Distributed Firewall Manager for Network Backbone Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication systems face inefficiencies and latency due to centralized firewall management, particularly in long haul network communications, which hinder optimal utilization of network backbone performance and introduce 'trombone' effects.

Innovation Solution

A distributed firewall management system with a centralized network controller that integrates multiple client site network components, enabling template-based policy management, asset aliasing, and intelligent packet distribution across diverse network connections for improved throughput and reduced latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized firewall management is used, then ease of operation is improved, but latency increases due to trombone network effects

Engineering Contradiction:
Improvefirewall managementVSAvoidlatency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system segments the centralized firewall management function into distributed firewall instances deployed at multiple network locations. Each location has its own firewall that can independently manage local traffic, eliminating the need for all traffic to traverse back to a central management site and thus reducing latency while maintaining centralized policy control through the controller.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a distributed controller as an intermediary that manages firewall policies across multiple locations without requiring traffic to pass through a central site. The controller communicates with firewalls at various locations via the network backbone, enabling centralized management while avoiding the trombone effect of traffic routing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If bonded/aggregated links are used to increase throughput, then network performance is improved, but network impedance increases causing long haul effects

Engineering Contradiction:
Improvenetwork throughputVSAvoidnetwork impedance
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system implements local firewall management at each network location, allowing traffic to be processed locally without traversing long distances through the network backbone. This local processing quality reduces the impact of network impedance and long haul effects while bonded/aggregated links maintain high throughput for traffic that does require backbone traversal.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If traffic is forwarded to remote central monitoring site, then centralized control is achieved, but inefficiencies and latency increase

Engineering Contradiction:
Improvecentralized controlVSAvoidtraffic processing efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system segments the centralized control function into a distributed controller that can manage firewalls at multiple locations simultaneously without requiring traffic to be forwarded to a single remote central monitoring site. This segmentation allows efficient local traffic processing while maintaining centralized policy control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from a single-point centralized control model to a multi-point distributed control model. The controller operates across multiple dimensions by simultaneously managing firewalls at various locations through the network backbone, eliminating the need to forward all traffic to a single remote site and improving overall processing efficiency.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11870753B2System, apparatus and method for providing a unified firewall manager
Publication Date: 2024.01.09 ADEIA MEDIA HOLDINGS INC
  • US11870753B2 patent drawing
  • US11870753B2 patent drawing
  • US11870753B2 patent drawing

AI summary

A network system is provided between at least a first client site and a second client site, the first and the second client site are at a distance from one another. A client site network component is implemented at least at the first client site, the client site network component bonding or aggregating one or more diverse network connections so as to configure a bonded/aggregated connection that has increased throughput. At least one network server component may be configured to connect to the client site network component using the bonded/aggregated connection. A cloud network controller may be configured to manage the data traffic and a virtual edge providing transparent lower-link encryption for the bonded/aggregated connection between the client site network component and the network server component.