Application Access Control Using Egress Gateways for SD-WAN Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software defined networking (SD-WAN), the limited number of routing configuration strategies leads to erroneous traffic scheduling across regions, resulting in prolonged access latency for business applications accessing resources in different geographical areas.

Innovation Solution

An application access control method that utilizes pre-configured application information and egress gateway data to direct traffic to the correct region, reducing erroneous routing by using target access identifications and egress gateway information to optimize traffic scheduling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If traditional routing configuration strategies are used in SD-WAN, then the network configuration is simple, but the access latency increases due to erroneous traffic scheduling across regions

Engineering Contradiction:
Improveaccess latencyVSAvoidrouting configuration complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring application information and egress gateway information before traffic needs to be routed. The system queries and obtains target application information and target egress gateway information in advance, so that when traffic scheduling occurs, the correct routing path is already determined, avoiding erroneous routing and reducing access latency without requiring complex real-time routing decisions

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where a controller or server acts as a mediator between the terminal device and the routing decision. The controller queries application configuration information, determines the correct egress gateway, and provides routing instructions to the terminal device. This intermediary approach simplifies the terminal device's routing logic while ensuring correct traffic scheduling across regions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If limited routing configuration strategies are used, then the system is easier to implement, but traffic scheduling becomes erroneous and access latency increases

Engineering Contradiction:
Improvetraffic scheduling accuracyVSAvoidrouting strategy coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies parameter changes by dynamically selecting egress gateway information based on query results from application configuration information. Instead of using fixed routing strategies, the system changes routing parameters (egress gateway selection) according to the specific application and region requirements, enabling accurate traffic scheduling for various scenarios while maintaining ease of implementation through automated parameter determination

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If cross-region access is enabled, then application accessibility improves, but access latency increases due to detours through other regions

Engineering Contradiction:
Improvecross-region access capabilityVSAvoidaccess latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies local quality by determining the optimal egress gateway based on the specific application and the user's location. Instead of using a uniform routing strategy for all cross-region access, the system selects routing parameters tailored to each specific access scenario, directing traffic through the most appropriate regional gateway to minimize detours and reduce latency while maintaining broad cross-region access capability

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4668692A1Application access control method and apparatus, device, storage medium, and program product
Publication Date: 2025.12.24 BEIJING VOLCANO ENGINE TECH CO LTD
  • EP4668692A1 patent drawingFigure 1
  • EP4668692A1 patent drawingFigure 2~3
  • EP4668692A1 patent drawingFigure 4~5

AI summary

The present disclosure provides an application access control method and apparatus, a device, a storage medium, and a program product. The method includes: obtaining application configuration information, where the application configuration information includes preset application information, and preset access identifications and egress gateway information corresponding to the preset application information; obtaining, in response to a connection request from a client of a security management application, a target access identification of the client; querying, based on the target access identification, corresponding target application information and target egress gateway information corresponding to the target application information from the application configuration information; and feeding the target application information and the target egress gateway information back to the client, to cause the client to perform access control on a first business application on a target terminal device based on the target application information and the target egress gateway information.