Path Control System for Gateway Load Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing path control systems concentrate processing loads on gateway devices, particularly due to the incorporation of multiple security features in a single gateway device, leading to bottlenecks in communication networks.

Innovation Solution

A path control system that dynamically selects between paths through a security device and those not through the security device based on a path information table associating data attributes with communication paths, reducing the load on gateway devices by optimizing data routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security features (firewall, antivirus, URL filtering, IPS) are incorporated into one gateway device, then security functionality is improved, but the processing load on the gateway device increases causing it to become a bottleneck

Engineering Contradiction:
Improvesecurity functionalityVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the security processing function from the gateway device by introducing a dedicated security appliance that handles all security features (firewall, antivirus, URL filtering, IPS) separately. This segmentation allows the gateway to focus on routing while the security appliance handles security processing, thereby maintaining security functionality while reducing the gateway's processing load and eliminating the bottleneck.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If a router packet path control device receives all packets once before transferring them, then packet path control is achieved, but the load concentrates on the router packet path control device

Engineering Contradiction:
Improvepacket path controlVSAvoidload concentration
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent introduces a path control device as an intermediary component that receives routing information from the gateway and independently determines packet paths based on a path information table. This intermediary approach distributes the path control logic, preventing load concentration on either the gateway or the router, while maintaining effective packet path control through centralized path information management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the gateway device determines whether to apply IPsec by referring to a routing table and performs IPsec setting process, then security encryption is achieved, but the load concentrates on the gateway device

Engineering Contradiction:
Improveencryption securityVSAvoidgateway processing load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the IPsec determination and setting process from the gateway device and relocates it to the path control device. The path control device refers to the path information table to determine whether IPsec should be applied and performs the IPsec setting process, thereby maintaining encryption security while removing this processing burden from the gateway, thus reducing gateway load and eliminating it as a bottleneck.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10038669B2Path control system, control device, and path control method
Publication Date: 2018.07.31 NEC CORP
  • US10038669B2 patent drawing
  • US10038669B2 patent drawing
  • US10038669B2 patent drawing

AI summary

To provide a path control system, a control device and a path control method that can achieve reduction of the load on a gateway device, there are included a communication device, a communication device, a security device that provides a security feature to data transmitted and received between the communication device and the communication device, and a path control device that selects one of a first path through the security device and a second path not through the security device as a communication path of the data based on a path information table where an attribute of the data and a communication path between the communication device and the communication device are associated.