One-Way Proxy TCP Session Reliability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional two-way proxy server architectures are inefficient and unreliable, as they require complete TCP processing for both directions of traffic, leading to performance issues and inability to maintain TCP sessions during hardware bypass events.

Innovation Solution

A one-way proxy system that intercepts and processes TCP traffic in one direction only, using a hardware bypass switch to ensure reliable operation and maintain TCP sessions even during failures, by propagating TCP options and properties unchanged and modifying packet headers as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional two-way proxy server architecture is used to intercept TCP traffic, then the system can provide complete TCP processing for both directions of traffic, but the network performance deteriorates due to high overhead and the system cannot maintain TCP sessions during hardware bypass events

Engineering Contradiction:
ImproveTCP session survival during hardware bypassVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the proxy functionality into two independent one-way proxy systems, each handling one direction of TCP traffic separately. This allows each proxy to operate independently with its own hardware bypass capability, enabling one proxy to failover while the other maintains TCP session state, thus resolving the contradiction between reliability and productivity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a state synchronization mechanism as an intermediary between the two one-way proxies. This mediator exchanges TCP state information between proxies, allowing them to coordinate during hardware bypass events without requiring complete TCP processing in both directions simultaneously, thereby maintaining both reliability and performance

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional two-way proxy server architecture is used, then both TCP sessions can be processed completely, but the device complexity increases and the system cannot provide fail close support

Engineering Contradiction:
Improvefail close supportVSAvoidproxy system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the complex two-way proxy into two simpler one-way proxies, each with dedicated hardware bypass switches. This segmentation reduces the complexity of individual proxy components while collectively providing the reliability and fail-close support that the original complex system lacked

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each one-way proxy is designed with local hardware bypass capability specific to its direction of traffic. This local quality allows each proxy to independently handle failures in its own path without affecting the other direction, providing fail-close support with simpler, more modular architecture

Inventive Principle:
Principle #3Local quality

3Reliability

If complete TCP processing is performed for both TCP sessions in conventional proxy, then all traffic can be analyzed, but the processing overhead increases and performance metrics such as throughput decrease

Engineering Contradiction:
ImproveTCP session continuityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies partial action by having each one-way proxy process only its designated direction of traffic rather than both directions. This reduces processing overhead and energy consumption while maintaining TCP session continuity through coordinated state management between the two proxies

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

By segmenting the processing load into two separate one-way proxies, each handling only one direction, the system reduces the processing overhead per proxy while maintaining overall TCP session reliability through state synchronization, thereby reducing energy loss without sacrificing session continuity

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8069250B2One-way proxy system
Publication Date: 2011.11.29 VMWARE INC
  • US8069250B2 patent drawing
  • US8069250B2 patent drawing
  • US8069250B2 patent drawing

AI summary

A one-way proxy system is provided that supports one-way analysis of a transport control protocol (TCP) data stream. The one-way proxy system is used to intercept a TCP data link between two respective TCP endpoints. A one-way analyzer such as a one-way content filter, virus scanner, or firewall may be used to analyze a TCP data stream that is intercepted by the one-way proxy system. The one way proxy system preserves TCP options and TCP properties associated with the TCP packets in the TCP data stream, so that an existing TCP session between the TCP endpoints can survive in the event of a hardware bypass operation. The one-way proxy has a low overhead because significant TCP processing of the TCP data stream is only required in one direction.