Segment Routing Path Constraint for Firewall Inclusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Segment Routing (SR) networks, it is not guaranteed that a packet forwarding path includes a specific key node, such as a firewall, which can compromise network security.

Innovation Solution

A method and system where a network node obtains a segment identifier advertisement message with a flag bit indicating that a packet needs to be forwarded through a specific node, ensuring that the packet forwarding path includes that node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If an SR network node uses shortest path first algorithm to calculate packet forwarding path, then forwarding efficiency is improved, but it cannot be ensured that packet passes through specific key node

Engineering Contradiction:
Improveforwarding efficiencyVSAvoidpath constraint satisfaction
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the forwarding path into multiple segments using segment identifiers (SIDs). Each SID represents a specific node or link segment, allowing the network to divide the end-to-end path into controllable segments. This segmentation enables the path to be constructed by concatenating specific SIDs, ensuring passage through key nodes while maintaining routing efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary path planning by pre-calculating and advertising segment identifiers for key nodes before packet forwarding. The segment identifier advertisement messages are propagated in advance through the network, enabling ingress nodes to construct constrained paths without real-time computation. This preliminary action ensures key node inclusion while maintaining fast forwarding.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If packet forwarding path is calculated without node constraint, then routing flexibility is improved, but network security is compromised due to bypassing key nodes

Engineering Contradiction:
Improverouting flexibilityVSAvoidnetwork security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by associating specific properties (security requirements) with specific network nodes through segment identifiers. Key nodes are marked with special SIDs that indicate their security-critical nature. This allows different parts of the network to have different forwarding requirements - some paths must pass through security nodes while others can take optimal routes, maintaining both flexibility and security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces segment identifiers as intermediaries between the source and destination nodes. These SIDs act as mediators that encode path constraints and security requirements. Instead of direct source-destination routing, packets are routed through a sequence of SIDs that represent intermediate key nodes, ensuring security policies are enforced without compromising overall routing flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250184262A1Method and System for Determining Packet Forwarding Path, and Network Node
Publication Date: 2025.06.05 HUAWEI TECH CO LTD
  • US20250184262A1 patent drawing
  • US20250184262A1 patent drawing
  • US20250184262A1 patent drawing

AI summary

A method includes obtaining, by a first network node, a first segment identifier advertisement message, where the first segment identifier advertisement message includes a first segment identifier and a first flag bit, and the first segment identifier is corresponding to a second network node; determining, by the first network node, that the first flag bit indicates that a packet needs to be forwarded through the second network node; and generating, by the first network node, a first packet forwarding path, where the first packet forwarding path includes the second network node.