Offloading Dropped Flows to Access Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern network architectures, enforcing network security policies at firewall clusters can lead to bottlenecks and inefficient use of bandwidth, as dropped traffic flows continue to consume resources.

Innovation Solution

The technology offloads dropped traffic flows from firewall clusters to access switches based on host location, allowing network policies to be enforced closer to the traffic source, thereby reducing resource consumption and mitigating bottlenecks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security policies are enforced at firewall clusters, then network security is improved, but bandwidth efficiency deteriorates due to dropped traffic flows consuming resources

Engineering Contradiction:
Improvenetwork securityVSAvoidbandwidth efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the network security function by moving policy enforcement from centralized firewall clusters to distributed access switches. Each access switch independently enforces security policies for its connected hosts, dividing the enforcement burden across multiple locations rather than concentrating it at single points.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The controller acts as an intermediary that detects dropped flows at firewall clusters, determines host locations, and programs corresponding flow entries at access switches. This intermediary coordinates the redistribution of enforcement responsibilities without requiring direct intervention at each enforcement point.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If dropped traffic flows are handled at firewall clusters, then security policy enforcement is centralized, but network bottlenecks increase due to resource consumption

Engineering Contradiction:
Improvepolicy enforcement structureVSAvoidnetwork throughput
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent extracts dropped flow handling from the centralized firewall cluster and redistributes it to access switches. By removing the burden of processing dropped flows from the firewall cluster, the system eliminates the bottleneck while maintaining security policy enforcement capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local quality by having each access switch enforce security policies specifically for its connected hosts. This localized enforcement approach ensures that security decisions are made close to the traffic source, reducing the need for centralized processing and improving overall network throughput.

Inventive Principle:
Principle #3Local quality

3Loss of energy

If network policies are enforced at access switches closer to hosts, then bandwidth waste is reduced, but policy management complexity increases

Engineering Contradiction:
Improvebandwidth wasteVSAvoidpolicy management
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The controller continuously monitors network conditions and firewall cluster behavior to detect dropped flows. This feedback mechanism enables the controller to dynamically identify which flows should be offloaded to access switches, automating the policy management process while reducing bandwidth waste from dropped flows.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system implements self-service by having access switches autonomously enforce security policies for their connected hosts without requiring constant centralized control. The controller initially programs the flow entries, but once configured, the access switches independently handle policy enforcement, reducing management overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250141840A1Policy and Traffic Management in an Overlay Network
Publication Date: 2025.05.01 GOOGLE LLC
  • US20250141840A1 patent drawing
  • US20250141840A1 patent drawing
  • US20250141840A1 patent drawing

AI summary

Technique or mechanism in which network security policies are applied close to the source or origin associated with policy decisions. For example. the disclosed technology moves dropped flows from a firewall cluster to a leaf switch based on host location.