Switch Device Access Control via Virtual Port Grouping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network technologies, such as Fibre Channel over Ethernet (FCoE) networks, lack a mechanism for implementing zoning and access control between virtual nodes, making them complex, error-prone, and difficult to scale, especially when using central-controlling devices like Fibre Channel Forwarders (FCF) in Fibre Channel fabrics.
Innovation Solution
A switch device is configured to associate virtual ports with access groups and implement filter rules based on an access set table, allowing or prohibiting data units from being sent between virtual ports based on their access group associations, eliminating the need for a central-controlling device by using a switch module and access set table to manage access control within a Layer 2 domain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central-controlling device such as a Fibre Channel Forwarder (FCF) is used to implement zoning and access control, then access control functionality is achieved, but device complexity increases and the system becomes difficult to scale
Solution Approach 1:
The patent extracts the access control functionality from a central-controlling device and embeds it directly into the switch device. The switch device locally stores access control information in an access control table and makes forwarding decisions autonomously without requiring a central FCF, thereby eliminating the complex centralized control architecture while maintaining reliable access control.
Solution Approach 2:
The switch device performs self-service by autonomously managing access control decisions. It maintains its own access control table, evaluates destination addresses against stored access control information, and independently determines whether to forward or block data units without requiring external control signals from a central device.
2Reliability
If a central-controlling device is used for access control, then access control is implemented, but the system becomes error prone and difficult to scale
Solution Approach 1:
The patent segments the access control function by distributing it across multiple switch devices rather than concentrating it in a single central FCF. Each switch device maintains its own access control table and independently manages access control for its local connections, enabling the system to scale horizontally by adding more switch devices without increasing central control complexity.
3Ease of operation
If VN2VN protocol is used without access control mechanism, then network simplicity is maintained, but security and access control capabilities are lost
Solution Approach 1:
The patent merges access control functionality with the existing VN2VN switching protocol by integrating the access control table directly into the switch device. The switch device combines destination address evaluation with access control table lookup in a single forwarding decision process, thereby maintaining protocol simplicity while adding robust access control capabilities without requiring separate complex control protocols.
Data Source
AI summary
A switch device is configured to receive a data unit from a virtual port from a first set of virtual ports. The switch device is configured to associate an identifier of each virtual port from the first set of virtual ports with an identifier of a first access group that is associated with an access set. The switch device is configured to prohibit the data unit from being sent to a remaining virtual port from the first set of virtual ports if the data unit is addressed to that virtual port. The switch device is configured to otherwise allow the data unit to be sent to a virtual port from a second set of virtual ports associated with a second access group when the second access group is associated with the access set. The second set of virtual ports is mutually exclusive from the first set of virtual ports.


