Overlay Flow Entry Removal for Role-Based Traffic Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In overlay networks, managing resources for role-based traffic segmentation is inefficient due to unused entries in flow data structures when packets are dropped at destination devices, leading to overutilization and inability to allocate resources to legitimate flows.

Innovation Solution

The destination network device sends a control packet to the source network device indicating RBTS enforcement, allowing the source to remove specific entries from the flow data structure and maintain generic entries in a cache, thereby freeing resources and managing bandwidth efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the source network device maintains flow entries in the flow data structure for all packets, then traffic segmentation is enforced, but resources are overutilized due to unused entries when packets are dropped at destination devices

Engineering Contradiction:
Improvetraffic segmentation enforcementVSAvoidflow data structure capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and removes unused flow entries from the flow data structure by having the destination network device send control packets to the source network device indicating RBTS enforcement. This allows the source to free up resources by removing entries corresponding to dropped packets while maintaining necessary entries for legitimate traffic flows.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a feedback mechanism where the destination network device sends control packets back to the source network device to indicate when RBTS has been enforced and packets should be dropped. This feedback loop enables the source to dynamically manage its flow data structure by removing unused entries based on actual traffic conditions.

Inventive Principle:
Principle #23Feedback

2Quantity of substance

If the source network device removes entries from the flow data structure, then resource utilization is optimized, but the ability to track and manage traffic flows is reduced

Engineering Contradiction:
Improveflow data structure capacityVSAvoidtraffic flow tracking information
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The patent selectively extracts only the unused flow entries from the flow data structure while retaining entries for active legitimate traffic flows. The control packets from the destination provide the information needed to identify which entries should be removed, ensuring that traffic flow tracking capability is maintained for useful traffic while freeing resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The feedback control packets contain information about which flow entries correspond to dropped packets, enabling the source network device to remove only those specific entries while preserving entries for active flows. This selective removal maintains necessary traffic management information.

Inventive Principle:
Principle #23Feedback

3Reliability

If the destination network device enforces RBTS on all packets, then security is improved, but network performance deteriorates due to unnecessary packet forwarding attempts

Engineering Contradiction:
Improverole-based securityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by having the source network device remove flow entries before packets are actually forwarded to the destination. When the source receives a control packet indicating RBTS enforcement, it proactively removes the corresponding flow entry, preventing future unnecessary forwarding attempts and improving network throughput.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The feedback mechanism allows the destination to inform the source about RBTS enforcement decisions. The source uses this feedback to remove flow entries for dropped packets, preventing repeated attempts to forward these packets and reducing unnecessary network traffic while maintaining security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260012416A1Efficient resource management for role-based traffic segmentation in an overlay network
Publication Date: 2026.01.08 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20260012416A1 patent drawing
  • US20260012416A1 patent drawing
  • US20260012416A1 patent drawing

AI summary

A first network device in a network is provided. During operation, the first network device can send a first packet of a first data flow to a second network device in the network. Here, a source of the first data flow can be associated with a first role and a destination of the first data flow can be associated with a second role. The first network device can receive, from the second network device, a control packet indicating that the second role is precluded from receiving traffic from the first role. The first network device can then identify the first data flow based on information in a payload of the control packet and remove an entry from a flow data structure maintained in the forwarding hardware of the first network device. The entry can include identifying information of the first data flow.