Packet Tagging Node for Metro Network Capacity and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Metro networks face bottlenecks due to limited capacity and high operational overhead of TDM circuits, and basic Ethernet switches lack customer separation, security, and scalability, allowing cross-traffic and potential DoS attacks, with complex hardware and slow restoration protocols.

Innovation Solution

Implementing a node with access ports and uplinks that tag and forward packets in a tree topology, using standard 802.1q tagged Ethernet frames for multiplexing and de-multiplexing, and employing full duplex links for secure and efficient traffic management, allowing for automatic topology detection and configuration to prevent cross-traffic and enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If TDM circuits are used to connect customers to the Internet, then customer connectivity is provided, but capacity is limited and operational overhead is high

Engineering Contradiction:
ImprovecapacityVSAvoidoperational overhead
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/TDM-based circuit switching system with a packet-based Ethernet switching system. This substitution enables statistical multiplexing of traffic, allowing multiple customers to share the same physical infrastructure with higher capacity and lower operational overhead, directly resolving the contradiction between limited capacity and high operational overhead in TDM systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of traffic representation from fixed TDM circuits to variable packet-based Ethernet frames. This parameter change enables flexible capacity allocation through statistical multiplexing, allowing the network to dynamically adjust to varying traffic demands and achieve higher productivity with reduced operational complexity

Inventive Principle:
Principle #35Parameter changes

2Productivity

If basic Ethernet switches are used for packet-based access, then high capacity is achieved, but customer separation and security are compromised

Engineering Contradiction:
ImprovecapacityVSAvoidcustomer separation and security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the Ethernet switch functionality by introducing separate Virtual LAN (VLAN) tables and forwarding tables for different customers. This segmentation allows multiple customers to share the same physical Ethernet infrastructure while maintaining logical isolation, thus achieving high capacity through packet switching while preserving customer separation and security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces VLAN tags as intermediary elements between the physical Ethernet frame and the forwarding decision. These tags act as mediators that carry customer identification information, enabling the switch to distinguish between different customers' traffic and enforce security policies while maintaining the high-speed packet-based architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automatic features like dynamic address learning are enabled in Ethernet switches, then forwarding is optimized, but security is reduced due to potential DoS attacks

Engineering Contradiction:
Improveforwarding optimizationVSAvoidDoS attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by enabling dynamic address learning only for specific VLANs or customer groups while maintaining stricter security controls for others. This selective approach allows forwarding optimization to be applied where safe, while preventing DoS attacks in critical segments through localized security policies

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback mechanisms through VLAN-based MAC address learning, where the switch learns and tracks MAC addresses within the context of specific VLANs. This feedback loop allows the system to optimize forwarding for legitimate traffic while detecting and blocking suspicious patterns that indicate DoS attacks, thus balancing optimization with security

Inventive Principle:
Principle #23Feedback

4Reliability

If manual configuration is used for security in Ethernet switches, then security is improved, but device complexity and configuration time increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables self-service through automatic VLAN assignment and configuration based on pre-defined policies. When packets arrive, the switch automatically determines the appropriate VLAN and applies security controls without requiring manual configuration for each customer, thus maintaining high security while reducing configuration complexity and time

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7283524B2Method of sending a packet through a node
Publication Date: 2007.10.16 ADTRAN NETWORKS (UK) LTD
  • US7283524B2 patent drawing
  • US7283524B2 patent drawing
  • US7283524B2 patent drawing

AI summary

The method is for sending information through a node and includes providing a node that has a first access port, a second access port, a first uplink and a second uplink. A first packet is sent via the first access port to the node. When the node is in a leaf mode, the node creates a tag inside the first packet. The tag contains a first port number corresponding to the first access port. When the node is in a branch node, the node adds the first port number to the tag and sends the packet in the first uplink and the second uplink. A second packet, received via the second access port, is sent via the first uplink of the node. The node receives the second packet. The node removes a second port number that corresponds to the second access port from the tag. The node sends the second packet via the second access port to another node or customer lower down in the node tree.