Segment Routing Path Constraint for Firewall Inclusion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Segment Routing (SR) networks, it is not guaranteed that a packet forwarding path includes a specific key node, such as a firewall, which can compromise network security.
Innovation Solution
A method and system where a network node obtains a segment identifier advertisement message with a flag bit indicating that a packet needs to be forwarded through a specific node, ensuring that the packet forwarding path includes that node.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If an SR network node uses shortest path first algorithm to calculate packet forwarding path, then forwarding efficiency is improved, but it cannot be ensured that packet passes through specific key node
Solution Approach 1:
The patent segments the forwarding path into multiple segments using segment identifiers (SIDs). Each SID represents a specific node or link segment, allowing the network to divide the end-to-end path into controllable segments. This segmentation enables the path to be constructed by concatenating specific SIDs, ensuring passage through key nodes while maintaining routing efficiency.
Solution Approach 2:
The patent performs preliminary path planning by pre-calculating and advertising segment identifiers for key nodes before packet forwarding. The segment identifier advertisement messages are propagated in advance through the network, enabling ingress nodes to construct constrained paths without real-time computation. This preliminary action ensures key node inclusion while maintaining fast forwarding.
2Adaptability or versatility
If packet forwarding path is calculated without node constraint, then routing flexibility is improved, but network security is compromised due to bypassing key nodes
Solution Approach 1:
The patent applies local quality by associating specific properties (security requirements) with specific network nodes through segment identifiers. Key nodes are marked with special SIDs that indicate their security-critical nature. This allows different parts of the network to have different forwarding requirements - some paths must pass through security nodes while others can take optimal routes, maintaining both flexibility and security.
Solution Approach 2:
The patent introduces segment identifiers as intermediaries between the source and destination nodes. These SIDs act as mediators that encode path constraints and security requirements. Instead of direct source-destination routing, packets are routed through a sequence of SIDs that represent intermediate key nodes, ensuring security policies are enforced without compromising overall routing flexibility.
Data Source
AI summary
A method includes obtaining, by a first network node, a first segment identifier advertisement message, where the first segment identifier advertisement message includes a first segment identifier and a first flag bit, and the first segment identifier is corresponding to a second network node; determining, by the first network node, that the first flag bit indicates that a packet needs to be forwarded through the second network node; and generating, by the first network node, a first packet forwarding path, where the first packet forwarding path includes the second network node.


