Pre-Encryption Policy Aggregation for Router Bottleneck Relief
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internal bottlenecks in communication networks, particularly at internal feature modules like crypto-engines, cause latency and packet drops, especially during peak usage, due to resource contention and encryption obscuring payload data, making it difficult to apply post-encryption services effectively.
Innovation Solution
The method involves aggregating user-configured service policies to determine if internal feature modules can satisfy bandwidth requirements, applying aggregate service policies before packet processing, and implementing priority queuing to ensure that latency-sensitive packets are encrypted and processed efficiently, thereby prioritizing and scheduling packets to alleviate bottlenecks and meet service guarantees.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is applied to data packets, then security and confidentiality are improved, but payload data becomes obscured making it difficult to apply post-encryption services
Solution Approach 1:
The patent applies classification and service policy determination before encryption occurs. The system examines packet payloads, determines required services, and applies them prior to the encryption process, thus avoiding the need to examine obscured encrypted data later.
Solution Approach 2:
The patent introduces an intermediary classification mechanism that operates between packet ingress and encryption. This intermediary component extracts necessary information from packet payloads before encryption obscures them, enabling service determination without direct examination of encrypted data.
2Ease of operation
If internal feature modules process all packets equally on FIFO basis, then processing simplicity is maintained, but latency-sensitive packets experience excessive delay during peak usage
Solution Approach 1:
The patent applies different processing qualities to different packets based on their service requirements. Latency-sensitive packets receive priority processing with expedited handling, while other packets follow standard FIFO processing, thus optimizing time-critical traffic without compromising overall system simplicity.
Solution Approach 2:
The system performs preliminary classification of packets before they enter the processing queue, identifying latency-sensitive traffic in advance. This allows priority queuing to be implemented without complex real-time decision-making during packet processing, maintaining operational simplicity while improving time-critical performance.
3Reliability
If service policies are applied after encryption, then security is maintained, but classification accuracy decreases due to obscured payload information
Solution Approach 1:
The patent performs service classification and policy determination before encryption occurs. By examining packet payloads and determining required services in plaintext before encryption obscures the data, the system achieves both accurate classification and maintained security.
Solution Approach 2:
Instead of applying services after encryption (the conventional approach), the patent inverts the sequence by applying classification and service determination before encryption. This reversal enables accurate payload examination while maintaining security through subsequent encryption.
Data Source
AI summary
Methods and apparatuses for identifying and alleviating bottlenecks prior to processing packets in internal feature modules are described. First, a method is provided for aggregating the service policies of various physical interfaces, and using results of the aggregation to determine whether a packet processing engine is capable of satisfying the aggregated service policy information. Second, a method and apparatus for applying the aggregated service policy prior to processing in an internal feature module, such as a crypto-engine. Packets on routers/switches are expected to be subjected to certain policies to address resource contention or streamlining/prioritization on outbound interfaces. Internal bottlenecks that a user can neither see nor control may cause packet transmission guarantees to be violated. Encryption is an example of an internal service that adds overhead thereby creating an internal bottleneck. Such internal bottlenecks are cured through intelligent means of pre-processing and pre-application of certain policy rules.


