Switch Device Access Control via Virtual Port Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network technologies, such as Fibre Channel over Ethernet (FCoE) networks, lack a mechanism for implementing zoning and access control between virtual nodes, making them complex, error-prone, and difficult to scale, especially when using central-controlling devices like Fibre Channel Forwarders (FCF) in Fibre Channel fabrics.

Innovation Solution

A switch device is configured to associate virtual ports with access groups and implement filter rules based on an access set table, allowing or prohibiting data units from being sent between virtual ports based on their access group associations, eliminating the need for a central-controlling device by using a switch module and access set table to manage access control within a Layer 2 domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central-controlling device such as a Fibre Channel Forwarder (FCF) is used to implement zoning and access control, then access control functionality is achieved, but device complexity increases and the system becomes difficult to scale

Engineering Contradiction:
Improveaccess control functionalityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the access control functionality from a central-controlling device and embeds it directly into the switch device. The switch device locally stores access control information in an access control table and makes forwarding decisions autonomously without requiring a central FCF, thereby eliminating the complex centralized control architecture while maintaining reliable access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The switch device performs self-service by autonomously managing access control decisions. It maintains its own access control table, evaluates destination addresses against stored access control information, and independently determines whether to forward or block data units without requiring external control signals from a central device.

Inventive Principle:
Principle #25Self-service

2Reliability

If a central-controlling device is used for access control, then access control is implemented, but the system becomes error prone and difficult to scale

Engineering Contradiction:
Improveaccess control implementationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the access control function by distributing it across multiple switch devices rather than concentrating it in a single central FCF. Each switch device maintains its own access control table and independently manages access control for its local connections, enabling the system to scale horizontally by adding more switch devices without increasing central control complexity.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If VN2VN protocol is used without access control mechanism, then network simplicity is maintained, but security and access control capabilities are lost

Engineering Contradiction:
Improvenetwork simplicityVSAvoidaccess control capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges access control functionality with the existing VN2VN switching protocol by integrating the access control table directly into the switch device. The switch device combines destination address evaluation with access control table lookup in a single forwarding decision process, thereby maintaining protocol simplicity while adding robust access control capabilities without requiring separate complex control protocols.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8804708B1Methods and apparatus for implementing access control at a network switch
Publication Date: 2014.08.12 JUNIPER NETWORKS INC
  • US8804708B1 patent drawing
  • US8804708B1 patent drawing
  • US8804708B1 patent drawing

AI summary

A switch device is configured to receive a data unit from a virtual port from a first set of virtual ports. The switch device is configured to associate an identifier of each virtual port from the first set of virtual ports with an identifier of a first access group that is associated with an access set. The switch device is configured to prohibit the data unit from being sent to a remaining virtual port from the first set of virtual ports if the data unit is addressed to that virtual port. The switch device is configured to otherwise allow the data unit to be sent to a virtual port from a second set of virtual ports associated with a second access group when the second access group is associated with the access set. The second set of virtual ports is mutually exclusive from the first set of virtual ports.