Spoofed DNS Entries for Inter-Cloud Service Chains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices lack the hardware capacity to implement service chains for inter-cloud traffic due to the large number of IP addresses involved, exceeding the limitations of hardware resources such as TCAM capacity.

Innovation Solution

A system that reduces the number of IP addresses needed for programming service chains by creating IP-to-domain mappings and using spoofed DNS entries to map cloud domains to a smaller set of IP addresses, allowing service chains to be programmed on network devices despite limited hardware capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If service chains are programmed for each IP address allocated to cloud providers, then service chain functionality is comprehensive, but hardware capacity is exceeded

Engineering Contradiction:
Improveservice chain coverageVSAvoidnumber of IP addresses
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent uses spoofed DNS entries to create virtual copies of cloud domain IP addresses. Instead of programming service chains for all actual IP addresses, the system creates a reduced set of spoofed entries that map to the same physical appliances. This allows the hardware to store fewer entries while still providing comprehensive service chain functionality for all cloud providers.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent extracts only the essential information needed for service chain routing from the full IP address space. By using domain names and spoofed DNS entries instead of complete IP address lists, the system extracts and stores only the necessary mapping information, reducing the quantity of data that must be stored in hardware while maintaining routing accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If service chains are programmed for all origin and destination cloud IPs, then inter-cloud traffic routing is complete, but TCAM capacity is insufficient

Engineering Contradiction:
Improveinter-cloud traffic supportVSAvoidhardware capacity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces spoofed DNS entries as an intermediary layer between the service chain programming system and the actual cloud IP addresses. This intermediary reduces the direct mapping complexity by providing a condensed representation of cloud destinations that can be stored in limited hardware capacity while still enabling complete inter-cloud traffic routing functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from a flat IP address-based addressing scheme to a domain name-based hierarchical structure. By using domain names as intermediaries and creating spoofed DNS entries that map domain names to appliance addresses, the system adds a dimensional layer that reduces the direct hardware storage requirements while maintaining comprehensive routing capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Quantity of substance

If the number of service chain entries is reduced, then hardware capacity is respected, but routing precision may be compromised

Engineering Contradiction:
Improvenumber of entriesVSAvoidrouting accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent creates spoofed DNS entries that are virtual copies of actual cloud IP addresses. These spoofed entries maintain the necessary routing precision by preserving the mapping relationship between domain names and physical appliances, while using fewer entries overall to reduce hardware requirements.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent makes the spoofed DNS entries universal by having them serve multiple purposes: they provide service chain routing information, enable traffic identification, and maintain mapping to physical appliances. This multi-functionality ensures that reduced entry counts do not compromise routing precision, as each entry serves multiple critical functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11799821B2Service chains for inter-cloud traffic
Publication Date: 2023.10.24 CISCO TECHNOLOGY INC
  • US11799821B2 patent drawing
  • US11799821B2 patent drawing
  • US11799821B2 patent drawing

AI summary

Systems, methods, and computer-readable media for creating service chains for inter-cloud traffic. In some examples, a system receives domain name system (DNS) queries associated with cloud domains and collects DNS information associated the cloud domains. The system spoofs DNS entries defining a subset of IPs for each cloud domain. Based on the spoofed DNS entries, the system creates IP-to-domain mappings associating each cloud domain with a respective IP from the subset of IPs. Based on the IP-to-domain mappings, the system programs different service chains for traffic between a private network and respective cloud domains. The system routes, through the respective service chain, traffic having a source associated with the private network and a destination matching the IP in the respective IP-to-domain mapping.