Network Services Header Tagging for Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring network services and security policies in modern networks is a time-consuming and complex task, particularly in cloud provider and data center networks where rapid application deployment is essential, due to the mobility of virtual machines and services.

Innovation Solution

The method involves inserting user identification and service identification information into Network Services Headers of packets, allowing network devices to process packets based on this metadata, thereby simplifying policy application and reducing the need for deep packet inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is used to process packets and apply network services, then policy application accuracy is improved, but processing time and complexity increase

Engineering Contradiction:
Improvepolicy application accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by inserting service identification information into packet headers at the edge of the network fabric before packets enter the core switching fabric. This pre-tagging approach allows core switches to make forwarding decisions based on pre-inserted metadata rather than performing deep packet inspection, thereby reducing processing time while maintaining policy application accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts critical policy-relevant information (service identification, user identification) from packet payloads and places it into packet headers at the network edge. This extraction allows core network devices to process packets based on header information only, eliminating the need for time-consuming deep packet inspection while preserving policy enforcement capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If network services are configured in traditional networks, then service policy control is achieved, but configuration time and complexity increase

Engineering Contradiction:
Improveservice policy controlVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary configuration by establishing service identification information and mapping it to network services at the network edge before packets traverse the core fabric. This pre-configuration enables rapid service deployment and simplifies policy management, as services are identified by metadata rather than requiring complex traditional network configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces service identification information as an intermediary element between applications and network services. This intermediary metadata layer simplifies service configuration and policy control by providing a standardized interface for service identification, eliminating the need for complex traditional network service configuration while maintaining reliable service control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If virtual machines and services are made mobile in data center networks, then adaptability is improved, but network service topology management becomes complex

Engineering Contradiction:
Improvevirtual machine mobilityVSAvoidnetwork service topology management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts service identification information from fixed network topology dependencies and embeds it in packet headers. This allows virtual machines and services to move freely within the network fabric without requiring complex topology reconfiguration, as service identification is decoupled from physical network structure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The service identification information serves multiple functions: it identifies services for policy control, enables rapid service deployment, and facilitates virtual machine mobility. This universal metadata approach simplifies network service topology management while supporting adaptable virtual machine movement across the network fabric.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9800551B2AVC Bi-directional correlation using an overlay fabric header
Publication Date: 2017.10.24 CISCO TECHNOLOGY INC
  • US9800551B2 patent drawing
  • US9800551B2 patent drawing
  • US9800551B2 patent drawing

AI summary

Techniques for tagging packets within a network fabric. An authentication device for a network fabric receives a first packet originating from a source device, in transit to a destination device, corresponding to a first network flow. User identification information corresponding to an authenticated user of the source device is inserted into a Network Services Header of the first packet. Embodiments receive a second packet that corresponds to the first network flow at the authentication device, the second packet including service identification information within a Network Services Header of the second packet that identifies a service type of the network flow. Upon receiving a third packet for the first network flow, the authentication device inserts the user identification and the service identification information into a Network Services Header of the third packet.