Network Service Chain Cloud Entity Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network service chains lack the ability to identify and isolate cloud computing entities on a per-cloud, per-service, and per-tenant basis at the network layer, preventing network services from being applied based on cloud provider, cloud service, or cloud tenant information.

Innovation Solution

Incorporating cloud service identifiers into the metadata fields of network service headers (NSH) allows network service functions to apply services based on cloud provider, cloud service, or cloud tenant-specific policies, using a hierarchical classification scheme that includes cloud IDs, service IDs, and tenant IDs, enabling end-to-end connection and service provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional network service chains are used without cloud entity identifiers, then network services can be applied to packets, but classification and isolation on a per-cloud, per-service, and per-tenant basis cannot be achieved

Engineering Contradiction:
Improveclassification and isolation capabilityVSAvoidcloud entity information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces cloud entity identifiers (cloud ID, service ID, tenant ID) as intermediary elements that bridge the gap between network packets and cloud computing entities. These identifiers are embedded in packet headers, enabling network service functions to classify and isolate traffic based on cloud entity information without requiring direct access to cloud management systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud entity identification is segmented into multiple hierarchical levels: cloud ID for provider-level classification, service ID for service-level classification, and tenant ID for tenant-level classification. This segmentation enables granular control and isolation at different levels of the cloud computing hierarchy.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If cloud service identifiers are extracted and used for policy-based service application, then cloud-service-specific network services can be provided, but additional processing steps are required

Engineering Contradiction:
Improvepolicy-based service applicationVSAvoidprocessing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Cloud entity identifiers are extracted from packet headers at the beginning of the service chain and made available to all subsequent network service functions. This preliminary extraction action eliminates the need for each service function to independently query cloud management systems, reducing overall processing complexity despite the added extraction step.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10547692B2Adding cloud service provider, cloud service, and cloud tenant awareness to network service chains
Publication Date: 2020.01.28 CISCO TECHNOLOGY INC
  • US10547692B2 patent drawing
  • US10547692B2 patent drawing
  • US10547692B2 patent drawing

AI summary

A packet is received at a device configured to provide a service function within a network service chain. A cloud service identifier is extracted from a header of the packet. The service function is applied to the packet according to policies specific to a cloud service identified in the cloud service identifier.