One-Way Proxy TCP Session Reliability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional two-way proxy server architectures are inefficient and unreliable, as they require complete TCP processing for both directions of traffic, leading to performance issues and inability to maintain TCP sessions during hardware bypass events.
Innovation Solution
A one-way proxy system that intercepts and processes TCP traffic in one direction only, using a hardware bypass switch to ensure reliable operation and maintain TCP sessions even during failures, by propagating TCP options and properties unchanged and modifying packet headers as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional two-way proxy server architecture is used to intercept TCP traffic, then the system can provide complete TCP processing for both directions of traffic, but the network performance deteriorates due to high overhead and the system cannot maintain TCP sessions during hardware bypass events
Solution Approach 1:
The patent segments the proxy functionality into two independent one-way proxy systems, each handling one direction of TCP traffic separately. This allows each proxy to operate independently with its own hardware bypass capability, enabling one proxy to failover while the other maintains TCP session state, thus resolving the contradiction between reliability and productivity
Solution Approach 2:
The patent introduces a state synchronization mechanism as an intermediary between the two one-way proxies. This mediator exchanges TCP state information between proxies, allowing them to coordinate during hardware bypass events without requiring complete TCP processing in both directions simultaneously, thereby maintaining both reliability and performance
2Reliability
If conventional two-way proxy server architecture is used, then both TCP sessions can be processed completely, but the device complexity increases and the system cannot provide fail close support
Solution Approach 1:
The patent divides the complex two-way proxy into two simpler one-way proxies, each with dedicated hardware bypass switches. This segmentation reduces the complexity of individual proxy components while collectively providing the reliability and fail-close support that the original complex system lacked
Solution Approach 2:
Each one-way proxy is designed with local hardware bypass capability specific to its direction of traffic. This local quality allows each proxy to independently handle failures in its own path without affecting the other direction, providing fail-close support with simpler, more modular architecture
3Reliability
If complete TCP processing is performed for both TCP sessions in conventional proxy, then all traffic can be analyzed, but the processing overhead increases and performance metrics such as throughput decrease
Solution Approach 1:
The patent applies partial action by having each one-way proxy process only its designated direction of traffic rather than both directions. This reduces processing overhead and energy consumption while maintaining TCP session continuity through coordinated state management between the two proxies
Solution Approach 2:
By segmenting the processing load into two separate one-way proxies, each handling only one direction, the system reduces the processing overhead per proxy while maintaining overall TCP session reliability through state synchronization, thereby reducing energy loss without sacrificing session continuity
Data Source
AI summary
A one-way proxy system is provided that supports one-way analysis of a transport control protocol (TCP) data stream. The one-way proxy system is used to intercept a TCP data link between two respective TCP endpoints. A one-way analyzer such as a one-way content filter, virus scanner, or firewall may be used to analyze a TCP data stream that is intercepted by the one-way proxy system. The one way proxy system preserves TCP options and TCP properties associated with the TCP packets in the TCP data stream, so that an existing TCP session between the TCP endpoints can survive in the event of a hardware bypass operation. The one-way proxy has a low overhead because significant TCP processing of the TCP data stream is only required in one direction.


