Packet Switch Security Application Load Balancing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Scalable network security protocol systems face challenges in handling increased communication traffic volumes, particularly in maintaining security and efficiency as traffic volumes fluctuate, with existing solutions either requiring larger hardware installations or distributing load unevenly across multiple sub-systems.
Innovation Solution
Implementing virtualization to create and manage multiple instances of security applications across multiple host machines, using stateful load balancing and resilient hashing to ensure consistent and efficient distribution of packet flows, and utilizing a hot spare security application instance to handle failures and recoveries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network security protocol systems are scaled up to handle increased traffic volumes, then security capacity is improved, but hardware complexity and cost increase
Solution Approach 1:
The patent segments the network security protocol system into multiple independent sub-systems, each handling a portion of the traffic load. This allows the security capacity to be scaled by adding more sub-systems rather than upgrading a single large hardware installation, thereby improving security capacity while avoiding proportional increases in hardware complexity and cost.
2Productivity
If load is distributed across multiple sub-systems, then scalability is improved, but load distribution uniformity deteriorates
Solution Approach 1:
The patent implements a load balancing mechanism that monitors the load status of multiple security sub-systems and dynamically adjusts packet distribution accordingly. This feedback loop ensures that traffic is evenly distributed across available sub-systems, maintaining load distribution uniformity while preserving the scalability benefits of having multiple sub-systems.
3Productivity
If security applications are virtualized across host machines, then resource efficiency is improved, but system reliability deteriorates
Solution Approach 1:
The patent implements a hot spare security application instance that is pre-configured and ready to immediately take over if a primary virtualized security application fails. This beforehand cushioning mechanism ensures that the potential reliability risks associated with virtualization are mitigated, allowing the system to maintain high resource efficiency while preserving system reliability through failover capability.
Data Source
AI summary
Methods and apparatus for statefully load balancing bidirectional packet flows over a plurality of identical instances of a security application or of a security appliance using a generic packet switch and a monitoring agent are disclosed including the provisioning of spare security application instances or spare security appliances and minimizing redistribution of packet flows from the failure of a security application instance or of a security appliance.


