Service Chain Table for Virtual Network Packet Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network virtualization technologies do not support the insertion of service appliances into virtual networks without requiring control plane activity, and they struggle to distinguish between packets belonging to different virtual networks, limiting the use of service appliances in virtualized environments.

Innovation Solution

The solution involves designating specific virtual network identifiers (VNIDs) for endpoint devices, waypoint devices, and virtual switches, and creating a service chain table to manage packet forwarding, allowing service appliances to be inserted into virtual networks without engaging in control plane activities. This includes querying a controller for service chains based on packet destinations and VNIDs to determine the next hop and routed hop for packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service appliances are inserted as a bump in the wire in physical networks, then service functionality is provided, but this approach cannot be applied to virtual networks where multiple virtual networks share the same physical infrastructure

Engineering Contradiction:
Improveservice appliance insertion capabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the service appliance insertion mechanism by creating virtual port pairs (service port and service peer port) that allow service appliances to be inserted into specific virtual networks without affecting other virtual networks sharing the same physical infrastructure. Each virtual network gets its own isolated service insertion points.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual ports as intermediary elements between service appliances and virtual network packets. These virtual ports act as mediators that enable service appliances to intercept and process packets from specific virtual networks without requiring physical bump-in-the-wire insertion.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If control plane activity is required for service appliance insertion in overlay networks, then service chaining is enabled, but control plane overhead increases and service appliance complexity increases

Engineering Contradiction:
Improveservice chaining capabilityVSAvoidcontrol plane interaction overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs preliminary configuration by pre-establishing virtual port pairs and associating them with specific virtual networks and service appliances during network setup. This preliminary action eliminates the need for runtime control plane queries when packets need to be forwarded through service appliances.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables service appliances to be inserted and managed through data plane configurations rather than requiring continuous control plane interactions. Once configured, the service chaining paths are self-determined based on pre-established virtual port associations, reducing control plane overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10491424B2Servicing packets in a virtual network and a software-defined network (SDN)
Publication Date: 2019.11.26 KYNDRYL INC
  • US10491424B2 patent drawing
  • US10491424B2 patent drawing
  • US10491424B2 patent drawing

AI summary

In one embodiment, an apparatus includes a processor and logic integrated with and/or executable by the processor. The logic is configured to cause the processor to receive one or more packets to be switched to a next hop, the one or more packets indicating a destination address and a first virtual network identifier (VNID). The logic is also configured to cause the processor to send a query to a controller in order to determine a service chain for the one or more packets, the query including the first VNID and the destination address. Moreover, the logic is configured to cause the processor to receive a response that includes the next hop and a next routed hop for the one or more packets. Other systems, methods, and computer program products are described in accordance with more embodiments.