Network Services Header Tagging for Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring network services and security policies in modern networks is a time-consuming and complex task, particularly in cloud provider and data center networks where rapid application deployment is essential, due to the mobility of virtual machines and services.
Innovation Solution
The method involves inserting user identification and service identification information into Network Services Headers of packets, allowing network devices to process packets based on this metadata, thereby simplifying policy application and reducing the need for deep packet inspection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is used to process packets and apply network services, then policy application accuracy is improved, but processing time and complexity increase
Solution Approach 1:
The patent applies preliminary action by inserting service identification information into packet headers at the edge of the network fabric before packets enter the core switching fabric. This pre-tagging approach allows core switches to make forwarding decisions based on pre-inserted metadata rather than performing deep packet inspection, thereby reducing processing time while maintaining policy application accuracy.
Solution Approach 2:
The patent extracts critical policy-relevant information (service identification, user identification) from packet payloads and places it into packet headers at the network edge. This extraction allows core network devices to process packets based on header information only, eliminating the need for time-consuming deep packet inspection while preserving policy enforcement capabilities.
2Reliability
If network services are configured in traditional networks, then service policy control is achieved, but configuration time and complexity increase
Solution Approach 1:
The system performs preliminary configuration by establishing service identification information and mapping it to network services at the network edge before packets traverse the core fabric. This pre-configuration enables rapid service deployment and simplifies policy management, as services are identified by metadata rather than requiring complex traditional network configuration.
Solution Approach 2:
The patent introduces service identification information as an intermediary element between applications and network services. This intermediary metadata layer simplifies service configuration and policy control by providing a standardized interface for service identification, eliminating the need for complex traditional network service configuration while maintaining reliable service control.
3Adaptability or versatility
If virtual machines and services are made mobile in data center networks, then adaptability is improved, but network service topology management becomes complex
Solution Approach 1:
The patent extracts service identification information from fixed network topology dependencies and embeds it in packet headers. This allows virtual machines and services to move freely within the network fabric without requiring complex topology reconfiguration, as service identification is decoupled from physical network structure.
Solution Approach 2:
The service identification information serves multiple functions: it identifies services for policy control, enables rapid service deployment, and facilitates virtual machine mobility. This universal metadata approach simplifies network service topology management while supporting adaptable virtual machine movement across the network fabric.
Data Source
AI summary
Techniques for tagging packets within a network fabric. An authentication device for a network fabric receives a first packet originating from a source device, in transit to a destination device, corresponding to a first network flow. User identification information corresponding to an authenticated user of the source device is inserted into a Network Services Header of the first packet. Embodiments receive a second packet that corresponds to the first network flow at the authentication device, the second packet including service identification information within a Network Services Header of the second packet that identifies a service type of the network flow. Upon receiving a third packet for the first network flow, the authentication device inserts the user identification and the service identification information into a Network Services Header of the third packet.


