Distributed Cluster Packet Processing via Star Topology

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems in cloud computing and large data centers face inefficiencies due to serial connectivity, leading to wasted computing resources, increased network delay, single points of failure, and complex software management, which hinder high-performance processing and flexible service deployment.

Innovation Solution

A distributed cluster processing system with a star topology structure, utilizing external interface units, processing units, and a switching unit to manage packet processing, where each processing unit performs specified service processing and determines lower-level processing based on session policies, reducing redundant processing and enabling dynamic registration and deregistration of units for performance optimization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If serial connection of security and value-added service products is used, then each product can perform its function, but computing resources are wasted due to repeated processing

Engineering Contradiction:
ImprovefunctionalityVSAvoidcomputing resource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the packet processing function into two distinct parts: abnormal packet detection (performed by only one product in the series) and normal packet processing (performed by all products). This segmentation eliminates redundant computing resource consumption while maintaining the functionality of each security and value-added service product.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If serial connection of multiple devices is used, then comprehensive security services are provided, but network delay increases due to multiple processing nodes

Engineering Contradiction:
Improveservice comprehensivenessVSAvoidnetwork delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies local quality by making each device in the serial connection specialize in specific processing tasks rather than performing all processing functions. Each device processes packets locally according to its designated function, reducing the cumulative delay that would result from all devices performing comprehensive processing on every packet.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If serial connection of devices is used, then security services are provided, but single points of failure increase reducing system reliability

Engineering Contradiction:
Improvesecurity service capabilityVSAvoidsystem reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces dynamic packet routing capabilities that allow the system to adaptively route packets around failed devices. This dynamic behavior enables the system to maintain security service functionality even when individual devices fail, thereby improving overall system reliability while preserving security service capabilities.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If serial connection mode is used, then security processing is performed, but processing performance is limited by the node with lowest capability

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidend-to-end processing performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the bottleneck constraint by separating abnormal packet detection from normal packet processing. High-performance nodes can process normal packets at full speed without being constrained by the lower processing capability of nodes responsible for abnormal packet detection, thereby achieving end-to-end performance that exceeds the limitations of the slowest node in the serial connection.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10404773B2Distributed cluster processing system and packet processing method thereof
Publication Date: 2019.09.03 HUAWEI TECH CO LTD
  • US10404773B2 patent drawing
  • US10404773B2 patent drawing
  • US10404773B2 patent drawing

AI summary

The present invention provides a distributed cluster processing system and a packet processing method thereof. The system includes at least one external interface unit, multiple processing units, and a switching unit, where each of the at least one external interface unit is connected between a corresponding processing unit of the multiple processing units and an external network element, and is configured to receive a packet from the external network element, forward the packet to a corresponding processing unit of the multiple directly connected processing units, and send a processed packet to the external network element; and each of the multiple processing units performs specified service processing and is respectively connected to the switching unit, so that the multiple processing units and the switching unit form a star topology structure. According to the system and the method, through a logical combination between the processing units, end-to-end high performance may be achieved.