Datacenter Network Topology Generation via Routing and MAC Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network topology generation methods in datacenters, relying on protocols like LLDP and CDP, face security concerns due to lack of authentication and potential for denial of service attacks, making it necessary to disable these protocols, which complicates determining network device adjacencies and paths, especially in environments without VLAN information.
Innovation Solution
A management node is introduced to generate network topology based on network device information, using routing and MAC address information to determine adjacency between devices, allowing for secure network path generation even without CDP/LLDP, by storing device information and using a network topology generation unit to create a network path between endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If protocols like LLDP and CDP are used for network topology generation, then network device adjacency determination is simplified, but security vulnerabilities increase due to lack of authentication and susceptibility to denial of service attacks
Solution Approach 1:
The patent extracts the topology generation function from dependent protocols (LLDP/CDP) and implements it using standard routing protocols that are already present in the network. By extracting the adjacency determination logic from proprietary protocols and implementing it through analysis of routing table data from standard protocols, the system eliminates security vulnerabilities while maintaining functionality.
Solution Approach 2:
The patent introduces a management node as an intermediary that collects routing table information from multiple network devices and performs adjacency determination centrally. This intermediary approach allows secure collection of routing data using authenticated protocols while performing the topology generation function in a controlled manner, avoiding direct exposure to unauthenticated protocol exchanges.
2Reliability
If CDP/LLDP protocols are disabled for security reasons, then network security is improved, but network topology generation becomes more complex and requires manual inspection
Solution Approach 1:
The patent implements self-service by enabling network devices to automatically provide their routing table information to the management node through standard routing protocols. The management node then automatically performs adjacency determination and topology generation without requiring manual inspection or configuration, allowing the system to serve itself while maintaining security.
Solution Approach 2:
The patent establishes a feedback mechanism where the management node collects routing table information from network devices, processes this data to determine adjacencies, and uses this information to generate and update the network topology. This continuous feedback loop automates the topology generation process, eliminating the need for manual intervention while maintaining accuracy.
3Reliability
If manual inspection methods are used for topology generation, then security concerns are addressed, but time consumption and productivity decrease
Solution Approach 1:
The patent applies preliminary action by having network devices pre-populate their routing tables using standard routing protocols before topology generation is needed. The management node then leverages this pre-existing routing information to automatically determine adjacencies and generate topology, eliminating the need for time-consuming manual inspection while maintaining security.
Solution Approach 2:
The patent substitutes the mechanical system of manual inspection with an automated electronic system. The management node electronically collects routing table data from multiple devices and automatically performs adjacency determination through algorithmic processing, replacing manual visual inspection and significantly improving productivity while maintaining security standards.
Data Source
AI summary
In one example, a management node may include a storage device to store network device information associated with a plurality of network devices and physical hosts in a datacenter. Example network device information may include at least one of routing information and media access control (MAC) address information. Further, the management node may include a processor operable with the storage device and memory coupled to the processor. In one example, the memory may include a network topology generation unit to determine adjacency between the plurality of network devices in the datacenter using the routing information and/or media access control (MAC) address information associated with the plurality of network devices and generate a network topology including a network path between a source endpoint and a destination endpoint using the adjacency between the plurality of network devices.


