Tunnel Encapsulation Header for Application Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In tunnel encapsulated traffic, underlay nodes such as switches and routers lose visibility into application traffic, making application-specific processing, analytics, and policy control difficult without expensive deep packet inspection, which requires hardware upgrades and increased processing time.

Innovation Solution

Appending an encapsulation header with an application identification field to data units, allowing forwarding nodes to identify and prioritize applications without deep packet inspection, using application-specific MAC addresses to enable end-to-end application tracking and analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is performed on every node in the path to identify applications, then application identification accuracy is improved, but processing time increases and hardware upgrades are required

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The application identification information is inserted into the encapsulation header at the source end (virtual switch or host) before the traffic enters the underlay network. This preliminary action allows underlay nodes to identify applications without performing deep packet inspection, thereby avoiding increased processing time and hardware upgrade requirements while maintaining accurate application identification.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If deep packet inspection is performed on every node in the path to identify applications, then application identification accuracy is improved, but device complexity and cost increase due to hardware upgrades

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidhardware complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The application identification function is extracted from the underlay nodes and relocated to the overlay control plane (virtual switch or host). The underlay nodes only need to forward packets based on the application identification information already present in the encapsulation header, eliminating the need for complex deep packet inspection hardware while maintaining accurate application identification.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of manufacture

If application identification is implemented in underlay nodes without encapsulation header modification, then existing hardware can be used, but underlay nodes cannot identify applications inside tunnels

Engineering Contradiction:
Improvehardware compatibilityVSAvoidapplication visibility
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The encapsulation header serves as an intermediary structure that carries application identification information from the overlay network through the underlay network. By modifying the encapsulation header to include application identification fields, underlay nodes gain visibility into applications without requiring changes to their core forwarding hardware, thus maintaining hardware compatibility while enabling application identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11522795B1End to end application identification and analytics of tunnel encapsulated traffic in the underlay
Publication Date: 2022.12.06 JUNIPER NETWORKS INC
  • US11522795B1 patent drawing
  • US11522795B1 patent drawing
  • US11522795B1 patent drawing

AI summary

In some embodiments a method includes receiving, at a first network device, a data unit to be sent to second network device via a tunnel, the data unit associated with an application. The method includes appending, to the data unit, an encapsulation header that includes a first portion configured such that the second network device is configured to forward the data unit based on the second portion of the encapsulation header that is configured to identify the application. The method includes sending, from the first network device to the second network device via a first portion of the tunnel, the data unit such that the second network device appends the encapsulation header to the data unit prior to forwarding the data unit via a second portion of the tunnel.