Service Chain Domain Interworking via Border Packet Conversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing service chain technologies fail to support seamless interworking between different domains managed by various service providers, limiting the ability to provide dynamically adaptable and personalized security services in network environments transformed by NFV, SDN, and SFC.
Innovation Solution
The implementation of a communication method and device for interworking between service function chain domains, which includes the conversion of a first packet into a second packet with interworking information, and the transmission and conversion of packets between logic nodes in different domains to facilitate interworking between service function chains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If service chains are deployed in different domains managed by various service providers, then service coverage and versatility are improved, but interworking capability and seamless integration between domains deteriorate
Solution Approach 1:
The patent introduces a domain border node as an intermediary entity between different service chain domains. This border node performs packet conversion functions, translating packets from the first domain's format to the second domain's format, enabling seamless interworking while maintaining domain independence. The border node acts as a mediator that resolves the interworking capability issue without compromising service coverage across multiple domains.
Solution Approach 2:
The patent implements parameter changes by modifying packet structures at domain borders. Specifically, service path identifiers, flow identifiers, and metadata parameters are transformed when packets cross domain boundaries. This parameter transformation enables compatibility between different domain protocols while maintaining the ability to support diverse service chains across multiple domains.
2Stability of the object's composition
If traditional security facilities are deployed at fixed locations based on hardware middleware, then device stability is improved, but flexibility and adaptability to dynamic security requirements deteriorate
Solution Approach 1:
The patent implements dynamics by enabling service chains to be dynamically instantiated, configured, and modified across different domains. Service function chains can be programmatically deployed and reconfigured based on changing security requirements, while the underlying infrastructure maintains stability through standardized domain border nodes that handle the dynamic changes.
Solution Approach 2:
The patent applies universality by creating a multi-functional service chain architecture that can accommodate various security services (firewall, intrusion detection, deep packet inspection) within a unified domain interworking framework. The domain border nodes provide universal packet conversion capabilities that work across different security service types, enabling flexible deployment while maintaining system stability.
3Adaptability or versatility
If service chains are extended across multiple administrative domains, then service versatility is improved, but packet conversion complexity and device complexity increase
Solution Approach 1:
The patent applies segmentation by dividing the packet conversion function into discrete domain border nodes positioned at specific domain boundaries. Each border node handles conversion for its adjacent domains independently, breaking down the overall conversion complexity into manageable segments. This segmentation allows service versatility across multiple domains while keeping individual conversion operations simple and modular.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Embodiments of the present disclosure relate to method and device for interworking between service function chain (i.e., service chain) domains. In some embodiments, there is provided a communication method comprising: receiving, at a first logic node of a first service chain in a first domain, a first packet associated with a second service chain in a second domain; converting the first packet into a second packet comprising first interworking information between the first service chain and the second service chain, the first interworking information comprising a flag indicating that the second packet is an interworking packet, an address of the first logic node, a first flow identifier of the second packet, a first service path identifier of the second packet and metadata associated with the second service chain; transmitting the second packet to a second logic node in the second domain; and receiving from the second logic node a response to the metadata.