Proxy Ports for Network Device Traffic Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network ports lacking certain capabilities, such as encryption or decryption, cannot modify network traffic data units, limiting their functionality in data processing and transmission.

Innovation Solution

A system that associates network ports with proxy ports capable of modifying network traffic data units, using a proxy port to receive, analyze, and modify data units based on identifiers, and then transmit them to an egress port, enabling functionalities like encryption, decryption, and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network ports are used without proxy ports, then device complexity is reduced, but network functionality and security capabilities are limited

Engineering Contradiction:
Improvenetwork functionalityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces proxy ports as intermediary components that mediate between network ports lacking modification capabilities and the control plane. These proxy ports receive network traffic data units, perform modifications (encryption, decryption, authentication, etc.), and forward them to the control plane, enabling enhanced functionality without requiring every network port to have native modification capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If network ports perform all modifications natively, then processing speed is improved, but device complexity increases

Engineering Contradiction:
Improveprocessing speedVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the network device into distinct components: network ports for high-speed packet forwarding, proxy ports for modification operations, and control plane for management. This segmentation allows each component to specialize in its strength - network ports maintain high processing speed while proxy ports handle complex modifications, avoiding the need for every port to have full modification capabilities.

Inventive Principle:
Principle #1Segmentation

3Reliability

If proxy ports are introduced for all network ports, then security capabilities are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity capabilitiesVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates proxy ports with universal modification capabilities that can serve multiple network ports. A single proxy port can handle encryption, decryption, authentication, and other modifications for multiple associated network ports, reducing the overall number of proxy ports needed compared to having dedicated proxy ports for each network port.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11283733B2Proxy ports for network device functionality
Publication Date: 2022.03.22 ARISTA NETWORKS INC
  • US11283733B2 patent drawing
  • US11283733B2 patent drawing
  • US11283733B2 patent drawing

AI summary

Methods and systems for modifying network traffic data. The method of modifying network traffic may include receiving a network traffic data unit that includes an identifier, at a proxy port; based on the identifier, performing a proxy port action set to obtain a modified network traffic data unit; and transmitting the modified network traffic data unit towards an egress port.