Delayed Proxy-less NAT Decision Based on Application Payload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for choosing a network path based on an application payload during a client-server handshake are complex and require extensive transport layer protocol modifications and application layer payload buffering, making them inefficient and compute-intensive.

Innovation Solution

A method and system that manage handshake messages between a client and a server until an application layer message is communicated, allowing for a policy decision to be made based on the payload, which selects a path and chooses a target device from multiple potential devices, establishing the selected path for communication without the need for a proxy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If policy decisions are made during the handshake phase based on application payload, then network path selection can be optimized, but the system requires extensive transport layer protocol modification and application layer payload buffering capabilities

Engineering Contradiction:
Improvenetwork path selection efficiencyVSAvoidtransport layer protocol modification complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by establishing the connection first and then making the policy decision later based on the application payload. The system buffers the connection state and makes the routing decision after seeing the actual application data, rather than trying to make the decision during the handshake phase. This eliminates the need for complex transport layer modifications while achieving payload-based path selection.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If policy decisions are made during the handshake phase, then network path selection can be optimized, but application layer payload buffering capabilities are required

Engineering Contradiction:
Improvenetwork path selection efficiencyVSAvoidapplication layer payload buffering requirements
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts the policy decision-making process from the handshake phase and moves it to occur after the application payload is received. By separating the connection establishment function from the routing decision function, the system can make informed routing decisions based on actual application data without requiring complex buffering mechanisms during the handshake phase.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If extensive transport layer protocol modification is performed to enable payload-based routing, then path selection can be optimized, but the system becomes more complex and difficult to implement

Engineering Contradiction:
Improvepath selection flexibilityVSAvoidimplementation complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent introduces an intermediary approach where the system receives the connection, buffers it temporarily, then makes the routing decision based on the application payload before forwarding. This intermediary buffering mechanism allows payload-based routing without requiring modifications to the transport layer protocols, maintaining simplicity while achieving flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11483394B2Delayed proxy-less network address translation decision based on application payload
Publication Date: 2022.10.25 FORCEPOINT LLC
  • US11483394B2 patent drawing
  • US11483394B2 patent drawing
  • US11483394B2 patent drawing

AI summary

A method, system, and computer-usable medium are disclosed for, responsive to communication of a client handshake to a server for establishing communications between the client and server, managing handshake messages between the client and server until an application layer message is communicated from the client, such that a connection between the client and the server appears to be established, and responsive to communication of the application layer message from the client, rendering a policy decision with respect to a connection between the client and the server based on a payload of the application layer message, the policy decision defining a selected path between the client and the server and including a chosen target device from a plurality of potential target devices, wherein the chosen target device is within the selected path and establishing the selected path for communication between the client and the server in accordance with the policy decision.