first network rule that was applied to the network packet by a one of the first appliance processing stages, and the one of the first appliance processing stages that applied the first network rule to the network packet.