Network Switch Inline Tool Routing via Packet Signature Lookup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network switch devices that route packets through inline tools face limitations, including complexity and inefficiency due to the need for additional information injection into packets, which can confuse analysis and limit the number of communication endpoints.
Innovation Solution
The technology records associations between packet signatures and input network ports, allowing for proper routing through inline tools without modifying the packets, using a hardware-based address table to support high data throughput and efficiently manage lookup tables.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If additional information is injected into packets for routing through inline tools, then packet routing capability is improved, but device complexity and analysis confusion increase
Solution Approach 1:
The patent extracts the routing information from the packet content itself and places it in a separate hardware address table. The packet signature (source/destination MAC addresses) serves as the key, and the inline tool port mapping serves as the value. This separation allows routing information to be injected into packets without modifying the actual packet content, thus avoiding analysis confusion while maintaining routing capability.
Solution Approach 2:
The patent introduces a hardware-based address table as an intermediary between the packet and the routing logic. This table stores the mapping between packet signatures and inline tool ports, acting as a mediator that enables efficient routing decisions without requiring complex processing of packet contents or injection of additional routing information into the packets themselves.
2Adaptability or versatility
If additional information is injected into packets for routing through inline tools, then packet routing capability is improved, but measurement precision of packet analysis decreases
Solution Approach 1:
The routing information is extracted from the packet header fields (source and destination MAC addresses) and used to look up the appropriate inline tool port in the hardware address table. This approach uses existing packet information without adding modifications, ensuring that the original packet content remains intact and analysis precision is maintained.
3Adaptability or versatility
If traditional routing methods are used through inline tools, then packet routing is achieved, but productivity and data throughput are limited
Solution Approach 1:
The patent replaces software-based routing processing with a hardware-based address table lookup mechanism. The hardware address table is implemented in fast memory (such as TCAM or SRAM) and uses parallel lookup circuits, enabling high-speed routing decisions that can keep up with line-rate traffic. This hardware implementation eliminates the bottlenecks of software processing and significantly increases data throughput capability.
Solution Approach 2:
The routing mappings are pre-computed and stored in the hardware address table before packets arrive. When packets need routing, the system performs a direct lookup of the packet signature in the pre-populated table, rather than computing the routing path in real-time. This preliminary preparation of routing information enables extremely fast forwarding decisions and high productivity.
Data Source
AI summary
Introduced herein is a technology for a network switch device to route network packets through a inline tool, without introducing additional information to the network packets. The technology records an association between an input network port and a signature (e.g., source MAC address) of the network packet, before forwarding the packet to the inline tool. When receiving the packet back from the inline tool, the network device recognizes that the packet signature is associated with the input network port, and that the input network port is paired with a particular output network port. Thus, the network device identifies the output network port for sending the packet, without modifying contents of the packet.


