Smart Firewall Filtering in Label-Based Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewall devices are limited in implementing policies for packets traversing specific paths through a network, as they typically rely on source, destination, and traffic class, failing to account for more complex routing requirements such as traversing particular sequences of network nodes.
Innovation Solution
A network device communicates with a path computation element to receive label sets that define specific sequences of nodes, allowing it to configure firewall policies based on these labels and perform actions on packets accordingly, enabling more sophisticated routing decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If firewall devices use traditional filtering methods based on source, destination, and traffic class, then the firewall implementation is simple, but the ability to control packets based on specific path sequences is lost
Solution Approach 1:
The patent introduces a path computation element as an intermediary that computes label sets representing specific path sequences through the network. This intermediary enables the firewall device to control packets based on node sequences without the firewall device itself needing to perform complex path computations, thus resolving the contradiction between enhanced adaptability and device complexity.
Solution Approach 2:
The patent changes the filtering parameters from traditional source/destination/traffic class to label sets that encode path sequences. By transforming the control parameters, the firewall device gains the ability to control packets based on specific node sequences while maintaining a relatively simple filtering mechanism.
2Reliability
If firewall devices implement complex path-based filtering, then packet routing control is improved, but processing overhead increases
Solution Approach 1:
The path computation element performs path computation and label set generation in advance, before packets need to be filtered. By pre-computing the label sets that represent desired path sequences, the system avoids performing complex computations in real-time during packet processing, thus improving routing control accuracy while reducing processing overhead.
Solution Approach 2:
The patent extracts the complex path computation function from the firewall device and places it in a separate path computation element. This separation allows the firewall device to focus on simple label matching operations while the complex computation is performed elsewhere, reducing processing overhead while maintaining reliable path-based filtering.
3Adaptability or versatility
If traditional firewalls are used, then device simplicity is maintained, but the ability to avoid specific network segments is lost
Solution Approach 1:
The path computation element acts as an intermediary that translates high-level path requirements (such as avoiding specific network segments) into concrete label sets. This intermediary enables the firewall device to achieve complex network segment avoidance capabilities while the configuration process remains relatively simple, as users only need to specify their path requirements rather than manually constructing label sets.
Data Source
AI summary
A network device may receive an input identifying one or more conditions associated with traversal of packets through a network and one or more actions to be performed if the one or more conditions are satisfied. The network device may transmit, to a path computation element, a request for a label set that satisfies the one or more conditions. The network device may receive the label set from the path computation element. The network device may configure a firewall policy indicating that the one or more actions are to be performed for a packet associated with a label stack that includes the label set.


