Distributed Cluster Packet Processing via Star Topology
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security systems in cloud computing and large data centers face inefficiencies due to serial connectivity, leading to wasted computing resources, increased network delay, single points of failure, and complex software management, which hinder high-performance processing and flexible service deployment.
Innovation Solution
A distributed cluster processing system with a star topology structure, utilizing external interface units, processing units, and a switching unit to manage packet processing, where each processing unit performs specified service processing and determines lower-level processing based on session policies, reducing redundant processing and enabling dynamic registration and deregistration of units for performance optimization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If serial connection of security and value-added service products is used, then each product can perform its function, but computing resources are wasted due to repeated processing
Solution Approach 1:
The patent segments the packet processing function into two distinct parts: abnormal packet detection (performed by only one product in the series) and normal packet processing (performed by all products). This segmentation eliminates redundant computing resource consumption while maintaining the functionality of each security and value-added service product.
2Adaptability or versatility
If serial connection of multiple devices is used, then comprehensive security services are provided, but network delay increases due to multiple processing nodes
Solution Approach 1:
The patent applies local quality by making each device in the serial connection specialize in specific processing tasks rather than performing all processing functions. Each device processes packets locally according to its designated function, reducing the cumulative delay that would result from all devices performing comprehensive processing on every packet.
3Adaptability or versatility
If serial connection of devices is used, then security services are provided, but single points of failure increase reducing system reliability
Solution Approach 1:
The patent introduces dynamic packet routing capabilities that allow the system to adaptively route packets around failed devices. This dynamic behavior enables the system to maintain security service functionality even when individual devices fail, thereby improving overall system reliability while preserving security service capabilities.
4Adaptability or versatility
If serial connection mode is used, then security processing is performed, but processing performance is limited by the node with lowest capability
Solution Approach 1:
The patent extracts the bottleneck constraint by separating abnormal packet detection from normal packet processing. High-performance nodes can process normal packets at full speed without being constrained by the lower processing capability of nodes responsible for abnormal packet detection, thereby achieving end-to-end performance that exceeds the limitations of the slowest node in the serial connection.
Data Source
AI summary
The present invention provides a distributed cluster processing system and a packet processing method thereof. The system includes at least one external interface unit, multiple processing units, and a switching unit, where each of the at least one external interface unit is connected between a corresponding processing unit of the multiple processing units and an external network element, and is configured to receive a packet from the external network element, forward the packet to a corresponding processing unit of the multiple directly connected processing units, and send a processed packet to the external network element; and each of the multiple processing units performs specified service processing and is respectively connected to the switching unit, so that the multiple processing units and the switching unit form a star topology structure. According to the system and the method, through a logical combination between the processing units, end-to-end high performance may be achieved.


