Administrative Delegation for Network Traffic Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices outside an administrative domain have limited control over traffic they receive, leading to issues during denial of service attacks where they continue to send data, overwhelming downstream devices and causing service loss.

Innovation Solution

The administrative delegation system allows downstream network devices to request and receive partial administrative control from upstream devices, enabling capabilities such as rate-limiting, traffic inspection, and load-balancing across administrative domains through a shared trust model and secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If upstream network devices send traffic freely across administrative domains, then network connectivity and data flow are maintained, but downstream network devices become vulnerable to overload and loss of service control

Engineering Contradiction:
Improveservice continuityVSAvoidtraffic overload
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a traffic parameter delegation mechanism as an intermediary layer between upstream and downstream network devices. The downstream device's traffic parameters (rate limits, filters, priorities) are transmitted to and enforced by the upstream device, which acts as a mediator to control traffic before it reaches the downstream device. This resolves the contradiction by maintaining free connectivity while preventing harmful overload through parameter-based control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by having the downstream network device pre-configure and communicate its desired traffic parameters to the upstream device before traffic flows occur. The upstream device then applies these parameters in advance to filter, rate-limit, or prioritize traffic, preventing overload before it occurs rather than reacting after the fact.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If downstream network devices have full control over upstream traffic, then traffic management and attack mitigation are improved, but administrative domain boundaries and device autonomy are compromised

Engineering Contradiction:
Improvetraffic control capabilityVSAvoidadministrative control structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments administrative control by allowing downstream devices to have control authority over specific traffic parameters (rate limits, filters, priorities) while the upstream device retains control over other aspects (device configuration, physical connectivity). This segmentation enables granular traffic control without requiring complete administrative control, resolving the contradiction between ease of operation and device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements local quality by allowing each downstream network device to define its own specific traffic parameters and policies tailored to its local needs and threat profiles. Each device can customize its traffic control requirements without imposing a uniform complex control structure across the entire administrative domain, enabling localized optimization while maintaining overall system simplicity.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If network devices operate autonomously within their administrative domains, then device independence and simplicity are maintained, but coordination and control across domains are insufficient

Engineering Contradiction:
Improvecross-domain control flexibilityVSAvoidcontrol mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal traffic parameter delegation protocol that can be applied across different administrative domains and device types (routers, switches, firewalls). The same mechanism handles various traffic control needs (rate limiting, filtering, prioritization) uniformly, providing cross-domain control flexibility without requiring domain-specific complex control mechanisms for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9692678B2Method and system for delegating administrative control across domains
Publication Date: 2017.06.27 CISCO TECHNOLOGY INC
  • US9692678B2 patent drawing
  • US9692678B2 patent drawing
  • US9692678B2 patent drawing

AI summary

In one embodiment, a method for delegating partial administrative controls across one or more administrative domains is provided. An upstream network device may advertise capabilities for controlling certain administrative functions to a downstream network device. The downstream network device may choose to act on one or more capabilities, allowing for partial administrative control across the administrative domain.