IP Library Granted Patent US 10,764,177
Granted Patent B2
US 10,764,177 · App. 16/252,760 · Granted Sep 1, 2020

Efficient implementation of complex network segmentation

Inventors: Barak Gafni (Campbell, CA); Aviv Kfir (Nili, IL); Benny Koren (Zichron Yaakov, IL)
Assignee: MELLANOX TECHNOLOGIES TLV LTD.
H04L45/74H04L12/4641H04L45/34H04L47/20H04L47/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,764,177
App. No.
16/252,760
Granted
Sep 1, 2020
Kind
B2
Abstract

In one embodiment, a network device includes an interface to receive packets from sources in a network for forwarding to destinations in the network, the sources and destinations being assigned to groups, each packet including a source and destination identifier, a memory configured to store a source-group mapping table that maps source identifiers to source-groups, a destination-group mapping table that maps destination identifiers to destination-groups, and an intergroup access-control list that maps source-destination-group pairs to forwarding rules, and a single IC chip configured, for each packet, to find a source-group for the source identifier in the source-group mapping table, find a destination-group for the destination identifier in the destination-group mapping table, find a forwarding rule for a source-destination pair including the found source and destination-group in the intergroup access-control list, and forward or drop the packet according to the found forwarding rule.

Claims (26)

1. A network device comprising:

an interface configured to receive a plurality of packets from sources disposed in a network for forwarding to destinations disposed in the network, the sources and the destinations being assigned to a plurality of groups, each packet of the plurality of packets including a source identifier and a destination identifier;

a memory configured to store: a source-group mapping table that maps source identifiers to source-groups; a destination-group mapping table that maps destination identifiers to destination-groups; and an intergroup access-control list that maps source-destination-group pairs to forwarding rules; and

a single Integrated Circuit (IC) chip configured, for each packet received through the interface, to:

find a source-group for the source identifier in the source-group mapping table;

find a destination-group for the destination identifier in the destination-group mapping table;

find a forwarding rule for a source-destination pair including the found source-group and the found destination-group in the intergroup access-control list; and

forward the packet through the interface or drop the packet according to the found forwarding rule.

2. The device according to claim 1 , wherein the single IC chip is configured to manage a timing of operations so that for each packet, a first time period in which the source-group is found and a second time period in which the destination-group is found at least partially overlap.

3. The device according to claim 1 , wherein the intergroup access-control list allows bidirectional forwarding between two entities from different groups of the plurality of groups.

4. The device according to claim 1 , wherein the intergroup access-control list allows unidirectional forwarding between two entities from different groups of the plurality of groups.

5. The device according to claim 1 , wherein the network supports a multi-tenant infrastructure.

6. The device according to claim 1 , wherein the source identifier and the destination identifier are classified according to any one or more of the following: a virtual extensible local area network (VXLAN) network identifier, a media access control (MAC) address from an Ethernet header, an Internet Protocol (IP) address from an Internet Protocol version 4 header, an IP address from an Internet Protocol version 6 header, and a virtual local area network (VLAN) identify from an Ethernet header.

7. An access control method, comprising:

receiving a plurality of packets from sources disposed in a network for forwarding to destinations disposed in the network, the sources and the destinations being assigned to a plurality of groups, each packet of the plurality of packets including a source identifier and a destination identifier;

storing: a source-group mapping table that maps source identifiers to source-groups; a destination-group mapping table that maps destination identifiers to destination-groups; and an intergroup access-control list that maps source-destination-group pairs to forwarding rules; and

performing the following for each packet in a single Integrated Circuit (IC) chip:

finding a source-group for the source identifier in the source-group mapping table;

finding a destination-group for the destination identifier in the destination-group mapping table;

finding a forwarding rule for a source-destination pair including the found source-group and the found destination-group in the intergroup access-control list; and

forwarding or dropping the packet according to the found forwarding rule.

8. The method according to claim 7 , further comprising managing a timing of operations so that for each packet, a first time period in which the source-group is found and a second time period in which the destination-group is found at least partially overlap.

9. The method according to claim 7 , wherein the intergroup access-control list allows bidirectional forwarding between two entities from different groups of the plurality of groups.

10. The method according to claim 7 , wherein the intergroup access-control list allows unidirectional forwarding between two entities from different groups of the plurality of groups.

11. The method according to claim 7 , wherein the network supports a multi-tenant infrastructure.

12. The method according to claim 7 , wherein the source identifier and the destination identifier are classified according to any one or more of the following: a virtual extensible local area network (VXLAN) network identifier, a media access control (MAC) address from an Ethernet header, an Internet Protocol (IP) address from an Internet Protocol version 4 header, an IP address from an Internet Protocol version 6 header, and a virtual local area network (VLAN) identify from an Ethernet header.

Assignments (2)
MERGER Recorded Dec 15, 2021
From: MELLANOX TECHNOLOGIES TLV LTD.
To: MELLANOX TECHNOLOGIES, LTD.
Reel/Frame 058517/0564 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2019
From: GAFNI, BARAK; KFIR, AVIV; KOREN, BENNY
To: MELLANOX TECHNOLOGIES TLV LTD.
Reel/Frame 048066/0293 →
Continuity (1)
Related Publication 20200236042A1 · Jul 23, 2020