SDN Flow Rule Prioritization Engine for Conflict Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In software-defined networking (SDN) systems, the integration of multiple SDN applications from different vendors can lead to conflicting rules and actions, resulting in unpredictable network behavior, as each application assumes full control over the flow table pipeline, making it difficult to leverage new innovations without building a comprehensive SDN application that encompasses all desired functionalities.
Innovation Solution
A network switching system that includes a storage device with application-provided flow-based rules and a packet processor with a flow-based handler and rule processing engine, which determines priorities and applies rules to packets, allowing multiple SDN applications to operate independently without conflicts by associating and prioritizing flow-based rules for each packet based on its flow session.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple SDN applications are integrated into the system, then the functionality and versatility of the network switching system is improved, but conflicting rules and unpredictable network behavior occur
Solution Approach 1:
The patent introduces a flow-based rule processing engine as an intermediary component that sits between multiple SDN applications and the flow table pipeline. This engine receives flow-based rules from multiple applications, processes them through a standardized interface, and applies them in a controlled manner. The intermediary resolves conflicts between applications by providing a centralized rule processing mechanism that ensures predictable network behavior while maintaining the ability to integrate multiple functional applications.
Solution Approach 2:
The patent segments the rule processing functionality into distinct components: individual SDN applications can independently provide flow-based rules, while the flow-based rule processing engine separately handles rule prioritization, conflict resolution, and application to the flow table pipeline. This segmentation allows each application to maintain its independence and functionality while the system as a whole achieves predictability through structured rule processing.
2Reliability
If a single comprehensive SDN application is built to perform all functions, then conflicting rules are avoided and network behavior is predictable, but the system complexity and difficulty of integrating new innovations increases
Solution Approach 1:
The flow-based rule processing engine serves as a universal component that can handle flow-based rules from any SDN application regardless of its specific function. Rather than requiring each application to be custom-built for specific functions, the universal rule processing engine provides a standardized mechanism for all applications to contribute their rules. This multi-functional approach allows the system to integrate diverse applications (load balancing, security policy, routing) without increasing overall system complexity.
Solution Approach 2:
The rule processing engine acts as an intermediary that shields individual applications from the complexity of rule conflict resolution and prioritization. Applications simply provide their flow-based rules through a standardized interface, while the intermediary handles the complex tasks of rule validation, prioritization, and conflict resolution. This separation of concerns reduces application complexity while maintaining predictable network behavior.
3Ease of operation
If SDN applications assume full control over the flow table pipeline, then each application can independently manage its rules, but conflicts arise when multiple applications are added
Solution Approach 1:
Instead of allowing each SDN application to directly control and modify the flow table pipeline (the traditional approach), the patent inverts the control structure. The flow-based rule processing engine is positioned between the applications and the pipeline, receiving rules from applications but controlling their application to the pipeline. This inversion maintains application independence for rule generation while ensuring rule consistency through centralized control of the rule application process.
Solution Approach 2:
The flow-based rule processing engine serves as an intermediary that decouples application independence from rule consistency. Applications can independently generate and submit their flow-based rules through standardized interfaces, maintaining ease of operation and application independence. The intermediary then processes these rules through a consistent framework that ensures reliability and prevents conflicts before applying them to the flow table pipeline.
Data Source
AI summary
A network switching system includes a storage device including a plurality of application-provided flow-based rules provided by a plurality of applications. A packet processor is coupled to the storage device and includes a flow-based handler that is operable to receive a packet, determine that the packet is associated with a flow session, and associate a plurality of the application-provided flow-based rules with the packet based the association of the packet with the flow session. The packet processor also includes a flow-based rule processing engine that is operable to determine a priority for the plurality of application-provided flow-based rules and apply at least one of the plurality of application-provided flow-based rules to the packet according to the priority. The system allows a plurality of SDN applications to operate in a network switching system independently and without knowledge of each other.


