QoS Traffic Steering Using Separate Security Associations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network devices experience traffic outages due to packet fragmentation, reordering, and congestion when handling high priority traffic, leading to resource wastage in identifying and correcting these issues.
Innovation Solution
Implementing a network device that assigns different priorities to traffic and establishes separate security associations for high and low priority traffic, enabling efficient processing and routing based on these priorities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network devices handle high priority traffic through shared security associations, then resource utilization is improved, but traffic outages and packet reordering increase
Solution Approach 1:
The patent segments traffic into different priority levels (first priority traffic and second priority traffic) and establishes separate security associations for each priority level. This segmentation allows high priority traffic to be processed through dedicated security associations, preventing packet fragmentation and reordering, while still utilizing available network resources efficiently.
Solution Approach 2:
The patent applies different quality characteristics to different security associations based on traffic priority. First priority traffic receives enhanced processing with dedicated security associations that provide guaranteed service quality, while second priority traffic uses standard security associations. This local quality differentiation resolves the contradiction by ensuring reliability for critical traffic while maintaining overall resource efficiency.
2Device complexity
If network devices process all traffic through the same security association, then device complexity is reduced, but service quality predictability deteriorates
Solution Approach 1:
The patent implements dynamic security association selection based on traffic priority. The system automatically determines which security association to use for each packet based on its priority level, creating a dynamic adaptation mechanism that improves service quality predictability without requiring complex manual configuration. This dynamic approach resolves the contradiction by making the system responsive to traffic requirements.
Solution Approach 2:
The patent changes the parameter of security association selection based on traffic priority. By modifying which security association is active for which traffic type, the system achieves predictable service quality for different priority levels. This parameter change approach allows the same physical infrastructure to provide differentiated service quality without increasing hardware complexity.
3Ease of operation
If high priority traffic is mixed with low priority traffic in the same queue, then queue management is simplified, but traffic handling reliability deteriorates
Solution Approach 1:
The patent segments traffic queues by priority level, creating separate handling paths for first priority and second priority traffic. This segmentation ensures that high priority traffic is not delayed or reordered by low priority traffic, improving traffic handling reliability. The segmented approach maintains operational simplicity through automated priority-based routing.
Solution Approach 2:
The patent introduces priority-based classification as an intermediary mechanism between traffic arrival and queue processing. This intermediary automatically directs traffic to appropriate queues based on priority, simplifying queue management by eliminating the need for complex manual prioritization while ensuring reliable traffic handling through dedicated priority queues.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
A first network device of a network receives first traffic and second traffic, and assigns a first priority to the first traffic and a second priority to the second traffic. The first network device provides, to a second network device, a first message requesting whether the second network device can process the first traffic, and receives, from the second network device, a first response with a first value indicating that the second network device can process the first traffic. The first network device establishes, with the second network device, a path that includes a first security association and a second security association. The first network device provides, to the second network device, the first traffic with the first priority, via the first security association of the path, and the second traffic with the second priority, via the second security association of the path.