Networking Security Split Architecture for High-Bandwidth Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions face challenges in efficiently handling high-throughput networks, particularly in environments with 100G or higher speed links, where virtual security solutions become expensive due to computing resource utilization, and achieving true elasticity and service level performance in SASE environments is technically challenging.

Innovation Solution

A networking and security split architecture is introduced, separating the security entity into a Networking Anchor Layer for handling networking tasks like IPSec termination and routing, and a Security Offloading Layer for performing security functions such as Layer-7 Content Inspection, with an Offloading Interface between the two layers, allowing for elastic deployment of security resources without networking knowledge.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual security solutions are deployed in high-throughput networks (100G or higher speed links), then security functions can be provided, but computing resource utilization increases making the solutions expensive

Engineering Contradiction:
Improvesecurity function provisionVSAvoidcomputing resource utilization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent divides the security service into two separate layers: a Networking Anchor Layer that handles networking tasks (IPSec termination, routing) and a Security Offloading Layer that handles security functions (Layer-7 content inspection). This segmentation allows each layer to be optimized independently, reducing the computing resource burden on the networking layer while maintaining security functionality in high-throughput environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts security processing functions from the networking layer and places them in a separate Security Offloading Layer. This extraction removes CPU-intensive security tasks from the networking anchor layer, enabling better management of networking resources and reducing overall computing resource utilization while maintaining security protection.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If security resources are deployed to handle high-throughput traffic, then security performance improves, but achieving true elasticity and service level performance becomes technically challenging

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidelasticity and service level performance
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic architecture where the Security Offloading Layer can be independently scaled and configured without affecting the Networking Anchor Layer. This dynamic separation enables true elasticity, allowing security resources to be adjusted based on traffic conditions while maintaining service level performance in high-throughput networks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a new architectural dimension by separating networking and security functions into different layers. This dimensional separation allows each layer to be optimized for its specific function, enabling both high productivity in security processing and true elasticity in resource deployment without compromising service level performance.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Device complexity

If networking and security functions are combined in a single layer, then device complexity is reduced, but performance in high-bandwidth environments deteriorates

Engineering Contradiction:
Improvesingle-layer architectureVSAvoidhigh-bandwidth network performance
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments the combined networking and security functions into separate layers: the Networking Anchor Layer for networking tasks and the Security Offloading Layer for security functions. This segmentation, while increasing architectural complexity, enables optimized performance in high-bandwidth environments by allowing each layer to specialize in its function without resource contention.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240372829A1Networking and security split architecture
Publication Date: 2024.11.07 PALO ALTO NETWORKS INC
  • US20240372829A1 patent drawing
  • US20240372829A1 patent drawing
  • US20240372829A1 patent drawing

AI summary

Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.