Access Gateway Inter-Module Headers for Packet Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In network environments, accurately managing policy information and ensuring proper billing and security for end users is challenging due to unknown, inaccurate, or ambiguous service levels, leading to synchronization issues and potential security vulnerabilities.

Innovation Solution

A system and method that utilize an access gateway encapsulation/decapsulation element and a client services packet gateway to implement enhanced packet processing through inter-module headers, enabling accurate billing and integrating security functionality within the gateway, while passing subscriber state in-band with packets for failover scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If policy information is distributed across multiple network components, then service flexibility and adaptability are improved, but synchronization accuracy and billing precision deteriorate

Engineering Contradiction:
Improveservice flexibilityVSAvoidbilling precision
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

An intermediary synchronization mechanism is introduced that mediates between distributed policy components and the billing system. This intermediary ensures that policy information is consistently propagated and synchronized across all network components, maintaining billing precision while allowing service flexibility. The intermediary acts as a central coordination point that resolves conflicts and ensures data consistency without restricting service adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If security functionality is integrated within the gateway, then system complexity is reduced, but security isolation and fault containment worsen

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The gateway is segmented into distinct functional modules, with security functionality separated into an independent security module. This segmentation maintains security isolation by creating clear boundaries between security functions and other gateway operations, while also managing complexity through modular design. Each module can be independently configured, maintained, and updated without affecting the entire system.

Inventive Principle:
Principle #1Segmentation

3Reliability

If subscriber state is passed in-band with packets, then failover capability is improved, but network bandwidth consumption and processing overhead worsen

Engineering Contradiction:
Improvefailover capabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Instead of passing complete subscriber state information with every packet, only essential state parameters are included in-band with packets. This partial action approach provides sufficient information for failover capability while minimizing network bandwidth consumption and processing overhead. The complete subscriber state is maintained separately in the gateway, and only critical updates are transmitted with packets.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7568093B2System and method for service tagging for enhanced packet processing in a network environment
Publication Date: 2009.07.28 CISCO TECHNOLOGY INC
  • US7568093B2 patent drawing
  • US7568093B2 patent drawing
  • US7568093B2 patent drawing

AI summary

An apparatus for charging in a network environment is provided that includes an access gateway encapsulation/decapsulation element operable to establish one or more packet data protocol (PDP) links on behalf of an end user and to perform encapsulation and decapsulation operations for one or more of the links associated with the end user. The access gateway encapsulation/decapsulation element is further operable to interface with a client services packet gateway (CSPG) that is operable to provide enhanced packet processing for the end user for requested information. The apparatus also includes an access gateway policy element operable to interface with the CSPG. The access gateway encapsulation/decapsulation element and the access gateway policy element cooperate to use one or more inter-module headers in order to coordinate the enhanced packet processing for one or more communication flows associated with the end user.