Application-Level Bandwidth Reservation via Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network configurations, such as 'best effort' networks, fail to provide reliable minimum application levels of service, leading to bandwidth hogging by certain applications that starve other applications of resources, and port-level configurations are ineffective in discriminating between applications and vulnerable to spoofing.
Innovation Solution
Implementing a system that registers and authenticates applications, allowing service level settings to be set on a per-application basis, using a receiver, parser, traffic management, and routing units to manage network traffic according to application-specific criteria, thereby ensuring reliable application levels of service while preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If port-level configuration is used to prioritize certain packets, then minimum level of service is maintained for those packets, but applications can easily spoof the network to exploit the configuration without user consent
Solution Approach 1:
The patent segments the network traffic identification from port-level to application-level by introducing application identifiers (A-IDs) in packet headers. This allows the system to identify and prioritize traffic based on specific applications rather than generic port configurations, preventing spoofing while maintaining service levels.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the network infrastructure verifies application identities using A-IDs before applying QoS policies. This intermediary layer prevents direct exploitation of port configurations by spoofed applications.
2Ease of operation
If port-level configuration is used to detect packet types, then service prioritization is achieved, but there is no way to discriminate at the application level
Solution Approach 1:
The patent adds another dimension to packet identification by incorporating application identifiers (A-IDs) into the packet header structure. This enables discrimination at the application level while maintaining the existing port-level prioritization framework, allowing both dimensions to work together.
Solution Approach 2:
The patent changes the identification parameter from port numbers alone to a combination of port numbers and application identifiers (A-IDs). This parameter enhancement allows the system to distinguish between different applications using the same port, enabling fine-grained service differentiation.
3Adaptability or versatility
If best effort protocols are used to maintain network neutrality, then compatibility with any application is achieved, but applications can hog limited bandwidth resources
Solution Approach 1:
The patent introduces dynamic bandwidth allocation based on application authentication and service level agreements. The system can adaptively adjust bandwidth distribution among authenticated applications while maintaining network neutrality for unauthenticated traffic, preventing bandwidth hogging while preserving compatibility.
Solution Approach 2:
The patent changes the bandwidth allocation parameter from uniform best-effort treatment to application-specific allocations based on authentication status and service level agreements. This allows the system to guarantee minimum bandwidth to authorized applications while maintaining overall network neutrality.
Data Source
AI summary
Methods, systems, devices, and software are disclosed for providing application levels of service over a network. Embodiments of the invention maintain a list of registered applications (or application providers) that have registered with a network resources provider. Customers of the network resources provider may authenticate some or all of the registered applications, indicating a desire to allow traffic relating to those applications over their access networks. Customers may further set application levels of service with respect to those authenticated applications. Certain embodiments may manage network traffic to accord with the application levels of service.


