Network Traffic Segmentation for Shared Security Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network traffic management systems, particularly in 5G transport networks, face inefficiencies due to the resource-intensive requirements of security and encryption protocols like MACsec and IPsec, which are not optimally allocated and can lead to bottlenecks, increased latency, and unnecessary hardware costs, especially in fronthaul links where most traffic does not require such protocols.
Innovation Solution
A mechanism for detecting and separating protocol data units requiring different processing power, such as security-sensitive frames, and transmitting them over different links, while using placeholder frames to maintain synchronization and reduce unnecessary encryption, allowing shared resource allocation across multiple links.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security protocols (MACsec/IPsec) are applied to all traffic in 5G transport networks, then security protection is improved, but processing resource consumption and latency increase significantly
Solution Approach 1:
The patent segments traffic into two categories: protected traffic (control plane, management, sensitive user information) and unprotected traffic (data plane). By applying security protocols only to the protected subset rather than all traffic, the system maintains security where needed while significantly reducing processing resource consumption and latency for the majority of data plane traffic.
Solution Approach 2:
The patent applies different security qualities to different parts of the traffic flow. Control plane and management traffic receive full MACsec/IPsec protection, while data plane traffic is transmitted without encryption. This localized application of security protocols optimizes the balance between security and performance by matching protection levels to traffic sensitivity requirements.
2Use of energy by moving object
If security protocols are applied to a subset of traffic, then processing resources are saved, but packet synchronization and ordering between protected and unprotected traffic becomes complex
Solution Approach 1:
The patent introduces a traffic classification and marking mechanism as an intermediary layer between the data plane and security processing. By marking packets with security requirements before transmission, the system enables simple router forwarding decisions without complex real-time synchronization logic, reducing device complexity while maintaining resource efficiency.
3Reliability
If dedicated MACsec hardware is deployed on each trunk port, then security processing capability is improved, but hardware costs and device complexity increase
Solution Approach 1:
The patent enables security processing resources to serve multiple functions and multiple traffic flows. Instead of dedicating MACsec hardware to each trunk port, the system uses centralized or shared security processing units that can dynamically handle security requirements across multiple ports and traffic types, reducing hardware costs and device complexity while maintaining security processing capability.
4Reliability
If MACsec is applied to fronthaul links, then security protection is improved, but latency increases and synchronization protocol performance is degraded
Solution Approach 1:
The patent segments fronthaul traffic to identify and protect only the small portion containing sensitive control information, while allowing the majority of data plane traffic to flow without encryption. This segmentation maintains security protection for critical fronthaul control signals while minimizing latency impact on the overall fronthaul performance.
Data Source
AI summary
There is provided a method comprising: detecting (310) a subset of protocol data units in an original stream of protocol data units to be transmitted over the network, wherein the original stream is associated with a first source port; generating (320) an updated transmitting-side stream of protocol data units based on the original stream, wherein the updated transmitting-side stream excludes the detected subset; merging (330) the subset of protocol data units with a subset of protocol data units associated with a second source port to form a merged stream; transmitting (340) the merged stream, as a first stream, over a first link of the network; transmitting (350) the updated transmitting-side stream associated with the first source port, as a second stream, over a second link; and transmitting (360) an updated transmitting-side stream associated with the second source port, as a third stream, over a third link.


