Service Chaining via Opaque Session Cookies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying dedicated appliances or custom hardware within existing routing infrastructure for network services is expensive and time-consuming, preventing service providers from quickly deploying new services, and increases operational costs due to the need for multiple interconnected and statically configured devices with limited integration with routers or other network elements.

Innovation Solution

Implementing session-aware, stateful network services by using general-purpose computing servers to execute network services software, where packet flows are directed through service chains with tunneling and opaque session cookies to uniquely identify collections of session-specific packet flows, allowing service nodes to apply services without inspecting individual packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated appliances or custom hardware are deployed within existing routing infrastructure, then network services can be provided, but deployment cost and time increase significantly

Engineering Contradiction:
Improvenetwork service deliveryVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies universality by enabling general-purpose network elements (routers, switches, firewalls) to function as service nodes through software installation. Instead of requiring dedicated hardware appliances for each service, these universal network elements can be dynamically configured to provide multiple services including deep packet inspection, application awareness, and stateful service delivery, thereby reducing deployment time while maintaining service reliability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses copying by creating virtual instances of service functionality through software rather than physical hardware replication. Service nodes are instantiated as software components that can be rapidly deployed and replicated across existing network infrastructure, eliminating the need to physically install and configure dedicated appliances for each service instance

Inventive Principle:
Principle #26Copying

2Reliability

If multiple dedicated appliances are interconnected and statically configured, then network services are provided, but operational costs increase

Engineering Contradiction:
Improvenetwork service deliveryVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple dedicated service appliances into unified service nodes that run multiple service functions concurrently. Instead of having separate physical appliances for deep packet inspection, application awareness, and other services, these functions are combined into software-based service nodes that operate on existing network infrastructure, reducing the number of devices and simplifying operations

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables universal network elements to perform multiple service functions simultaneously. A single router or firewall can be configured to provide deep packet inspection, application awareness, and other services through software modules, eliminating the need for multiple specialized appliances and reducing operational complexity and costs

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dedicated appliances are used for network services, then services can be applied to incoming packets, but integration with routers and network elements is limited

Engineering Contradiction:
Improveservice application capabilityVSAvoidintegration capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes network elements universal by enabling them to perform both traditional routing functions and specialized service functions through software. Routers and firewalls can simultaneously handle packet forwarding and provide deep packet inspection, application awareness, and other services, creating seamless integration between core network functions and value-added services

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces service chains as intermediary structures that connect existing network elements with service functionality. Service chains act as mediators that orchestrate traffic flow through multiple service nodes, enabling flexible integration between traditional network infrastructure and new services without requiring direct hardware modifications

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If service nodes must process individual packets to identify subscriber sessions, then session-specific services can be applied, but processing burden and complexity increase

Engineering Contradiction:
Improvesession-specific service capabilityVSAvoidpacket processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing service chains and configuring service nodes with session identification information before packets arrive. Service nodes are pre-configured with session cookies and chain identifiers, so when packets arrive, the matching and service application process is simplified to basic lookup operations rather than complex packet inspection and session reconstruction

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10693770B2Service chaining within computer networks
Publication Date: 2020.06.23 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10693770B2 patent drawing
  • US10693770B2 patent drawing
  • US10693770B2 patent drawing

AI summary

Techniques are described for providing session-aware, stateful network services to subscriber packet flows. Devices within a service provider network direct subscriber packets along service chains. Each tunnel is established to direct traffic according a particular ordered set of network services for the corresponding service chain. An ingress device for the tunnels encapsulate the subscriber packets and embed opaque session cookies that each uniquely identifies a collection of packet flows of a subscriber session amongst other packet flows transported by a given service tunnel. Each service node need only identify the tunnel on which a tunnel packet was received and the session cookie embedded within the tunnel packet to uniquely associate the encapsulated subscriber packet with a subscriber session, without needing to further inspect the encapsulated subscriber packet, and to index or otherwise retrieve state and statistics required to enforce the network service the service nod is programmed to deliver.