SD-WAN Branch Traffic Control via Intermediary Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SD-WAN technologies fail to effectively control traffic access between branch devices, particularly in scenarios where financial or government customers require strict security measures to prevent communication between branches.

Innovation Solution

A traffic control method that involves a network device obtaining configuration policies from a management device to redirect and filter traffic between branch devices, using filtering devices to enforce access control policies, ensuring that traffic is only allowed between branches and their headquarters, while preventing mutual access between branches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hub-spoke networking is used for SD-WAN deployment, then centralized security monitoring is achieved, but traffic access between branch devices cannot be effectively controlled

Engineering Contradiction:
Improvesecurity monitoringVSAvoidtraffic access control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a filtering device as an intermediary component between the network device and branch devices. This filtering device specifically handles traffic access control between branches, while the network device maintains centralized security monitoring. The intermediary resolves the contradiction by separating the monitoring function (at network device) from the access control function (at filtering device), allowing both centralized security monitoring and effective traffic access control to coexist.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the traffic control functionality by introducing a dedicated filtering device that handles inter-branch traffic access control, separate from the network device that handles centralized security monitoring. This segmentation allows each device to specialize in its respective function, resolving the contradiction between maintaining centralized monitoring capability and implementing effective access control between branches.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If branches are allowed to communicate with each other, then mutual access is enabled, but security requirements of financial and government customers are not met

Engineering Contradiction:
Improvemutual access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The filtering device serves as an intermediary that mediates all inter-branch traffic. It enforces access control policies that prevent direct mutual access between branches, thereby eliminating security risks while still allowing controlled communication when authorized. The filtering device acts as a security gatekeeper that maintains the isolation required by financial and government customers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security control function from the general network routing functionality by introducing a dedicated filtering device. This extracted security function specifically handles inter-branch traffic filtering, ensuring that security requirements are met by removing unauthorized access paths while maintaining legitimate communication channels when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If configuration policies are implemented to control traffic, then access control is achieved, but network device complexity increases

Engineering Contradiction:
Improvetraffic control capabilityVSAvoidnetwork device configuration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complex access control policy enforcement functionality from the network device and places it in a dedicated filtering device. This extraction reduces the configuration complexity of the network device while maintaining full traffic control capability through the filtering device, which is专门 designed to handle access control policies.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The filtering device acts as an intermediary that absorbs the complexity of access control policy configuration and enforcement. By placing this complexity in a dedicated filtering device rather than the network device, the overall system achieves traffic control capability while the network device itself maintains relative simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11876704B2Method, device, and medium for controlling traffic of network branch devices
Publication Date: 2024.01.16 HUAWEI TECH CO LTD
  • US11876704B2 patent drawing
  • US11876704B2 patent drawing
  • US11876704B2 patent drawing

AI summary

A traffic control method including obtaining, by a network device, a configuration policy from a management device, where the configuration policy is used to control access between a plurality of branch devices, and where each of the plurality of branch devices is connected to the network device, and configuring, by the network device, a destination of traffic between the branch devices based on the configuration policy, so that the traffic between the branch devices is transmitted to the configured destination.