Application Service Virtual Circuit Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual circuit provisioning methods in packet switched networks do not consider user identities or network policies, leading to inadequate security and traffic management, as they provision circuits based solely on endpoint addresses without inspecting packets or determining the type of traffic or user identity.

Innovation Solution

The method involves a network device that retrieves user profiles and network traffic policies from a database to validate traffic forwarding requests, performing deep packet inspection to determine the validity of requests based on user identities and content, and provisioning application service virtual circuits only when the requests are valid, thereby ensuring secure and policy-compliant data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automatic provisioning is performed based on network addresses without packet inspection, then provisioning speed is improved, but security is worsened

Engineering Contradiction:
Improveprovisioning speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by retrieving user profiles and network traffic policies from a database before provisioning virtual circuits. This preliminary retrieval of security criteria enables fast decision-making during the provisioning process without compromising security, as the validation rules are prepared in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual security review processes with automated electronic validation. The network device automatically retrieves user profiles, validates traffic forwarding requests against stored policies, and provisions circuits based on electronic validation results, eliminating the need for manual security checks while maintaining high security standards.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If deep packet inspection is performed to validate traffic requests, then security is improved, but processing time is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts only the essential validation information (user identity, traffic type, policy compliance) from the traffic forwarding request through packet inspection, rather than performing complete deep packet inspection of all traffic. This selective extraction of critical security attributes enables validation without excessive processing time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network device retrieves pre-stored user profiles and network traffic policies from a database to use as validation criteria. By copying and using these pre-existing policy templates rather than creating validation rules in real-time, the system accelerates the validation process while maintaining security requirements.

Inventive Principle:
Principle #26Copying

3Ease of operation

If virtual circuits are provisioned without considering user identities or network policies, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveprovisioning simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network device automatically performs validation of traffic forwarding requests by retrieving user profiles and network policies from its own database and comparing them against the request. This self-service validation mechanism eliminates the need for external manual security approval while ensuring security compliance, thereby maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where the network device validates traffic requests against stored user profiles and policies, then uses the validation results to determine whether to provision virtual circuits. This automated feedback loop ensures security requirements are met while maintaining simple operation, as the system self-regulates based on policy compliance.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3747163B1Application service virtual circuit
Publication Date: 2024.05.01 ATC TECHNOLOGIES LLC
  • EP3747163B1 patent drawingFigure 1
  • EP3747163B1 patent drawingFigure 2
  • EP3747163B1 patent drawingFigure 3

AI summary

Systems and methods for exchanging data over a network are described. One method includes receiving, from a computing device via a physical network port, a request to forward network traffic, the request including a network domain identifier and a user identifier. The method includes retrieving, from a database storing user information, a user profile based on the user identifier. The method includes determining whether the traffic forwarding request is valid based on the user profile. The method includes, when the traffic forwarding request is valid, provisioning, on the network, an application service virtual circuit between a local virtual port of a communication interface coupled to the electronic processor and a peer port at a remote communication endpoint. The method includes forwarding the network traffic from the computing device to the remote communication end point via the application service virtual circuit.