VXLAN Encapsulation Offload to Spine Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data centers face challenges in securely and efficiently managing private connectivity and communication between network devices and virtual machines due to restrictive designs aimed at maintaining security and performance, which limits direct communication between network devices and virtual machines.

Innovation Solution

A method and system for VXLAN encapsulation and decapsulation that offloads these processes from leaf switches to spine switches, enabling efficient communication by generating augmented MAC frames that include ingress and egress port IDs and VXLAN network identifiers, allowing for secure and efficient routing of MAC frames across virtual extensible local area networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data centers limit or restrict private connectivity between network devices to maintain security and performance, then security and performance are improved, but communication capability between virtual machines is worsened

Engineering Contradiction:
Improvesecurity and performanceVSAvoidcommunication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces VXLAN tunneling as an intermediary mechanism that enables private communication between virtual machines while maintaining security boundaries. The VXLAN overlay network acts as a mediator that allows encrypted/tunneled communication paths through the physical network infrastructure, resolving the contradiction between security restrictions and communication needs

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new networking dimension by implementing VXLAN virtualization layers above the physical network. This creates multiple logical networking dimensions (VXLAN segments, VTEP pairs, overlay networks) that enable private communication channels without compromising the security of the underlying physical infrastructure

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If leaf switches perform VXLAN encapsulation and decapsulation, then communication functionality is provided, but processing overhead and performance are worsened

Engineering Contradiction:
Improvecommunication functionalityVSAvoidprocessing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the computationally intensive VXLAN encapsulation and decapsulation functions from leaf switches and relocates them to spine switches. This extraction removes the processing burden from leaf switches, improving their forwarding performance while maintaining VXLAN communication capabilities through the spine switches

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If more network devices are added to data centers, then communication capacity is improved, but security management complexity and performance restrictions are worsened

Engineering Contradiction:
Improvecommunication capacityVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal VXLAN tunneling framework that provides standardized security and communication capabilities across all network devices in the data center. This multi-functional approach allows the same VXLAN mechanism to handle security, routing, and communication tasks across diverse network devices, reducing management complexity despite increased device count

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9866409B2Method and system for VXLAN encapsulation offload
Publication Date: 2018.01.09 ARISTA NETWORKS INC
  • US9866409B2 patent drawing
  • US9866409B2 patent drawing
  • US9866409B2 patent drawing

AI summary

A method for virtual extensible local area network (VXLAN) encapsulation. The method includes receiving a first augmented MAC frame on a first ingress port of a first network device, where the first augmented MAC frame includes a first egress port ID (EPID), a first ingress port ID (IPID), and a first MAC frame. The method further includes identifying a first destination VXLAN tunnel endpoint (VTEP) internet protocol (IP) address based on the first EPID, where the first destination VTEP IP address is associated with a first destination VTEP. The method further includes identifying a source VTEP IP address based on the first IPID, performing VXLAN encapsulation of the first MAC frame to obtain a VXLAN frame, and sending the VXLAN frame to the first destination VTEP via a first egress port of the first network device.