Programmable Application Cache for Local Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized application of policy rules across multiple geographic locations in a network leads to increased latency, user experience degradation, and network resource bottlenecks due to the need for packets to be transmitted through a central network device before reaching the application platform.

Innovation Solution

A network device capable of receiving packets, identifying their destination, determining associated applications, and applying policy rules without inspecting the payload, allowing direct transmission to the application platform, thereby bypassing intermediate network devices and reducing latency and resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packets are transmitted through a central network device for centralized policy rule application, then policy control is improved, but latency increases and network resources are consumed

Engineering Contradiction:
Improvepolicy controlVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables local network devices at different geographic locations to independently determine and apply policy rules locally, rather than requiring all packets to travel to a central network device. This localizes the policy decision-making function, reducing the distance packets must travel and eliminating the latency associated with centralized processing while maintaining consistent policy control across the enterprise network.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If packets are routed through intermediate network devices, then centralized management is achieved, but network resource usage increases

Engineering Contradiction:
Improvecentralized managementVSAvoidnetwork resource usage
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by having network devices pre-determine policy rules and application information in advance using application cache data before packets arrive. This allows the network device to immediately apply the predetermined policy rule when a packet arrives, eliminating the need for real-time centralized processing and reducing network resource consumption during packet transmission.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If deep packet inspection is performed to identify applications, then accurate policy application is achieved, but processing overhead increases

Engineering Contradiction:
Improveapplication identification accuracyVSAvoidpacket processing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent uses application cache that stores pre-collected information about applications and their associated policy rules. When a packet arrives, the network device queries this cache to quickly identify the application and retrieve the corresponding policy rule, avoiding the need for time-consuming deep packet inspection while maintaining accurate application identification and policy application.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11032389B1Applying application-based policy rules using a programmable application cache
Publication Date: 2021.06.08 JUNIPER NETWORKS INC
  • US11032389B1 patent drawing
  • US11032389B1 patent drawing
  • US11032389B1 patent drawing

AI summary

A network device receives a packet from a client device, and identifies, based on receiving the packet, a destination of the packet. The network device determines, based on information included in an application cache, an application associated with the destination of the packet, where the first network device, the client device, and the application cache are included in a first local network. The network device determines, based on the information included in the application cache, a policy rule associated with the application, and applies the policy rule to the packet.