Router Layer-2 Firewall Service Type Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication systems face challenges in effectively managing and securing layer-2 traffic, particularly with unknown destination addresses, where existing firewall solutions struggle to differentiate between various service types and efficiently route packets while adhering to firewall rules and queue conditions.

Innovation Solution

A router with a datapath and layer-2 firewall is configured to receive packets with unknown destination addresses, determine service types, and send them to the layer-2 firewall based on service-specific indications, applying firewall rules and managing queue conditions to route packets appropriately among group members, ensuring secure and efficient communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packets with unknown destination addresses are sent to the layer-2 firewall for all service types, then network security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies different handling policies to different service types (VPWS vs VPLS) based on their specific security requirements. VPWS packets are always sent to the firewall while VPLS packets are sent only when queue conditions permit, creating localized quality differences in security processing that match the specific needs of each service type.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of firewall forwarding behavior based on service type identification. By detecting whether a packet belongs to VPWS or VPLS service, the router dynamically adjusts the forwarding decision parameter, sending VPWS packets to the firewall unconditionally while applying queue-based control for VPLS packets.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If packets are always forwarded to the layer-2 firewall, then security checking is improved, but productivity and network performance deteriorate

Engineering Contradiction:
Improvesecurity checkingVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of applying firewall checking to all packets unconditionally, the system applies partial action by selectively forwarding only certain packets (based on service type and queue conditions) to the layer-2 firewall. This partial application of security checking maintains adequate security while reducing the performance penalty of universal firewall processing.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system introduces dynamic behavior by using queue status as a conditional parameter. When the queue can accommodate packets, VPLS packets are sent to the firewall for security checking; when the queue is full, packets are forwarded directly without firewall processing. This dynamic adjustment optimizes network performance while maintaining security when resources are available.

Inventive Principle:
Principle #15Dynamics

3Productivity

If queue status is monitored for all packets, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvepacket forwarding efficiencyVSAvoidcontrol logic complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Queue status monitoring is applied locally and selectively only to VPLS service packets, not to all packets. VPWS packets bypass queue monitoring and are always sent to the firewall, while VPLS packets are subject to queue-based control. This localized application of queue monitoring reduces the overall complexity of the control logic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the packet handling logic into distinct paths based on service type. VPWS packets follow one path (always to firewall), while VPLS packets follow another path (queue-dependent). This segmentation of control logic makes the system more manageable and reduces the complexity of any single decision path.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11831605B2Router firewall
Publication Date: 2023.11.28 NOKIA SOLUTIONS & NETWORKS OY
  • US11831605B2 patent drawing
  • US11831605B2 patent drawing
  • US11831605B2 patent drawing

AI summary

Various example embodiments for supporting firewalling of traffic are presented. The support for firewalling of traffic may include support for firewalling of layer-2 traffic (e.g., applying firewall rules to layer-3 traffic embedded within layer-2 frames) using a layer-2 firewall. The firewalling of layer-2 traffic by a layer-2 firewall may include support for firewalling of layer-2 traffic associated with various types of layer-2 services. The firewalling of layer-2 traffic by a layer-2 firewall may include support for firewalling of layer-2 traffic for which the layer-2 destination address of the traffic is known and layer-2 traffic for which the layer-2 destination address of the traffic is unknown. The firewalling of layer-2 traffic by a layer-2 firewall may include receiving, by a router, a packet of a flow of a layer-2 service and supporting, by the router, layer-2 firewalling of the packet at the router while honoring layer-2 forwarding of the packet at the router.