Service Function Chaining via VLAN-Vsys Multi-Service Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In service function chain masquerading proxy networking, providing multiple application services increases networking costs due to the need for multiple service function forwarders to bypass service functions like firewall devices, each of which can only perform one type of service.

Innovation Solution

Deploy a switch between service function forwarders and service functions, supporting multiple virtual local area networks (VLANs) and virtual systems (Vsys) on the service function, associating different VLANs with distinct Vsys and application service policies, allowing the service function to determine and process packets based on VLAN identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple service function forwarders bypass service functions to provide different application services, then service diversity is improved, but networking costs increase

Engineering Contradiction:
Improveservice diversityVSAvoidnetworking costs
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The service function device is configured with multiple virtual local area networks (VLANs) and virtual systems (Vsys), allowing a single physical device to provide multiple different application services (such as different firewall security services) through logical segmentation. Each Vsys can be associated with different VLANs and configured with different application service policies, enabling one SF to replace multiple SFs while maintaining service diversity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The service function device is segmented into multiple virtual systems (Vsys) that are associated with different VLANs. This segmentation allows different application services to be isolated and managed independently within the same physical device, enabling multi-service capability without requiring multiple separate physical service function devices

Inventive Principle:
Principle #1Segmentation

2Reliability

If each service function provides only one type of service, then service quality is improved, but device utilization deteriorates

Engineering Contradiction:
Improveservice qualityVSAvoiddevice utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

A single service function device is designed to perform multiple application services through the configuration of multiple VLANs and Vsys. Each Vsys maintains dedicated application service policies ensuring service quality, while the physical device resources are shared across multiple services, improving overall device utilization

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a new dimension of virtualization by adding VLAN and Vsys layers above the physical hardware. This allows the service function device to operate in both physical and virtual dimensions simultaneously, maintaining service quality through logical isolation while improving resource utilization through physical consolidation

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP4697657A1Method and apparatus for implementing application service in service function chain pseudo-proxy networking
Publication Date: 2026.02.18 NEW H3C SECURITY TECH CO LTD
  • EP4697657A1 patent drawingFigure 1~3
  • EP4697657A1 patent drawingFigure 4~5
  • EP4697657A1 patent drawingFigure 6~8

AI summary

Embodiments of the present disclosure provide an application service implementation method and apparatus in service function chain masquerading proxy networking. In the embodiments, a switch is deployed between a service function forwarder (SFF) and a service function (SF), the switch and the SF are configured to support a plurality of virtual local area networks (VLANs), different VLANs supported by the SF are associated to corresponding virtual systems (Vsys) on the SF, a corresponding application service policy is configured for each of the Vsys, a VLAN identifier is carried on a packet sent by the SFF to the SF through the switch, the SF determines, based on the VLAN identifier carried in the packet, a virtual system Vsys associated with a VLAN corresponding to the VLAN identifier, and performs corresponding service processing on the packet according to an application service policy corresponding to the Vsys, so that different application services are provided on the same SF by combining multiple VLANs and Vsys on the SF, networking costs are reduced, and resource utilization of the SF is also improved.