Packet Header Application Signature Tag for Network Virtualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication networks face challenges in identifying and managing packet flows from different applications, especially when encryption is used, which makes it difficult to provide per-application services without increasing latency and requiring network elements to maintain stateful designs.
Innovation Solution
An application signature is added as a tag in the packet header, allowing network elements to map packets to a network virtualization identifier, enabling distributed services without the need for stateful tracking of flows, using techniques like Ethernet headers and virtualization identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network elements maintain state to track packet flows for per-application services, then service differentiation capability is improved, but device complexity and latency increase
Solution Approach 1:
The patent segments the identification task by introducing application-layer tags that carry application identifiers within packet headers. This allows network elements to identify application flows without maintaining complex state information, as the application identity is explicitly carried in the packet itself rather than requiring network element memory of flow states.
Solution Approach 2:
The application identifier is embedded in the packet header before the packet reaches network elements. This preliminary tagging action enables downstream network elements to perform simple table-lookup-based service differentiation without needing to maintain flow state, thereby reducing device complexity while preserving per-application service capability.
2Adaptability or versatility
If network elements perform flow correlation to identify application packets, then per-flow service application is improved, but processing latency increases
Solution Approach 1:
The patent separates the identification function from the forwarding function by embedding application identifiers in packet headers. This allows forwarding decisions to be made based on simple tag matching rather than complex flow correlation processing, thereby reducing latency while maintaining per-flow service capability.
Solution Approach 2:
Application identifiers are inserted into packet headers at the source before transmission. This preliminary action eliminates the need for intermediate flow correlation processing at network elements, reducing processing latency while enabling accurate per-flow service application throughout the network.
3Reliability
If encryption is applied to protect data privacy, then security is improved, but packet identification capability deteriorates
Solution Approach 1:
The patent segments information into two parts: encrypted payload data and unencrypted application identifier tags in the packet header. This allows the data payload to remain encrypted for privacy protection while the application identifier remains accessible for network processing and service differentiation.
Solution Approach 2:
The application identifier tag acts as an intermediary that bridges the gap between encrypted data and network processing requirements. It carries application identification information without requiring decryption of the payload, enabling network elements to provide appropriate services while maintaining data privacy through encryption.
Data Source
AI summary
An operating system adds an application signature as a tag in a packet header. In one embodiment the tag is inserted as a Q-tag in an Ethernet header. When a network element receives the tagged packet, it uses the tag alone or in combination with one or more additional header fields to map the packet to a network virtualization identifier segregating the application traffic on the network. Services are applied to packets according to network virtualization identifier to enable distributed application of services without requiring network elements to maintain state associated with packet flows.


