Packet Tagging Node for Metro Network Capacity and Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Metro networks face bottlenecks due to limited capacity and high operational overhead of TDM circuits, and basic Ethernet switches lack customer separation, security, and scalability, allowing cross-traffic and potential DoS attacks, with complex hardware and slow restoration protocols.
Innovation Solution
Implementing a node with access ports and uplinks that tag and forward packets in a tree topology, using standard 802.1q tagged Ethernet frames for multiplexing and de-multiplexing, and employing full duplex links for secure and efficient traffic management, allowing for automatic topology detection and configuration to prevent cross-traffic and enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If TDM circuits are used to connect customers to the Internet, then customer connectivity is provided, but capacity is limited and operational overhead is high
Solution Approach 1:
The patent replaces the mechanical/TDM-based circuit switching system with a packet-based Ethernet switching system. This substitution enables statistical multiplexing of traffic, allowing multiple customers to share the same physical infrastructure with higher capacity and lower operational overhead, directly resolving the contradiction between limited capacity and high operational overhead in TDM systems
Solution Approach 2:
The patent changes the fundamental parameter of traffic representation from fixed TDM circuits to variable packet-based Ethernet frames. This parameter change enables flexible capacity allocation through statistical multiplexing, allowing the network to dynamically adjust to varying traffic demands and achieve higher productivity with reduced operational complexity
2Productivity
If basic Ethernet switches are used for packet-based access, then high capacity is achieved, but customer separation and security are compromised
Solution Approach 1:
The patent segments the Ethernet switch functionality by introducing separate Virtual LAN (VLAN) tables and forwarding tables for different customers. This segmentation allows multiple customers to share the same physical Ethernet infrastructure while maintaining logical isolation, thus achieving high capacity through packet switching while preserving customer separation and security
Solution Approach 2:
The patent introduces VLAN tags as intermediary elements between the physical Ethernet frame and the forwarding decision. These tags act as mediators that carry customer identification information, enabling the switch to distinguish between different customers' traffic and enforce security policies while maintaining the high-speed packet-based architecture
3Ease of operation
If automatic features like dynamic address learning are enabled in Ethernet switches, then forwarding is optimized, but security is reduced due to potential DoS attacks
Solution Approach 1:
The patent applies local quality by enabling dynamic address learning only for specific VLANs or customer groups while maintaining stricter security controls for others. This selective approach allows forwarding optimization to be applied where safe, while preventing DoS attacks in critical segments through localized security policies
Solution Approach 2:
The patent implements feedback mechanisms through VLAN-based MAC address learning, where the switch learns and tracks MAC addresses within the context of specific VLANs. This feedback loop allows the system to optimize forwarding for legitimate traffic while detecting and blocking suspicious patterns that indicate DoS attacks, thus balancing optimization with security
4Reliability
If manual configuration is used for security in Ethernet switches, then security is improved, but device complexity and configuration time increase
Solution Approach 1:
The patent enables self-service through automatic VLAN assignment and configuration based on pre-defined policies. When packets arrive, the switch automatically determines the appropriate VLAN and applies security controls without requiring manual configuration for each customer, thus maintaining high security while reducing configuration complexity and time
Data Source
AI summary
The method is for sending information through a node and includes providing a node that has a first access port, a second access port, a first uplink and a second uplink. A first packet is sent via the first access port to the node. When the node is in a leaf mode, the node creates a tag inside the first packet. The tag contains a first port number corresponding to the first access port. When the node is in a branch node, the node adds the first port number to the tag and sends the packet in the first uplink and the second uplink. A second packet, received via the second access port, is sent via the first uplink of the node. The node receives the second packet. The node removes a second port number that corresponds to the second access port from the tag. The node sends the second packet via the second access port to another node or customer lower down in the node tree.


