Load Balancer for Scalable Network Security Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communications networks face challenges in scaling network security infrastructure to handle increasing traffic volumes effectively, as existing solutions either require larger capacity appliances (scale up) or spread security tasks across multiple appliances (scale out), but these approaches may not efficiently manage load balancing and packet processing.

Innovation Solution

A system and method that utilize a load balancer to determine the optimal instance of a security application for processing bidirectional packet flows based on relative loading, ensuring stateful load balancing and efficient distribution across multiple instances, while maintaining transparency to network nodes at and above the layer 2 data link layer of the Open Systems Interconnect model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network security infrastructure scales up by using larger capacity appliances, then security processing capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidappliance complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the network security function into multiple identical instances running on a host machine, each capable of independent packet flow processing. Instead of using a single large-capacity appliance, the system divides the security processing task across multiple smaller instances, thereby improving overall processing capability while avoiding the complexity and cost associated with scaling up a single appliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple identical security application instances on a single host machine to achieve scalable security processing. By combining the processing power of multiple instances and using a load balancer to distribute traffic, the system achieves enhanced security capability without requiring multiple separate physical appliances, thus reducing complexity.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If network security infrastructure scales out by spreading security tasks across multiple appliances, then processing capacity is improved, but load balancing complexity increases

Engineering Contradiction:
Improveprocessing capacityVSAvoidload balancing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The load balancer in the patent is designed as a universal component that can distribute traffic to multiple identical security application instances using simple routing rules. Rather than implementing complex load balancing logic across heterogeneous appliances, the system uses a universal load balancer that works with any number of identical instances, thereby increasing processing capacity while minimizing load balancing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs multiple identical instances of the security application, ensuring homogeneity in the system architecture. This homogeneity simplifies load balancing because the load balancer only needs to distribute traffic based on simple criteria (such as instance availability) rather than managing complex differences between heterogeneous appliances, thus improving processing capacity without significantly increasing load balancing complexity.

Inventive Principle:
Principle #33Homogeneity

3Adaptability or versatility

If multiple instances of security application are used, then scalability is improved, but packet flow management complexity increases

Engineering Contradiction:
ImprovescalabilityVSAvoidpacket flow management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The load balancer serves as an intermediary between the external network and multiple security application instances. It manages all packet flow distribution to instances, absorbing the complexity of flow management internally. This allows the system to scale by simply adding more instances without increasing the complexity visible to external systems, as the load balancer continues to handle all flow management uniformly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Each security application instance operates independently and autonomously, managing its own packet processing without requiring complex coordination with other instances. The instances self-serve by handling their assigned traffic independently, which simplifies overall flow management. The load balancer simply directs traffic to available instances without needing to manage state across instances, enabling easy scalability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11316791B2Methods and apparatus for scalable network security functions
Publication Date: 2022.04.26 CORSA TECH INC
  • US11316791B2 patent drawing
  • US11316791B2 patent drawing
  • US11316791B2 patent drawing

AI summary

The present disclosure relates to scalable network security functions and handling of packet flows between network security zones in a communications network. Packets that are part of a bidirectional packet flow between the network security zones are received, and a determination is made as to an instance of a security application to which to assign the bidirectional packet flow for security processing. The determination is made based on relative loading of a plurality of identical instances of the security application running on a host machine. All of the received packets that are part of the bidirectional packet flow are directed for processing on the host machine by the one of the security application instances.