Integrated Security Switch Merging Layer 2 and Layer 3 Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions, such as unified threat management (UTM) devices, increase network complexity and administrative overhead due to the need for dedicated devices for switching and security, which can reduce the effectiveness of security devices in managing growing network traffic and blended threats.

Innovation Solution

An integrated security switch that combines Layer 2 and Layer 3 switching functionality with a unified management interface, enabling seamless connectivity and security management through a single interface driven by both command line and graphic user interfaces, reducing complexity and enhancing flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated separate devices are deployed for switching and security, then network security functionality is provided, but network complexity and administrative overhead increase

Engineering Contradiction:
Improvenetwork security functionalityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines switching functions and security functions into a single integrated security switch device. The security module and switching module are merged into one system that can perform both packet forwarding and security processing (firewall, intrusion detection, virus filtering) simultaneously, eliminating the need for multiple separate devices and reducing network complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated security switch is designed as a multi-functional device that can perform switching operations and multiple security functions including firewall filtering, intrusion detection, virus scanning, and spam filtering. This universal device replaces multiple specialized devices, simplifying network architecture while maintaining comprehensive security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated separate devices are deployed for switching and security, then security features are implemented, but administrative overhead increases

Engineering Contradiction:
Improvesecurity featuresVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the management interfaces of switching and security functions into a unified management system. Administrators can configure and monitor both switching parameters and security policies through a single interface, eliminating the need to separately manage multiple devices and reducing administrative overhead.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If dedicated separate devices are deployed for switching and security, then network security is provided, but effectiveness of security device is reduced due to traffic absorption by switch

Engineering Contradiction:
Improvenetwork securityVSAvoideffectiveness of security device
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By integrating the security module directly with the switching module, the system ensures that all traffic passing through the switch is automatically available for security processing. The security module can inspect and filter traffic without requiring separate physical connections or additional traffic copying, maximizing security effectiveness while maintaining switching performance.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8588226B2Integrated security switch
Publication Date: 2013.11.19 FORTINET INC
  • US8588226B2 patent drawing
  • US8588226B2 patent drawing
  • US8588226B2 patent drawing

AI summary

An integrated security switch and related method for managing connectivity and security among networks. The integrated security switch includes a security function connectable with a first network and at least one switching function connectable with a second network. A common management interface driven by both command line interface and graphic user interface protocols manages the switching function via a management path dedicated between the security function and the switching function. The common management interface enables secure switching of traffic to flow via a traffic path dedicated between the switching function and the security function. Typically, the traffic is a flow of data between the Internet and a group of networked users such as a wide area network.