Network Traffic Flow Propagation via TCAM Policy Lookup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic management systems struggle to efficiently propagate network traffic flows between end points based on service and priority policies, leading to suboptimal traffic handling and potential security vulnerabilities.

Innovation Solution

The system configures network elements with network-disseminated traffic management policies, using ternary content addressable memory (TCAM) to perform high-speed lookups and direct network traffic flows based on source and destination groups, service policies, and priority levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network traffic management is automated with service policies and TCAM lookups, then traffic handling efficiency and security are improved, but device complexity increases

Engineering Contradiction:
Improvetraffic handling efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a control plane as an intermediary that manages the complexity of policy configuration and dissemination. The control plane generates flow instructions based on service policies and distributes them to forwarding plane devices, allowing automated traffic management without requiring complex manual configuration at each device. This separates the complexity of policy management from the forwarding devices themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-configuring service policies and generating flow instructions before actual traffic management is needed. The control plane pre-processes policy information and creates lookup tables in TCAM memory, so that when traffic needs to be managed, the devices can simply perform fast lookups rather than making complex decisions in real-time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If service policies are disseminated to all network elements, then traffic propagation control is improved, but network overhead increases

Engineering Contradiction:
Improvepolicy enforcement reliabilityVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by allowing different network elements to have different subsets of service policies based on their specific roles and requirements. Rather than uniformly distributing all policies to all devices, the control plane selectively disseminates only the relevant policies to each network element, reducing unnecessary overhead while ensuring reliable enforcement where needed.

Inventive Principle:
Principle #3Local quality

3Device complexity

If manual network design placement is used for service devices, then system simplicity is maintained, but adaptability to changing security constraints deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity constraint adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamics by enabling service policies to be updated and reconfigured at runtime through the control plane. Service devices can be dynamically added, removed, or repositioned in the network traffic path without requiring manual reconfiguration of each device. The control plane automatically detects changes and disseminates updated flow instructions, maintaining system simplicity while achieving high adaptability to changing security requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12341628B2Method and system for propagating network traffic flows between end points based on service and priority policies
Publication Date: 2025.06.24 ARISTA NETWORKS INC
  • US12341628B2 patent drawing
  • US12341628B2 patent drawing
  • US12341628B2 patent drawing

AI summary

A method and system for propagating network traffic flows between end points based on service and priority policies. Specifically, the method and system disclosed herein entail configuring network elements with network-disseminated traffic management policies. Each traffic management policy guides the handling of a network traffic flow between origination and termination end points (i.e., source and destination hosts), which may be defined through data link layer, network layer, and/or transport layer header information, as well as group assignment information, associated with the source and destination hosts.