Access Point Application Host Interface Bypassing Central Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In managed wide area networks, the current CAPWAP forwarding approach creates network bottlenecks and restricts applications from accessing external networks like the Internet directly, especially for applications requiring reliable transport protocols like TCP, due to the routing of all data traffic through a central controller, which increases resource usage and costs.
Innovation Solution
Establishing an application host interface at access points to bypass the central wireless local area network controller, allowing direct external network access while routing permitted application data via the external network, thereby reducing the load on the central controller and enabling TCP traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all data traffic is routed through a central controller, then network security and control are improved, but network resource utilization increases and costs increase
Solution Approach 1:
The patent segments network traffic into two paths: control traffic continues to flow through the central controller for security management, while data traffic for permitted applications is routed directly through the access point to external networks. This segmentation allows security control to be maintained for management purposes while eliminating unnecessary resource consumption for data forwarding through the controller.
Solution Approach 2:
The patent extracts data traffic handling functionality from the central controller and relocates it to the access point. By implementing a local data plane at the access point, the system removes the burden of forwarding all data traffic through the controller, reducing network resource utilization while maintaining centralized control for security policies.
2Extent of automation
If all data traffic is routed through a central controller, then centralized control is improved, but network efficiency deteriorates
Solution Approach 1:
The patent divides network functions into control plane (centralized at controller) and data plane (distributed at access points). Control plane traffic maintains centralized automation for security and policy management, while data plane traffic for permitted applications bypasses the controller for efficient direct routing, thereby improving overall network efficiency without sacrificing centralized control capabilities.
Solution Approach 2:
The patent introduces an intermediary mechanism (application host interface with permitted application list) that enables selective direct routing. This intermediary allows the system to maintain centralized control for authentication and policy enforcement while permitting efficient direct paths for approved applications, thus resolving the conflict between centralized control and network efficiency.
3Productivity
If applications require direct external network access, then network efficiency is improved, but TCP protocol support becomes unreliable
Solution Approach 1:
The patent introduces an application host interface at the access point that acts as an intermediary for permitted applications. This interface provides stateful packet inspection and connection tracking capabilities, ensuring that direct external network access maintains reliable TCP protocol support through proper connection management while still enabling efficient direct routing for approved applications.
Data Source
AI summary
Systems, methods, and computer program products to provide direct external network access at an access point (AP) in a managed wide area network (WAN). The method may include establishing an application host interface (AHI) at an access point and receiving application data from one or more client devices connected to the access point. The method may also include determining that the application data is received from a permitted application as shown in a list of applications permitted to use the AHI and routing, using the AHI, the received application data to the data destination via the external network thereby bypassing the WLC.


