Pre-Encryption Policy Aggregation for Router Bottleneck Relief

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internal bottlenecks in communication networks, particularly at internal feature modules like crypto-engines, cause latency and packet drops, especially during peak usage, due to resource contention and encryption obscuring payload data, making it difficult to apply post-encryption services effectively.

Innovation Solution

The method involves aggregating user-configured service policies to determine if internal feature modules can satisfy bandwidth requirements, applying aggregate service policies before packet processing, and implementing priority queuing to ensure that latency-sensitive packets are encrypted and processed efficiently, thereby prioritizing and scheduling packets to alleviate bottlenecks and meet service guarantees.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied to data packets, then security and confidentiality are improved, but payload data becomes obscured making it difficult to apply post-encryption services

Engineering Contradiction:
ImprovesecurityVSAvoidpayload examination
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies classification and service policy determination before encryption occurs. The system examines packet payloads, determines required services, and applies them prior to the encryption process, thus avoiding the need to examine obscured encrypted data later.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary classification mechanism that operates between packet ingress and encryption. This intermediary component extracts necessary information from packet payloads before encryption obscures them, enabling service determination without direct examination of encrypted data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If internal feature modules process all packets equally on FIFO basis, then processing simplicity is maintained, but latency-sensitive packets experience excessive delay during peak usage

Engineering Contradiction:
Improveprocessing simplicityVSAvoidpacket latency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent applies different processing qualities to different packets based on their service requirements. Latency-sensitive packets receive priority processing with expedited handling, while other packets follow standard FIFO processing, thus optimizing time-critical traffic without compromising overall system simplicity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary classification of packets before they enter the processing queue, identifying latency-sensitive traffic in advance. This allows priority queuing to be implemented without complex real-time decision-making during packet processing, maintaining operational simplicity while improving time-critical performance.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If service policies are applied after encryption, then security is maintained, but classification accuracy decreases due to obscured payload information

Engineering Contradiction:
ImprovesecurityVSAvoidclassification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent performs service classification and policy determination before encryption occurs. By examining packet payloads and determining required services in plaintext before encryption obscures the data, the system achieves both accurate classification and maintained security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of applying services after encryption (the conventional approach), the patent inverts the sequence by applying classification and service determination before encryption. This reversal enables accurate payload examination while maintaining security through subsequent encryption.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS9065741B1Methods and apparatuses for identifying and alleviating internal bottlenecks prior to processing packets in internal feature modules
Publication Date: 2015.06.23 CISCO TECHNOLOGY INC
  • US9065741B1 patent drawing
  • US9065741B1 patent drawing
  • US9065741B1 patent drawing

AI summary

Methods and apparatuses for identifying and alleviating bottlenecks prior to processing packets in internal feature modules are described. First, a method is provided for aggregating the service policies of various physical interfaces, and using results of the aggregation to determine whether a packet processing engine is capable of satisfying the aggregated service policy information. Second, a method and apparatus for applying the aggregated service policy prior to processing in an internal feature module, such as a crypto-engine. Packets on routers/switches are expected to be subjected to certain policies to address resource contention or streamlining/prioritization on outbound interfaces. Internal bottlenecks that a user can neither see nor control may cause packet transmission guarantees to be violated. Encryption is an example of an internal service that adds overhead thereby creating an internal bottleneck. Such internal bottlenecks are cured through intelligent means of pre-processing and pre-application of certain policy rules.