Network Security Controller for Dynamic DPI Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional deep packet inspection (DPI) deployments are limited by fixed 'bump-in-the-wire' configurations, which are costly and underutilized, failing to provide comprehensive network protection due to oversizing and high per-port costs, making it impractical to distribute multiple high-performance DPI devices across networks effectively.

Innovation Solution

A controller is employed to monitor and control network traffic, allowing network security devices to act as programmable services for multiple switches, optimizing workload and bandwidth usage by selecting the appropriate network security devices based on capabilities and workload, forming a pool of resources accessible to all network components, and dynamically reconfiguring policies to distribute traffic and resources efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional bump-in-the-wire DPI devices are deployed at fixed locations, then network security inspection is provided at specific points, but the solution is costly, underutilized, and limited in scale due to fixed port segments

Engineering Contradiction:
Improvenetwork security inspectionVSAvoiddeployment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms fixed bump-in-the-wire DPI deployments into dynamic, programmable service instances that can be dynamically allocated to different network segments on demand. The system allows flexible deployment configurations where DPI services can be moved, scaled, and reconfigured without physical reinstallation, resolving the contradiction between providing reliable security inspection and maintaining deployment flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal DPI service platform that can serve multiple network segments and topologies through a single pooled resource system. Instead of dedicated fixed devices for each segment, the system provides multi-functional DPI capabilities that can be dynamically assigned to various network locations, eliminating the need for separate fixed deployments at each segment while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple DPI devices are distributed across the network to provide protection for specific physical links, then coverage is improved, but the per-port cost becomes high and deployment complexity increases

Engineering Contradiction:
Improvenetwork protection coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple DPI device functions into a single pooled resource system that serves the entire network. Instead of distributing separate DPI devices to each network segment, the system combines DPI capabilities into a shared pool that can be dynamically allocated to multiple segments simultaneously, reducing overall device complexity while maintaining comprehensive coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a controller as an intermediary component that manages the dynamic allocation of DPI services to network segments. This controller simplifies deployment complexity by centralizing the management logic, allowing automated policy-based distribution of security services without requiring manual configuration at each segment, thus reducing operational complexity while maintaining extensive coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If fixed bump-in-the-wire DPI devices are used, then implementation is simple at each location, but the solution is oversized and underutilized leading to wasted resources

Engineering Contradiction:
Improveimplementation simplicityVSAvoidresource utilization efficiency
Core Design Contradiction:
Ease of manufactureVSLoss of energy

Solution Approach 1:

The patent implements dynamic resource allocation where DPI processing capacity is dynamically adjusted based on actual network traffic demands at each segment. Instead of fixed oversized devices that run at low utilization, the system dynamically scales resources up or down according to real-time needs, maintaining implementation simplicity through automated policy-based allocation while dramatically improving resource utilization efficiency.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of DPI deployment from fixed physical installations to dynamic virtualized services. This allows the system to adjust processing parameters, allocation ratios, and resource capacities dynamically based on network conditions, transforming static oversized devices into flexible resources that adapt to actual workload requirements and eliminate resource waste.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If DPI devices are redeployed to different network segments, then coverage is improved, but the network becomes unprotected during the redeployment process

Engineering Contradiction:
Improvesecurity coverageVSAvoiddeployment downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent ensures continuous security protection during redeployment by maintaining active DPI service instances in the pool that can be dynamically reassigned. Instead of taking devices offline for redeployment, the system continuously allocates active service instances to all network segments, ensuring uninterrupted security coverage while enabling flexible reconfiguration of the underlying infrastructure.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11005814B2Network security
Publication Date: 2021.05.11 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11005814B2 patent drawing
  • US11005814B2 patent drawing
  • US11005814B2 patent drawing

AI summary

An example of a computing system is described herein. The computing system includes a plurality of network security devices. The computing system also includes a network switch configured to direct network traffic. The computing system further includes a controller coupled to the network switch. The controller is to instruct the network switch in directing network traffic to the plurality of network security devices.