Packet Switching Service Application via State Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Packet switching devices face inefficiencies in applying services to both directions of a packet flow, as existing solutions require rerouting packets through services cards or blade servers, which consume resources and are not scalable for shared state information management.
Innovation Solution
A method where a first processing complex communicates state information to a second processing complex, allowing both to process packets in both directions without rerouting, using a single processing complex for service application and informing other complexes of the association to ensure efficient packet forwarding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If packets are rerouted through services cards or blade servers to apply services, then service application capability is improved, but device complexity and resource consumption increase
Solution Approach 1:
The patent merges the service application function with the packet forwarding function by implementing service processing directly within the packet switching device's forwarding path. Instead of separating services into external cards or blade servers, the invention integrates service rules and packet forwarding logic into a unified processing architecture, eliminating the need for additional hardware components while maintaining full service capability.
Solution Approach 2:
The packet switching device is designed to perform multiple functions simultaneously: it acts as both a packet forwarder and a service applicator. The device can apply various services (firewall, NAT, deep packet inspection, etc.) directly to packets during the forwarding process, making the forwarding plane universally capable of handling both routing and service enforcement without requiring dedicated service processing paths.
2Adaptability or versatility
If packets are rerouted through services cards or blade servers, then service processing is improved, but productivity and scalability deteriorate
Solution Approach 1:
The patent segments the service processing function into individual service rules that can be independently configured, enabled, and processed within the packet switching device. Each service rule operates as a discrete processing step in the packet forwarding chain, allowing the device to efficiently process multiple services without requiring centralized service card arbitration. This segmentation enables parallel processing and improves throughput.
Solution Approach 2:
The packet switching device performs service processing autonomously within its own forwarding plane without requiring external service cards or blade servers. The device self-manages service rule application, state information storage, and packet processing, eliminating the need for additional hardware resources and improving overall system productivity and scalability.
3Reliability
If state information is shared between processing complexes, then service consistency is improved, but communication overhead increases
Solution Approach 1:
The patent merges the state information storage and management function directly into the forwarding complex that processes packets. Instead of maintaining separate state databases that require complex inter-complex communication, the service state information is integrated into the forwarding plane's data structures, allowing processing complexes to access and share state information efficiently through existing communication paths without additional overhead.
Data Source
AI summary
A service is applied in a packet switching device to both directions of a flow of packets through the packet switching device, with the application of this Layer-4 to layer-7 service to one direction requiring state information shared from the application of the service to packets traversing in the other direction. The service (e.g. firewall, network address translation) can be applied by different processing complexes which do not share memory; thus, state information is communicated between the processing complexes. When the service is applied by a single processing complex, packets can be directed explicitly to the single processing complex. The inline application of services in a packet switching system typically eliminates the need to change a packet's path through the packet switching system to that through a dedicated application server, and may eliminate the need for a dedicated services card or blade server.


