Network Traffic Tunneling Through Service Blocks for Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks lack efficient mechanisms to tunnel network traffic for applying network functions such as security checks and policy enforcement across different entities, leading to inefficiencies in network management and security.

Innovation Solution

A network control system utilizing a software-defined network (SDN) controller to tunnel packets through a service insertion point and service block, applying network functions like NAT, encryption, and firewalling by adding service identifiers and performing look-up processes to ensure packets are routed with desired network functions applied.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If network traffic is directly routed between hosts without tunneling, then routing speed is improved, but network function application capability deteriorates

Engineering Contradiction:
Improverouting speedVSAvoidnetwork function application capability
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent introduces service insertion points and service blocks as intermediary components between source and destination hosts. These intermediaries enable network functions (firewall, NAT, encryption) to be applied to traffic without requiring direct host-to-host routing, thus maintaining routing efficiency while adding function application capability through the tunneling architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network functions are applied to all packets, then security and control are improved, but network overhead increases

Engineering Contradiction:
Improvesecurity and controlVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies network functions selectively based on service identifiers rather than uniformly to all packets. Different service blocks handle different types of traffic with appropriate functions (e.g., firewall for sensitive traffic, passthrough for trusted traffic), reducing unnecessary processing overhead while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial network function application by using service identifiers to determine which packets require which functions. Not all packets undergo all network functions - only those with matching service identifiers receive specific treatments, optimizing the balance between security and overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If service identifiers are added to packets, then network function routing is improved, but packet processing complexity increases

Engineering Contradiction:
Improvenetwork function routingVSAvoidpacket processing complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The service identifier field in the packet header serves multiple functions: it identifies the service type, determines routing decisions, and triggers appropriate network functions. This multi-functional use of a single field simplifies the overall system architecture compared to implementing separate identification and routing mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12463899B2Systems and methods for tunneling network traffic to apply network functions
Publication Date: 2025.11.04 GOOGLE LLC
  • US12463899B2 patent drawing
  • US12463899B2 patent drawing
  • US12463899B2 patent drawing

AI summary

The systems and methods described herein provide a mechanism to apply network functions to a packet. The packet received by a network switch from a host may be configured so that the packet may be transmitted and forwarded to a target destination with desired network function, such as desired security settings, traffic path control or policy enforcement. In one example, the system may include a network switch and a network controller. The packet from hosts may enter the network switch through network ports (Px). The packet may then be tunneled and further transmitted to a server insertion to add a service identifier for the packet. The packet with the service modifier is then transmitted to a service block over the network. The service block may apply specific network functions to be processed or already processed to the packets. Subsequently, the packet with the specific network functions may then routes to the target destination with the desired network functions.