Wireless Access Point Application Traffic Local Breakout
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless access points in computer networks tunnel all application traffic to a gateway device, increasing the load on the enterprise network, especially for bandwidth-intensive applications, and are unable to distinguish between different types of application traffic for optimal path selection.
Innovation Solution
Implementing an application server address cache in wireless access points to identify and classify application traffic, allowing for configuration of packet flows to either tunnel or break out locally based on application-specific policies, reducing the need for unnecessary communication sessions and optimizing network paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all application traffic is tunneled to the gateway device, then network security and centralized control are maintained, but the load on the enterprise network increases and bandwidth-intensive applications cause congestion
Solution Approach 1:
The patent segments application traffic into different categories using application identification. Bandwidth-intensive applications (video streaming, file transfers) are separated from other traffic types and routed through local breakout paths, while non-bandwidth-intensive traffic continues through the tunnel to the gateway device. This segmentation allows critical security functions to remain centralized while enabling high-performance local routing for specific application types.
Solution Approach 2:
The patent applies different routing qualities to different application traffic types. Instead of a uniform tunneling approach, bandwidth-intensive applications receive local breakout path treatment with direct local network access, while other applications maintain centralized gateway routing. This local quality differentiation optimizes throughput for specific applications without compromising overall network security architecture.
2Productivity
If application-specific path selection is implemented, then network performance is optimized, but device complexity increases due to application identification and classification requirements
Solution Approach 1:
The patent introduces an application identification module as an intermediary component within the access point. This module inspects application traffic, identifies application types, and provides classification information to the packet flow configuration module. By using this intermediary, the access point achieves sophisticated application-based routing without requiring complex integrated functionality across all system components.
Solution Approach 2:
The patent performs application identification and classification in advance before final routing decisions are made. The application identification module proactively analyzes traffic patterns and classifies applications, storing this information for subsequent routing decisions. This preliminary action allows the system to make efficient routing choices without performing complex analysis in real-time during packet forwarding.
3Productivity
If bandwidth-intensive applications use local breakout path, then network load is reduced, but ability to monitor and control all traffic through gateway is diminished
Solution Approach 1:
The patent implements feedback mechanisms where the access point continues to receive and process application identification information for local breakout traffic. This feedback loop allows the system to maintain awareness of traffic patterns, application types, and network conditions, enabling informed routing decisions while preserving the ability to monitor and control traffic even when using local breakout paths.
Data Source
AI summary
A wireless access point comprises a memory; and one or more processors operably coupled to the memory configured to: receive a first packet for an application; configure an initial packet flow for the application including a first forwarding action to send traffic for the application via a tunnel path; learn the application of the first packet; generate, based on a policy of the application, an entry in an application server address cache specifying an address of the application server and a second forwarding action to send traffic for the application via a local breakout path; receive a second packet for the application; and configure, in response to determining that a destination address of the second packet matches the entry in the application server address cache, a subsequent packet flow for the application including the second forwarding action to send traffic for the application via the local breakout path.


