Open Platform Architecture for Heterogeneous Network Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current edge network devices are a hodgepodge of disparate solutions from different vendors, leading to high setup and operational costs, inflexibility, and increased packet examination delays, particularly for real-time data packets, with limited ability to dynamically reconfigure devices for different purposes.
Innovation Solution
A single network platform that integrates multiple packet processing applications from different vendors, featuring programmable service cards and I/O cards, allowing dynamic reconfiguration and flexible routing of packets based on characteristics, enabling efficient processing and quality of service for various packet types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple disparate edge devices from different vendors are deployed to provide comprehensive network services, then service functionality and coverage are improved, but device complexity and operational costs increase significantly
Solution Approach 1:
The patent combines multiple disparate network services (firewall, intrusion detection, traffic monitoring, etc.) from different vendors into a single integrated edge device platform. This consolidation merges previously separate functions into one unified system, reducing the number of individual devices needed while maintaining comprehensive service coverage.
Solution Approach 2:
The integrated edge device is designed to perform multiple network services simultaneously through a universal platform architecture. Different service modules can be deployed on the same device, allowing it to function as firewall, intrusion detection system, traffic monitor, and other network services depending on configuration needs.
2Reliability
If packets are examined by multiple different devices for various security purposes, then security coverage is improved, but packet processing time and delays increase
Solution Approach 1:
Multiple security examination functions are merged into a single integrated device, allowing packets to be inspected by multiple security services simultaneously or in a coordinated sequence within one device rather than being passed between multiple separate devices. This reduces transmission overhead and processing delays.
Solution Approach 2:
The patent segments the packet processing workflow into different service modules within the integrated device, allowing parallel processing of different packet aspects by different services. High-priority packets can be routed through optimized paths with fewer examination steps, while maintaining comprehensive security checks for all packets.
3Ease of manufacture
If a fixed series of vendor solutions is used for packet routing, then implementation simplicity is improved, but flexibility and adaptability to different packet types deteriorate
Solution Approach 1:
The patent implements dynamic packet routing where the processing path for each packet can be adjusted based on packet characteristics, priority levels, and current system state. The system can dynamically select which service modules to apply to each packet flow, allowing flexible adaptation to different traffic types while maintaining a structured processing framework.
Solution Approach 2:
Different processing paths and service combinations are applied to different packet types based on their specific requirements. High-priority real-time packets may receive expedited processing with fewer inspection steps, while standard packets undergo comprehensive security checks. Each packet flow receives customized treatment appropriate to its characteristics.
4Reliability
If traditional edge devices with fixed functionality are used, then device stability and reliability are improved, but ability to dynamically reconfigure for different applications deteriorates
Solution Approach 1:
The integrated edge device incorporates dynamic reconfiguration capabilities that allow service modules and processing paths to be modified in real-time based on changing network requirements. The system can load, unload, and reconfigure service modules without requiring physical device changes, enabling adaptation to new applications while maintaining operational stability.
Solution Approach 2:
The patent enables parameter changes in device configuration and service behavior based on traffic patterns and requirements. Processing thresholds, service activation states, and routing parameters can be dynamically adjusted to optimize performance for different application scenarios while maintaining system reliability through controlled change management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A platform for seamlessly hosts a plurality of disparate types of packet processing applications. One or more applications are loaded onto a service card on the platform. A programmable path structure is included that maps a logical path for processing of the packets through one or more of the plurality of service cards according to characteristics of the packets. Multiple path structures may be programmed into the platform to offer different service paths for different types of packets.