Application Service Virtual Circuit Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtual circuit provisioning methods in packet switched networks do not consider user identities or network policies, leading to inadequate security and traffic management, as they provision circuits based solely on endpoint addresses without inspecting packets or determining the type of traffic or user identity.
Innovation Solution
The method involves a network device that retrieves user profiles and network traffic policies from a database to validate traffic forwarding requests, performing deep packet inspection to determine the validity of requests based on user identities and content, and provisioning application service virtual circuits only when the requests are valid, thereby ensuring secure and policy-compliant data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automatic provisioning is performed based on network addresses without packet inspection, then provisioning speed is improved, but security is worsened
Solution Approach 1:
The system performs preliminary actions by retrieving user profiles and network traffic policies from a database before provisioning virtual circuits. This preliminary retrieval of security criteria enables fast decision-making during the provisioning process without compromising security, as the validation rules are prepared in advance.
Solution Approach 2:
The patent replaces manual security review processes with automated electronic validation. The network device automatically retrieves user profiles, validates traffic forwarding requests against stored policies, and provisions circuits based on electronic validation results, eliminating the need for manual security checks while maintaining high security standards.
2Reliability
If deep packet inspection is performed to validate traffic requests, then security is improved, but processing time is worsened
Solution Approach 1:
The system extracts only the essential validation information (user identity, traffic type, policy compliance) from the traffic forwarding request through packet inspection, rather than performing complete deep packet inspection of all traffic. This selective extraction of critical security attributes enables validation without excessive processing time.
Solution Approach 2:
The network device retrieves pre-stored user profiles and network traffic policies from a database to use as validation criteria. By copying and using these pre-existing policy templates rather than creating validation rules in real-time, the system accelerates the validation process while maintaining security requirements.
3Ease of operation
If virtual circuits are provisioned without considering user identities or network policies, then ease of operation is improved, but security is worsened
Solution Approach 1:
The network device automatically performs validation of traffic forwarding requests by retrieving user profiles and network policies from its own database and comparing them against the request. This self-service validation mechanism eliminates the need for external manual security approval while ensuring security compliance, thereby maintaining ease of operation.
Solution Approach 2:
The system implements a feedback mechanism where the network device validates traffic requests against stored user profiles and policies, then uses the validation results to determine whether to provision virtual circuits. This automated feedback loop ensures security requirements are met while maintaining simple operation, as the system self-regulates based on policy compliance.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for exchanging data over a network are described. One method includes receiving, from a computing device via a physical network port, a request to forward network traffic, the request including a network domain identifier and a user identifier. The method includes retrieving, from a database storing user information, a user profile based on the user identifier. The method includes determining whether the traffic forwarding request is valid based on the user profile. The method includes, when the traffic forwarding request is valid, provisioning, on the network, an application service virtual circuit between a local virtual port of a communication interface coupled to the electronic processor and a peer port at a remote communication endpoint. The method includes forwarding the network traffic from the computing device to the remote communication end point via the application service virtual circuit.