Overlay Flow Entry Removal for Role-Based Traffic Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In overlay networks, managing resources for role-based traffic segmentation is inefficient due to unused entries in flow data structures when packets are dropped at destination devices, leading to overutilization and inability to allocate resources to legitimate flows.
Innovation Solution
The destination network device sends a control packet to the source network device indicating RBTS enforcement, allowing the source to remove specific entries from the flow data structure and maintain generic entries in a cache, thereby freeing resources and managing bandwidth efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the source network device maintains flow entries in the flow data structure for all packets, then traffic segmentation is enforced, but resources are overutilized due to unused entries when packets are dropped at destination devices
Solution Approach 1:
The patent extracts and removes unused flow entries from the flow data structure by having the destination network device send control packets to the source network device indicating RBTS enforcement. This allows the source to free up resources by removing entries corresponding to dropped packets while maintaining necessary entries for legitimate traffic flows.
Solution Approach 2:
The patent implements a feedback mechanism where the destination network device sends control packets back to the source network device to indicate when RBTS has been enforced and packets should be dropped. This feedback loop enables the source to dynamically manage its flow data structure by removing unused entries based on actual traffic conditions.
2Quantity of substance
If the source network device removes entries from the flow data structure, then resource utilization is optimized, but the ability to track and manage traffic flows is reduced
Solution Approach 1:
The patent selectively extracts only the unused flow entries from the flow data structure while retaining entries for active legitimate traffic flows. The control packets from the destination provide the information needed to identify which entries should be removed, ensuring that traffic flow tracking capability is maintained for useful traffic while freeing resources.
Solution Approach 2:
The feedback control packets contain information about which flow entries correspond to dropped packets, enabling the source network device to remove only those specific entries while preserving entries for active flows. This selective removal maintains necessary traffic management information.
3Reliability
If the destination network device enforces RBTS on all packets, then security is improved, but network performance deteriorates due to unnecessary packet forwarding attempts
Solution Approach 1:
The patent implements preliminary action by having the source network device remove flow entries before packets are actually forwarded to the destination. When the source receives a control packet indicating RBTS enforcement, it proactively removes the corresponding flow entry, preventing future unnecessary forwarding attempts and improving network throughput.
Solution Approach 2:
The feedback mechanism allows the destination to inform the source about RBTS enforcement decisions. The source uses this feedback to remove flow entries for dropped packets, preventing repeated attempts to forward these packets and reducing unnecessary network traffic while maintaining security.
Data Source
AI summary
A first network device in a network is provided. During operation, the first network device can send a first packet of a first data flow to a second network device in the network. Here, a source of the first data flow can be associated with a first role and a destination of the first data flow can be associated with a second role. The first network device can receive, from the second network device, a control packet indicating that the second role is precluded from receiving traffic from the first role. The first network device can then identify the first data flow based on information in a payload of the control packet and remove an entry from a flow data structure maintained in the forwarding hardware of the first network device. The entry can include identifying information of the first data flow.


