Prefix-Based Fat Flows for Cloud Data Center Flow Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems in cloud data centers face challenges in efficiently managing large numbers of flows due to resource limitations, particularly under conditions like DDOS attacks, where microflows do not scale effectively and lead to performance bottlenecks.

Innovation Solution

The formation of prefix-based fat flows, where multiple microflows are aggregated using criteria such as IP addresses and port numbers, allowing for the configuration of fat flows that ignore specific IP or port details, enabling efficient load balancing and reducing the entropy that disrupts flow management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If microflows are used to manage individual flows, then flow management precision is improved, but system scalability deteriorates under DDOS attack conditions

Engineering Contradiction:
Improveflow management precisionVSAvoidsystem scalability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent merges multiple microflows into macroflows by aggregating flows that share common characteristics (such as destination IP address, source IP address, or port numbers). This consolidation reduces the number of individual flow entries the system must manage, thereby improving scalability during DDOS attacks while maintaining the ability to distinguish between different traffic patterns through the aggregated flow representation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameters used for flow identification from granular microflow parameters (individual source-destination-port tuples) to coarser macroflow parameters (aggregated IP prefixes and port ranges). This parameter transformation enables the system to handle large volumes of flows efficiently while preserving sufficient differentiation to manage traffic strategically during attack conditions.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multiple microflows are managed individually, then flow differentiation accuracy is improved, but resource consumption increases

Engineering Contradiction:
Improveflow differentiation accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent combines multiple individual flow entries into aggregated macroflow entries, reducing the total number of flow table entries required. This merging operation directly decreases memory consumption and processing overhead while maintaining flow differentiation accuracy through the use of meaningful aggregation keys (IP addresses, ports) that preserve traffic identification capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal flow management mechanism that can handle both normal traffic and attack traffic through a unified macroflow aggregation approach. This multi-functional system simultaneously provides flow differentiation for legitimate traffic and resource efficiency for attack mitigation, eliminating the need for separate handling mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Quantity of substance

If fat flows are formed by aggregating multiple flows, then resource constraints are reduced, but flow management complexity increases

Engineering Contradiction:
Improveresource constraintsVSAvoidflow management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent simplifies flow management complexity by transforming the management interface from individual microflow parameters to aggregated macroflow parameters. This parameter abstraction reduces the cognitive and computational complexity of managing flows during attacks, as administrators and systems work with higher-level aggregates rather than granular details, while still maintaining sufficient precision for effective traffic management.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11165703B2Prefix-based fat flows
Publication Date: 2021.11.02 JUNIPER NETWORKS INC
  • US11165703B2 patent drawing
  • US11165703B2 patent drawing
  • US11165703B2 patent drawing

AI summary

A network device includes one or more processors configured to use a fat flow rule that specifies at least one of a mask to be applied to source Internet protocol (IP) addresses or to destination IP addresses, or that source ports or destination ports are to be ignored. The one or more processors may further be configured to receive packets having different source or destination IP addresses and/or different source or destination ports, and nevertheless assign the packets to the same fat flow according to the fat flow rule, e.g., by masking the source or destination IP addresses and/or ignoring the source or destination ports of the packets. In this manner, the network device may aggregate two or more different flows into a single fat flow.