Switch Inner Packet Inspection for Tunnel Traffic Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network switches lack visibility into tunnel traffic flows, preventing them from managing and identifying flows that require additional management, such as rogue traffic, due to their inability to inspect inner packets encapsulated with headers.

Innovation Solution

A switch is designed to inspect inner packets encapsulated with headers without decapsulation, applying rules based on virtual network identifiers and storing information in a tunnel information table to facilitate selective rule management and traffic flow management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If a switch inspects inner packets encapsulated with headers without decapsulation, then visibility into tunnel traffic flows is achieved, but device complexity increases

Engineering Contradiction:
Improvevisibility into tunnel traffic flowsVSAvoidswitch complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts only the necessary information from inner packets (source/destination addresses, protocol types) without performing full decapsulation. The inner packet module selectively extracts flow identification information while leaving the encapsulation intact, thus achieving visibility without the complexity of complete decapsulation processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary inner packet module that sits between the packet processor and the rule management module. This module acts as a mediator that provides the switch with visibility into inner packet contents through selective extraction, without requiring the switch's core forwarding logic to handle decapsulation, thus managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If rules are applied selectively based on inner packet inspection, then traffic flow management capability is improved, but processing time increases

Engineering Contradiction:
Improvetraffic flow management capabilityVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies partial action by inspecting only specific fields of inner packets (source/destination addresses, protocol types) rather than performing full packet analysis. This selective inspection provides sufficient information for rule application while minimizing processing overhead and time loss.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary action by pre-processing and extracting key information from inner packets before rule matching. The inner packet module prepares flow identification data in advance, so that when rules need to be applied, the switch already has the necessary information readily available, reducing processing time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the switch learns traffic patterns within tunnels, then network security is improved, but the switch's processing load increases

Engineering Contradiction:
Improvenetwork securityVSAvoidswitch processing load
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only essential traffic pattern information (flow identifiers, packet counts, byte counts) needed for security monitoring without performing comprehensive packet analysis. This selective extraction provides security insights while keeping processing load manageable.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements self-service by having the inner packet module automatically learn and store traffic patterns in local tables (tunnel information table, flow table) without requiring external intervention or complex processing. The switch serves its own security monitoring needs through automated, lightweight information gathering and storage.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10038627B2Selective rule management based on traffic visibility in a tunnel
Publication Date: 2018.07.31 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US10038627B2 patent drawing
  • US10038627B2 patent drawing
  • US10038627B2 patent drawing

AI summary

One embodiment of the present invention provides a switch. The switch includes a storage device, a rule management module, an inner packet module, and a packet processor. During operation, the rule management module obtains a rule associated with a data flow within tunnel encapsulation of a tunnel. This rule indicates how the flow is to be processed at the switch. The rule management module then applies an initial rule to a respective line card of the switch. The initial rule is derived from a virtual network identifier, which is associated with the tunnel, of the obtained rule. The inner packet module determines that a first inner packet, which is encapsulated with a first encapsulation header, belongs to the flow without decapsulating the first encapsulation header. The rule management module applies the obtained rule to a line card associated with an ingress port of the encapsulated first inner packet.