Packet Traffic Segmentation for Network Forwarding Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional centralized network security solutions divert all traffic to a single network device for policy checks, leading to increased forwarding pressure and reduced efficiency due to detour transmission and delays.

Innovation Solution

A method where a portion of packet traffic is sent to a forwarding controller for centralized policy checks, while another portion is forwarded nearby through strategically selected forwarding nodes based on network topology, reducing pressure on the controller and improving forwarding efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If all traffic is diverted to a single network device for centralized policy checks, then network management is simplified, but forwarding pressure on the network device increases and forwarding efficiency decreases

Engineering Contradiction:
Improvenetwork managementVSAvoidforwarding efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent segments traffic into two parts: a first part that is diverted to the forwarding controller for centralized policy checks, and a second part that is forwarded directly by access devices without detouring to the controller. This segmentation allows centralized management for security while maintaining efficient local forwarding for normal traffic, thus resolving the contradiction between simplified network management and high forwarding efficiency.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If all traffic is diverted to a single network device for centralized policy checks, then centralized deployment of check policies is achieved, but traffic detour transmission increases and delay occurs

Engineering Contradiction:
Improvecentralized policy deploymentVSAvoidtraffic delay
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent divides traffic into a first part requiring centralized policy verification and a second part that can be forwarded locally without detouring. This segmentation ensures that only necessary traffic undergoes the time-consuming centralized check process, while other traffic maintains its original fast forwarding path, thereby achieving centralized policy deployment without excessive traffic delay.

Inventive Principle:
Principle #1Segmentation

3Reliability

If all traffic is diverted to a single network device, then unified traffic checking is achieved, but forwarding pressure on the network device increases

Engineering Contradiction:
Improvetraffic checkingVSAvoidforwarding pressure
Core Design Contradiction:
ReliabilityVSStress or pressure

Solution Approach 1:

The patent segments traffic handling responsibilities: the forwarding controller handles the first part of traffic for centralized policy verification to ensure reliability, while access devices handle the second part of traffic for direct forwarding to reduce pressure on the controller. This segmentation maintains unified traffic checking for security-critical packets while distributing forwarding pressure across multiple devices.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12095727B2Method for sending packet traffic and apparatus
Publication Date: 2024.09.17 HUAWEI TECH CO LTD
  • US12095727B2 patent drawing
  • US12095727B2 patent drawing
  • US12095727B2 patent drawing

AI summary

In a method for sending packet traffic, an access device transmits a first part of to-be-transmitted traffic to a forwarding controller for check. After the check is passed, the forwarding controller forwards the first part of the to-be-transmitted traffic. The access device transmits a second part of the to-be-transmitted traffic to a first forwarding node, and the first forwarding node forwards the second part of the to-be-transmitted traffic based on received forwarding indication information and forwarding information of the to-be-transmitted traffic.