Programmable Application Cache for Local Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized application of policy rules across multiple geographic locations in a network leads to increased latency, user experience degradation, and network resource bottlenecks due to the need for packets to be transmitted through a central network device before reaching the application platform.
Innovation Solution
A network device capable of receiving packets, identifying their destination, determining associated applications, and applying policy rules without inspecting the payload, allowing direct transmission to the application platform, thereby bypassing intermediate network devices and reducing latency and resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packets are transmitted through a central network device for centralized policy rule application, then policy control is improved, but latency increases and network resources are consumed
Solution Approach 1:
The patent enables local network devices at different geographic locations to independently determine and apply policy rules locally, rather than requiring all packets to travel to a central network device. This localizes the policy decision-making function, reducing the distance packets must travel and eliminating the latency associated with centralized processing while maintaining consistent policy control across the enterprise network.
2Adaptability or versatility
If packets are routed through intermediate network devices, then centralized management is achieved, but network resource usage increases
Solution Approach 1:
The patent implements preliminary action by having network devices pre-determine policy rules and application information in advance using application cache data before packets arrive. This allows the network device to immediately apply the predetermined policy rule when a packet arrives, eliminating the need for real-time centralized processing and reducing network resource consumption during packet transmission.
3Measurement precision
If deep packet inspection is performed to identify applications, then accurate policy application is achieved, but processing overhead increases
Solution Approach 1:
The patent uses application cache that stores pre-collected information about applications and their associated policy rules. When a packet arrives, the network device queries this cache to quickly identify the application and retrieve the corresponding policy rule, avoiding the need for time-consuming deep packet inspection while maintaining accurate application identification and policy application.
Data Source
AI summary
A network device receives a packet from a client device, and identifies, based on receiving the packet, a destination of the packet. The network device determines, based on information included in an application cache, an application associated with the destination of the packet, where the first network device, the client device, and the application cache are included in a first local network. The network device determines, based on the information included in the application cache, a policy rule associated with the application, and applies the policy rule to the packet.


