Bi-Planar Network Traffic Redirection for Security and QoS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IP networks face challenges in managing security threats, maintaining quality of service, and controlling diverse traffic types, leading to increased network downtime and costs, as they were not designed to handle mission-critical applications like voice and video alongside data traffic, and lack effective access, attack, and application control mechanisms.

Innovation Solution

The implementation of a bi-planar network architecture that separates the connectivity plane for network connectivity functions from a control plane for network access, attack, and application control, allowing the control plane to register with and redirect traffic from the connectivity plane using protocols like SNMP, enabling advanced traffic management and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple control functions (firewalls, intrusion detection, bandwidth control) are added to IP networks, then network security and control capabilities are improved, but device complexity and difficulty of management increase

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments control functions into independent virtual appliances (firewall, intrusion detection, bandwidth control) that operate as separate entities in the network. Each appliance handles specific control tasks, allowing the network to benefit from comprehensive security and control capabilities while maintaining modularity. This segmentation reduces overall system complexity by dividing monolithic control functions into manageable, independent components that can be deployed and managed separately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal control plane architecture that can perform multiple control functions through a single infrastructure. The virtual appliance framework allows diverse control functions (firewall, intrusion detection, bandwidth control) to be delivered through a common platform, reducing the need for multiple separate hardware devices and simplifying network management while maintaining comprehensive security and control capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If data, voice, and video traffic are combined on a single IP network, then network versatility is improved, but quality of service and application performance deteriorate

Engineering Contradiction:
Improvenetwork versatilityVSAvoidquality of service
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network traffic into different virtual networks or virtual private networks (VPNs) based on traffic type and QoS requirements. Data, voice, and video traffic can be combined on the same physical infrastructure while being logically separated into distinct virtual networks. Each virtual network can enforce specific QoS policies, ensuring that time-sensitive traffic like voice and video receives appropriate prioritization and resource allocation, thereby maintaining service quality while achieving network versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality control by allowing different QoS characteristics and policies to be applied to different virtual networks or traffic flows within the same physical network infrastructure. Each virtual network can be customized with specific bandwidth guarantees, latency requirements, and priority levels appropriate to its traffic type, enabling the network to simultaneously support diverse applications with varying quality requirements.

Inventive Principle:
Principle #3Local quality

3Device complexity

If conventional connectivity networks are used for mission-critical applications, then infrastructure simplicity is maintained, but network reliability and downtime risk worsen

Engineering Contradiction:
Improveinfrastructure simplicityVSAvoidnetwork availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements prior cushioning by deploying redundant virtual appliances and control functions that can take over if primary systems fail. The virtual appliance architecture enables easy deployment of backup instances and facilitates rapid failover to alternative paths or resources. This preparatory redundancy cushioning ensures that mission-critical applications maintain high availability without requiring complete infrastructure redesign, balancing simplicity with reliability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent introduces a control plane as an intermediary layer between the connectivity plane and applications. This control plane mediates traffic flow, enforces security policies, and manages QoS requirements, protecting mission-critical applications from network issues. The intermediary control plane can detect and respond to failures, redirect traffic through alternative paths, and maintain service continuity, thereby improving network reliability while maintaining infrastructure simplicity through a unified control architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9338021B2Network traffic redirection in bi-planar networks
Publication Date: 2016.05.10 TREND MICRO INC
  • US9338021B2 patent drawing
  • US9338021B2 patent drawing
  • US9338021B2 patent drawing

AI summary

An electronic communication network includes a connectivity subsystem. The connectivity subsystem registers a control subsystem with the connectivity subsystem. The control subsystem requests that network traffic be redirected from the connectivity subsystem to the control subsystem. In response to the request, the connectivity subsystem redirects network traffic from the connectivity subsystem to the control subsystem.