SDN Tunnel Interface for Service Insertion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network service insertion methods in both software-defined networks (SDNs) and legacy networks face limitations in flexibility and efficiency, particularly in deploying service entities across different IP subnets, leading to potential network downtime and security risks during reconfiguration.
Innovation Solution
The implementation of an SDN-compatible network device (SDNC) that uses flow rules and hybrid network device settings to dynamically steer traffic to service entities, enabling transparent and secure service insertion through tunnel interfaces, regardless of the IP subnet, using encapsulation and decapsulation of packets to maintain original headers and tags.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If service entities are deployed in specific IP subnets in SDN, then network control can be centralized, but flexibility in service deployment is reduced
Solution Approach 1:
The patent introduces an SDN controller as an intermediary that manages service entities deployed in different IP subnets. The controller enables centralized automation while the service entities maintain deployment flexibility across multiple subnets by receiving dynamic flow rules that redirect traffic to appropriate services regardless of their subnet location.
2Adaptability or versatility
If network devices are reconfigured to deploy service entities, then service insertion can be achieved, but network downtime occurs
Solution Approach 1:
The patent implements preliminary action by pre-configuring service entities in standby positions within the network infrastructure. When service insertion is needed, pre-established tunnel interfaces and flow rule templates are quickly activated, avoiding the need for time-consuming device reconfiguration and minimizing network downtime.
Solution Approach 2:
The system employs dynamic flow rules that can be modified in real-time by the SDN controller without requiring static reconfiguration of network devices. This dynamic approach allows service entities to be inserted and removed from traffic flows on-the-fly, eliminating the network downtime associated with traditional reconfiguration methods.
3Adaptability or versatility
If network devices are reconfigured for service insertion, then service deployment is possible, but security risks increase
Solution Approach 1:
The SDN controller acts as a secure intermediary that manages all service deployment operations. It validates service entity credentials, authenticates traffic redirection requests, and enforces security policies before allowing flow rule modifications. This centralized security management reduces the security risks associated with distributed device reconfiguration.
Solution Approach 2:
The system implements feedback mechanisms where the SDN controller continuously monitors service entity performance and security compliance. Flow rules include validation checks that verify service entity authenticity and proper operation, providing real-time feedback to detect and prevent security violations, thereby reducing security risks during service deployment.
4Ease of operation
If tunnel interfaces are used for service insertion, then transparency to source and destination devices is achieved, but device complexity increases
Solution Approach 1:
The patent extracts the tunnel interface management complexity from end devices and centralizes it in the SDN controller. Source and destination devices simply send and receive traffic without needing to understand or configure tunnel interfaces. The SDN controller handles all tunnel establishment, encapsulation, and decapsulation operations, maintaining transparency for end devices while managing the complexity centrally.
Data Source
Figure 1a~1b
Figure 1c
Figure 1d
AI summary
Network service insertion includes determining a tunnel interface corresponding to a service entity to which an incoming packet is to be directed, the tunnel interface being determined based on software defined network (SDN) flow rules. Further, the incoming packet can be encapsulated based on a tunnel configuration corresponding to the tunnel interface to generate an encapsulated packet such that the encapsulated packet includes media access control (MAC) address headers and a virtual local area network (VLAN) tag associated with the incoming packet. The encapsulated packet can be sent to the service entity through the tunnel interface for network service insertion.