Access Point Application Host Interface Bypassing Central Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In managed wide area networks, the current CAPWAP forwarding approach creates network bottlenecks and restricts applications from accessing external networks like the Internet directly, especially for applications requiring reliable transport protocols like TCP, due to the routing of all data traffic through a central controller, which increases resource usage and costs.

Innovation Solution

Establishing an application host interface at access points to bypass the central wireless local area network controller, allowing direct external network access while routing permitted application data via the external network, thereby reducing the load on the central controller and enabling TCP traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all data traffic is routed through a central controller, then network security and control are improved, but network resource utilization increases and costs increase

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork resource utilization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments network traffic into two paths: control traffic continues to flow through the central controller for security management, while data traffic for permitted applications is routed directly through the access point to external networks. This segmentation allows security control to be maintained for management purposes while eliminating unnecessary resource consumption for data forwarding through the controller.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts data traffic handling functionality from the central controller and relocates it to the access point. By implementing a local data plane at the access point, the system removes the burden of forwarding all data traffic through the controller, reducing network resource utilization while maintaining centralized control for security policies.

Inventive Principle:
Principle #2Taking out (Extraction)

2Extent of automation

If all data traffic is routed through a central controller, then centralized control is improved, but network efficiency deteriorates

Engineering Contradiction:
Improvecentralized controlVSAvoidnetwork efficiency
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The patent divides network functions into control plane (centralized at controller) and data plane (distributed at access points). Control plane traffic maintains centralized automation for security and policy management, while data plane traffic for permitted applications bypasses the controller for efficient direct routing, thereby improving overall network efficiency without sacrificing centralized control capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (application host interface with permitted application list) that enables selective direct routing. This intermediary allows the system to maintain centralized control for authentication and policy enforcement while permitting efficient direct paths for approved applications, thus resolving the conflict between centralized control and network efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If applications require direct external network access, then network efficiency is improved, but TCP protocol support becomes unreliable

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidTCP protocol support
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an application host interface at the access point that acts as an intermediary for permitted applications. This interface provides stateful packet inspection and connection tracking capabilities, ensuring that direct external network access maintains reliable TCP protocol support through proper connection management while still enabling efficient direct routing for approved applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11283643B2Efficient and reliable data path for hosted applications on access point
Publication Date: 2022.03.22 CISCO TECHNOLOGY INC
  • US11283643B2 patent drawing
  • US11283643B2 patent drawing
  • US11283643B2 patent drawing

AI summary

Systems, methods, and computer program products to provide direct external network access at an access point (AP) in a managed wide area network (WAN). The method may include establishing an application host interface (AHI) at an access point and receiving application data from one or more client devices connected to the access point. The method may also include determining that the application data is received from a permitted application as shown in a list of applications permitted to use the AHI and routing, using the AHI, the received application data to the data destination via the external network thereby bypassing the WLC.