Source Edge Node Policy Application via Packet Encapsulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized networks, applying policies closer to the source of data traffic is challenging due to the lack of relevant information about destination devices, leading to potential dropped packets and inefficient use of network resources, especially in unidirectional data traffic scenarios where no reciprocal data flow occurs.

Innovation Solution

The method involves encapsulating packets with an indication of incomplete policy at the source edge node and sending them to the destination edge node, which then provides the necessary policy, allowing the source edge node to apply it to subsequent packets, thereby conserving network resources and improving performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policy is applied at the destination node, then policy enforcement is simplified, but network resources are wasted and packets are dropped due to lack of source information

Engineering Contradiction:
Improvepacket delivery reliabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent inverts the traditional policy application location by moving from destination-based enforcement to source-based enforcement. The source node now applies policies before packets enter the network, using encapsulation to carry policy information. This resolves the contradiction by preventing resource waste before it occurs while maintaining reliable packet delivery through proactive policy application at the source.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent applies policies in advance at the source node before packets are transmitted into the network. By encapsulating packets with policy information at the source, the system performs preliminary action that prevents unnecessary network resource consumption and packet drops, while ensuring policies are enforced before destination processing.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If policy is applied at the source node, then network resources are conserved, but policy application becomes more complex due to lack of destination information

Engineering Contradiction:
Improvenetwork throughput efficiencyVSAvoidpolicy application complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces encapsulation as an intermediary mechanism that carries policy information from the source node to the destination node. This encapsulation layer acts as a mediator that enables the source node to apply policies without having direct knowledge of destination details, thus maintaining high network efficiency while managing the complexity through a standardized intermediary structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent embeds policy information within the packet structure through encapsulation, creating a nested structure where policy data is contained within the packet header. This nesting approach allows the source node to apply policies using available information while the encapsulated structure preserves necessary context for destination processing, balancing complexity with functionality.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Adaptability or versatility

If traditional physical ToR switches are used, then network architecture is simple, but virtualized networks introduce greater latency and resource constraints

Engineering Contradiction:
Improvenetwork architecture flexibilityVSAvoiddata traffic latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent replaces traditional physical ToR switch mechanisms with a virtualized policy application approach. Instead of relying on physical hardware for policy enforcement, the system uses software-based encapsulation and processing at the source node. This substitution enables greater network architecture flexibility and adaptability to virtualized environments while reducing the latency and resource constraints associated with physical hardware limitations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11438263B2Policy application
Publication Date: 2022.09.06 CISCO TECHNOLOGY INC
  • US11438263B2 patent drawing
  • US11438263B2 patent drawing
  • US11438263B2 patent drawing

AI summary

This disclosure describes techniques for applying a policy proximate to a source of data traffic in a network. The techniques include indicating to a destination edge node that a policy relevant to the data traffic has not been applied at a source edge node. The destination edge node may send the policy to the source edge node. The source edge node may apply the policy to a subsequent packet of the data traffic. Application of the policy proximate to the source of the data traffic may conserve network resources and improve performance of the network.