Packet Switch Security Application Load Balancing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Scalable network security protocol systems face challenges in handling increased communication traffic volumes, particularly in maintaining security and efficiency as traffic volumes fluctuate, with existing solutions either requiring larger hardware installations or distributing load unevenly across multiple sub-systems.

Innovation Solution

Implementing virtualization to create and manage multiple instances of security applications across multiple host machines, using stateful load balancing and resilient hashing to ensure consistent and efficient distribution of packet flows, and utilizing a hot spare security application instance to handle failures and recoveries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network security protocol systems are scaled up to handle increased traffic volumes, then security capacity is improved, but hardware complexity and cost increase

Engineering Contradiction:
Improvesecurity capacityVSAvoidhardware complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the network security protocol system into multiple independent sub-systems, each handling a portion of the traffic load. This allows the security capacity to be scaled by adding more sub-systems rather than upgrading a single large hardware installation, thereby improving security capacity while avoiding proportional increases in hardware complexity and cost.

Inventive Principle:
Principle #1Segmentation

2Productivity

If load is distributed across multiple sub-systems, then scalability is improved, but load distribution uniformity deteriorates

Engineering Contradiction:
ImprovescalabilityVSAvoidload distribution uniformity
Core Design Contradiction:
ProductivityVSStability of the object's composition

Solution Approach 1:

The patent implements a load balancing mechanism that monitors the load status of multiple security sub-systems and dynamically adjusts packet distribution accordingly. This feedback loop ensures that traffic is evenly distributed across available sub-systems, maintaining load distribution uniformity while preserving the scalability benefits of having multiple sub-systems.

Inventive Principle:
Principle #23Feedback

3Productivity

If security applications are virtualized across host machines, then resource efficiency is improved, but system reliability deteriorates

Engineering Contradiction:
Improveresource efficiencyVSAvoidsystem reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a hot spare security application instance that is pre-configured and ready to immediately take over if a primary virtualized security application fails. This beforehand cushioning mechanism ensures that the potential reliability risks associated with virtualization are mitigated, allowing the system to maintain high resource efficiency while preserving system reliability through failover capability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS20240348658A1Method and apparatus for security application balancing using a packet switch
Publication Date: 2024.10.17 CORSA TECH INC
  • US20240348658A1 patent drawing
  • US20240348658A1 patent drawing
  • US20240348658A1 patent drawing

AI summary

Methods and apparatus for statefully load balancing bidirectional packet flows over a plurality of identical instances of a security application or of a security appliance using a generic packet switch and a monitoring agent are disclosed including the provisioning of spare security application instances or spare security appliances and minimizing redistribution of packet flows from the failure of a security application instance or of a security appliance.