Cloud Router Policy Enforcement via Dynamic Load Balancing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network architectures face challenges in dynamically managing network access controllers, leading to potential service disruptions due to changes in client device load, as adding or removing controllers is difficult and can result in overloading or underutilization, especially when controllers fail or are taken offline for maintenance.

Innovation Solution

The solution involves distributing client devices across multiple network access controllers to balance load, allowing for dynamic addition or removal of controllers, and using a packet forwarding component to manage the distribution based on utilization, authentication, and policy enforcement, ensuring efficient resource allocation and minimizing service disruptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network access controllers are statically configured to service specific access points, then network policy handling is stable, but the system cannot dynamically adapt to changing client device loads, leading to overloading or underutilization

Engineering Contradiction:
Improvedynamic adaptation to client device loadVSAvoidcomplexity of dynamically adding or removing controllers
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic association between network access controllers and access points. Controllers can be dynamically assigned to service access points based on current client device load conditions rather than static pre-configuration. This allows the system to adapt to changing loads by reassigning access points to different controllers as needed, preventing overloading while maintaining operational simplicity through automated load balancing.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If network access controllers are added or removed dynamically, then the system can adapt to load changes, but service disruptions occur during controller changes

Engineering Contradiction:
Improvescalability of network architectureVSAvoidcontinuity of network service
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements load pre-balancing mechanisms that proactively redistribute client devices across controllers before any controller is added or removed from the system. This preliminary redistribution ensures that when dynamic changes occur, no single controller becomes overloaded, and service continuity is maintained. The system prepares the load distribution in advance, preventing service disruptions during scaling operations.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If client devices are concentrated on fewer controllers, then device complexity is reduced, but network efficiency decreases due to overloading

Engineering Contradiction:
Improvenetwork throughput and efficiencyVSAvoidcomplexity of load distribution management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements automated load balancing where the network access controllers themselves perform load distribution management without external intervention. Each controller monitors its own load conditions and automatically redistributes client devices to maintain optimal performance. This self-service approach prevents overloading and maintains high network efficiency while avoiding the complexity of external load management systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11582149B2Cloud based router with policy enforcement
Publication Date: 2023.02.14 FRONTIIR PTE LTD
  • US11582149B2 patent drawing
  • US11582149B2 patent drawing
  • US11582149B2 patent drawing

AI summary

Cloud based router with policy enforcement. In some implementations, a system is provided. The system includes a plurality of access points. The plurality of access points receive data packets from a plurality of client devices. The system also includes a plurality of tunnel devices coupled to the plurality of access points. The plurality of tunnel devices generate encapsulated packets based on the data packets received by the plurality of access points. The system further includes a plurality of packet forwarding components coupled to the plurality of tunnel devices via a first set of tunnels. The plurality of packet forwarding components receive the encapsulated packets from the plurality of tunnel devices and forward the encapsulate packets. The system further includes a plurality of network access controllers coupled to the plurality of packet forwarding components via a second set of tunnels. The plurality of network access controllers enforce one or more network policies for the plurality of client devices, as the plurality of client devices move between the plurality of access points.