Clustered Network Appliances for Asymmetric Routing State Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Asymmetric routing in enterprise networks with multiple Internet Service Providers (ISPs) leads to issues with client IP spoofing, where return traffic may not reach the original proxy device, resulting in connection timeouts and incorrect connection resets, as proxies lack state information to associate return traffic with incoming connections.

Innovation Solution

Establishing a peering relationship among network appliances through control messages to maintain traffic flow state information, allowing for forwarding of network traffic among cluster members based on state information, and synchronizing local traffic flow state tables to manage network traffic effectively, including TCP connections and UDP flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple ISPs are used for enterprise network connectivity, then network redundancy and connectivity options are improved, but asymmetric routing occurs causing return traffic to not reach the original proxy device

Engineering Contradiction:
Improvenetwork connectivity reliabilityVSAvoidconnection state information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges multiple proxy devices into a unified cluster where connection state information is shared across all members. Through peering relationships and state synchronization, the cluster acts as a single logical entity, ensuring that return traffic can be properly associated with original connections regardless of which proxy receives it.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces cluster state tables and synchronization protocols as intermediaries between proxy devices. These intermediaries maintain and share connection state information across the cluster, enabling proxies to make informed forwarding decisions about return traffic without directly communicating with the original intercepting proxy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If proxy devices operate independently without state synchronization, then device complexity is reduced, but connection timeouts and incorrect resets occur due to lack of state information

Engineering Contradiction:
Improveproxy device complexityVSAvoidconnection handling reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary action by having proxies proactively share connection state information with the cluster before return traffic arrives. When a proxy intercepts a connection, it immediately synchronizes the connection state to the cluster state tables, ensuring readiness to handle asymmetric routing scenarios before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes feedback mechanisms through cluster state synchronization where proxies continuously exchange connection state information. This feedback loop ensures that all cluster members have up-to-date knowledge of active connections, enabling reliable handling of return traffic while maintaining relatively simple individual proxy devices.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If return traffic is forwarded to the original intercepting proxy, then connection state association is improved, but network traffic management complexity increases due to asymmetric routing handling

Engineering Contradiction:
Improvetraffic flow association accuracyVSAvoidtraffic management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses copying by creating and maintaining copies of connection state information in cluster state tables at each proxy device. Instead of complex inter-proxy communication for every packet, each proxy has local copies of relevant connection states, enabling fast and accurate forwarding decisions without centralized control complexity.

Inventive Principle:
Principle #26Copying

4Reliability

If cluster members synchronize traffic flow state tables, then return traffic association is improved, but control message overhead and synchronization complexity increase

Engineering Contradiction:
Improveconnection state consistencyVSAvoidcontrol message volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by having each proxy device maintain local copies of connection state tables tailored to its specific cluster role and traffic patterns. Rather than uniform full synchronization, each proxy holds only the state information relevant to its operations, reducing overall synchronization overhead while maintaining reliability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10009230B1System and method of traffic inspection and stateful connection forwarding among geographically dispersed network appliances organized as clusters
Publication Date: 2018.06.26 CA TECH INC
  • US10009230B1 patent drawing
  • US10009230B1 patent drawing
  • US10009230B1 patent drawing

AI summary

A peering relationship among two or more network appliances is established through an exchange of control messages among the network appliances. The peering relationship defines a cluster of peered network appliances, and at each network appliance of the cluster traffic flow state information for all the network appliances of the cluster is maintained. Network traffic associated with traffic flows of the network appliances of the cluster is managed according to the state information for the traffic flows. This managing of the network traffic may include forwarding among the network appliances of the cluster (i.e., to those of the appliances handling the respective flows) at least some of the network traffic associated with one or more of the traffic flows according to the state information for the one or more traffic flows. The traffic flows may be TCP connections or UDP flows.