Overlay Switch Role Segmentation via Fabric Route Packets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-fabric overlay networks, efficiently managing and distributing role information for fine-grained role-based traffic segmentation is challenging, leading to disruptions when end devices move between fabrics and requiring extensive policy programming in access switches.

Innovation Solution

Incorporating role information into fabric route packets and maintaining it in local data structures at switches, allowing switches to learn and distribute network addresses with associated roles, thereby enabling seamless role-based segmentation across the network without re-authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If role information is distributed across multiple switches in overlay networks, then role-based traffic segmentation can be enforced, but network complexity and policy programming overhead increase significantly

Engineering Contradiction:
Improverole-based traffic segmentation enforcementVSAvoidpolicy programming overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling switches to automatically learn and distribute role information through fabric route packets without requiring manual policy programming. Switches autonomously populate their local data structures with role information received from other switches, eliminating the need for administrators to manually configure segmentation policies on each device.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments role information distribution by maintaining it at the granularity of individual network addresses in local data structures at each switch. This allows role information to be distributed independently for each network address, enabling fine-grained traffic segmentation while reducing overall system complexity through modular, address-specific role management.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If role information is maintained at fine-grained network address level, then seamless role-based segmentation is achieved during device migration, but data structure and processing overhead increase

Engineering Contradiction:
Improveseamless device migration supportVSAvoiddata structure overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-distributing role information associated with network addresses through fabric route packets before device migration occurs. When an end device moves between fabrics, its role information is already present in the new fabric's switches, enabling seamless continuation of role-based segmentation without re-authentication or service interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent achieves universality by using fabric route packets, which are existing overlay network control plane messages, to carry both network address information and role information. This multi-functional use of standard packets reduces the need for specialized data structures while enabling fine-grained role-based segmentation and seamless device migration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If role information is distributed through existing control plane packets, then implementation complexity is reduced, but role information may not be propagated efficiently across all switches

Engineering Contradiction:
Improveimplementation simplicityVSAvoidrole information propagation completeness
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent implements feedback by utilizing the existing control plane packet routing mechanisms that already ensure complete propagation of routing information across all switches in the overlay network. Fabric route packets are naturally distributed to all relevant switches through established control plane protocols, ensuring that role information associated with network addresses is propagated efficiently and completely without requiring additional distribution logic.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250016091A1Fine-grained role-based segmentation in overlay network
Publication Date: 2025.01.09 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250016091A1 patent drawing
  • US20250016091A1 patent drawing
  • US20250016091A1 patent drawing

AI summary

A system for facilitating segmentation by a first switch of an overlay tunnel fabric is provided. During operation, the system can receive a route update packet for the fabric. The packet can be based on a control plane that allows the exchange of route information via the tunnel and can include a first media access control (MAC) address learned at a second switch and a first role identifier of a first role. The first role can indicate a level of access granted to a first device associated with the first MAC address. The system can store the first MAC address and the first role identifier in a local address data structure. Upon receiving a packet from the first device, the system can then determine, based on the first role identifier and a first segmentation policy, whether a local device is allowed to receive the packet from the first device.