Distributed Firewall Control Plane for Switching Stacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In centralized communication networks, the non-uniform configuration and increased administration overhead due to varying firewall capabilities across multiple switching units lead to inefficiencies and higher costs, especially when not all units have hardware or software firewall capabilities.

Innovation Solution

A distributed control plane mechanism optimally routes packets to available firewall modules within a switching stack, enabling stateful capabilities and centralized configuration and administration, allowing for flexible deployment and reduced packet routing overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized communication scheme with controller is used, then network control and security are improved, but device complexity and administration overhead increase due to non-uniform configuration requirements

Engineering Contradiction:
Improvenetwork control and securityVSAvoidconfiguration uniformity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the firewall capability from individual switching units and consolidates it into a centralized controller. The controller receives packets from multiple switching units, performs deep packet inspection and firewall functions centrally, then forwards packets to appropriate destinations. This eliminates the need for each switching unit to have built-in firewall capabilities, achieving uniform configuration while maintaining strong network control and security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The controller acts as an intermediary between multiple switching units. Instead of each switching unit independently performing firewall functions, packets are routed through the controller which mediates the firewall processing. The controller receives packets from switching units without firewalls, processes them centrally, and forwards them to destinations or back to switching units for forwarding.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enhanced firewall capabilities are added to all switching units, then network security is improved, but cost and administration overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the expensive and complex firewall functionality from individual switching units and consolidates it into a centralized controller. This allows standard, cost-effective switching units to be deployed without requiring expensive firewall hardware or software licenses on each unit, while the centralized controller provides comprehensive firewall capabilities for the entire network.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The controller provides universal firewall functionality to multiple switching units that individually lack this capability. Instead of each switching unit having dedicated firewall hardware, the controller serves all switching units by receiving their packets, performing firewall inspection, and forwarding them appropriately. This multi-functional approach provides security to the entire network through a single centralized system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If each switching unit has firewall capabilities, then distributed security processing is improved, but administration overhead increases due to non-uniform configuration

Engineering Contradiction:
Improvefirewall processing efficiencyVSAvoidadministration overhead
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent extracts firewall processing from distributed switching units and consolidates it in a centralized controller. This eliminates the need for administrators to configure and manage firewall settings on multiple individual devices, significantly reducing administration overhead. The controller centrally manages all firewall policies and packet processing for the entire network.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the firewall processing functions that were previously distributed across multiple switching units into a single centralized controller. By combining these functions, the system achieves simplified administration while maintaining efficient packet processing. The controller aggregates packets from multiple switching units and performs firewall inspection centrally, then distributes the results back to the network.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9130896B2Distributed functionality across multiple network devices
Publication Date: 2015.09.08 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9130896B2 patent drawing
  • US9130896B2 patent drawing
  • US9130896B2 patent drawing

AI summary

According to one embodiment, a method comprises an operation of identifying a plurality of network devices, and detecting a presence of firewall processing functionality in a subset of the network devices. At least one of the network devices not in the firewall subset is configured to forward packets to a network device of the subset for firewall processing.