Networking Security Split Architecture for High-Bandwidth Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions face challenges in efficiently handling high-throughput networks, particularly in environments with 100G or higher speed links, where virtual security solutions become expensive due to computing resource utilization, and achieving true elasticity and service level performance in SASE environments is technically challenging.
Innovation Solution
A networking and security split architecture is introduced, separating the security entity into a Networking Anchor Layer for handling networking tasks like IPSec termination and routing, and a Security Offloading Layer for performing security functions such as Layer-7 Content Inspection, with an Offloading Interface between the two layers, allowing for elastic deployment of security resources without networking knowledge.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual security solutions are deployed in high-throughput networks (100G or higher speed links), then security functions can be provided, but computing resource utilization increases making the solutions expensive
Solution Approach 1:
The patent divides the security service into two separate layers: a Networking Anchor Layer that handles networking tasks (IPSec termination, routing) and a Security Offloading Layer that handles security functions (Layer-7 content inspection). This segmentation allows each layer to be optimized independently, reducing the computing resource burden on the networking layer while maintaining security functionality in high-throughput environments.
Solution Approach 2:
The patent extracts security processing functions from the networking layer and places them in a separate Security Offloading Layer. This extraction removes CPU-intensive security tasks from the networking anchor layer, enabling better management of networking resources and reducing overall computing resource utilization while maintaining security protection.
2Productivity
If security resources are deployed to handle high-throughput traffic, then security performance improves, but achieving true elasticity and service level performance becomes technically challenging
Solution Approach 1:
The patent implements a dynamic architecture where the Security Offloading Layer can be independently scaled and configured without affecting the Networking Anchor Layer. This dynamic separation enables true elasticity, allowing security resources to be adjusted based on traffic conditions while maintaining service level performance in high-throughput networks.
Solution Approach 2:
The patent introduces a new architectural dimension by separating networking and security functions into different layers. This dimensional separation allows each layer to be optimized for its specific function, enabling both high productivity in security processing and true elasticity in resource deployment without compromising service level performance.
3Device complexity
If networking and security functions are combined in a single layer, then device complexity is reduced, but performance in high-bandwidth environments deteriorates
Solution Approach 1:
The patent segments the combined networking and security functions into separate layers: the Networking Anchor Layer for networking tasks and the Security Offloading Layer for security functions. This segmentation, while increasing architectural complexity, enables optimized performance in high-bandwidth environments by allowing each layer to specialize in its function without resource contention.
Data Source
AI summary
Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.


