Packet Scheduling Policies for Secure SD-WAN Traffic Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SD-WAN infrastructure lacks optimal data traffic management due to unknown network access conditions, traffic volume changes, and security vulnerabilities from external AI-based solutions, leading to non-optimized routing and potential security breaches.
Innovation Solution
Implementing a method for managing data traffic by selecting packet scheduling policies based on application characteristics, supported by both source and recipient entities, to optimize routing and security, using protocols like QUIC and SDN controllers for local control over data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If external AI-based solutions are used for predictive management of quality of experience, then routing optimization is improved, but security vulnerabilities and data confidentiality issues arise
Solution Approach 1:
The patent extracts the AI/ML functionality from external entities and relocates it to the network edge devices (gateways and endpoints). This allows predictive analytics to be performed locally using distributed ledger data, eliminating the need to share sensitive telemetry data with external AI services while maintaining routing optimization capabilities.
Solution Approach 2:
The distributed ledger acts as an intermediary that enables secure information sharing between network entities. Instead of directly sharing sensitive data with external AI systems, the patent uses the distributed ledger to provide verified network conditions and performance metrics, which then feed into local predictive algorithms at the edge devices.
2Measurement precision
If large volumes of telemetry data are exchanged with external entities for predictive management, then quality of experience prediction is improved, but data security and confidentiality risks increase
Solution Approach 1:
The patent implements local quality by performing predictive analytics at the network edge rather than centralizing data processing. Each gateway and endpoint runs local predictive algorithms that use distributed ledger data from their specific network context, eliminating the need to transmit sensitive data to external entities while maintaining precise quality of experience predictions.
Solution Approach 2:
Network entities perform self-service by maintaining their own predictive models and making local routing decisions based on distributed ledger data. This self-service approach eliminates dependency on external AI services and prevents sensitive data from leaving the network boundary, while still achieving accurate quality of experience prediction through local computational resources.
3Productivity
If centralized AI entities are used for traffic management, then routing decisions are improved, but security vulnerabilities from data aggregation increase
Solution Approach 1:
The patent segments the centralized AI entity into distributed predictive algorithms deployed at individual network edges. Instead of one central system aggregating all data, multiple independent predictive models operate locally at each gateway and endpoint, each making routing decisions based on local distributed ledger data. This segmentation eliminates the security vulnerability of centralized data aggregation while maintaining routing decision quality.
Data Source
AI summary
A method of managing data traffic between a source entity and a recipient entity, and corresponding entity and computer program. The method is for managing data traffic between a source entity and a recipient entity, implementing the following steps: selecting, for the source entity and the recipient entity, at least one policy for scheduling application data packets exchanged between the source entity and the recipient entity, taking into account at least one characteristic of an application associated with the application data, and establishing at least one connection between the source entity and the recipient entity, on which the at least one selected packet scheduling policy is implemented.


