SD-WAN Flow Identifier for Reduced Header Packet Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SD-WAN technologies face inefficiencies due to significant overhead in packet headers, leading to increased bandwidth usage and transmission delays, particularly in low-bandwidth links like satellite connections, which affect customer experience.
Innovation Solution
Implementing a flow identifier system that reduces packet headers by removing immutable fields and converting them into metadata, allowing for tunnel-less communication between hubs in an SD-WAN, thereby optimizing packet size and reducing overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packet headers include all standard fields for secure tunnel communication, then communication reliability is maintained, but bandwidth efficiency deteriorates and transmission delays increase
Solution Approach 1:
The patent extracts and removes immutable fields from packet headers, keeping only the flow identifier and essential mutable fields. This extraction principle directly resolves the contradiction by eliminating redundant data that consumes bandwidth without contributing to communication reliability, thereby improving bandwidth efficiency while maintaining the necessary header information for secure tunnel communication.
Solution Approach 2:
Instead of including all standard header fields and removing what's unnecessary, the patent inverts the approach by starting with minimal fields (flow identifier) and adding only what's essential. This inversion strategy achieves bandwidth efficiency while maintaining reliability by including only the critical fields needed for secure communication.
2Reliability
If packet headers include all standard fields for secure tunnel communication, then communication reliability is maintained, but transmission speed deteriorates due to increased packet size
Solution Approach 1:
The patent extracts and removes immutable fields from packet headers, keeping only the flow identifier and essential mutable fields. This extraction directly improves transmission speed by reducing packet size, while maintaining the necessary header information for secure tunnel communication and reliability.
3Loss of energy
If flow identifier system is implemented to reduce packet size, then bandwidth efficiency is improved, but device complexity increases due to state management requirements
Solution Approach 1:
The patent applies preliminary action by establishing flow state information at the beginning of communication sessions. The hub pre-processes and stores flow identifier mappings before data transmission begins, which simplifies subsequent packet handling. This preliminary state management reduces the complexity of real-time processing while maintaining bandwidth efficiency through consistent flow identification.
Solution Approach 2:
The patent uses copying by maintaining flow state information as a separate data structure that mirrors essential communication parameters. Instead of reprocessing full packet headers, the system copies and references flow identifier mappings from the established state, reducing computational complexity while preserving bandwidth efficiency benefits.
4Loss of time
If tunnel-less communication is implemented with reduced headers, then transmission delays are reduced, but security overhead increases due to encryption/decryption operations
Solution Approach 1:
The patent extracts and removes redundant header fields that would otherwise require processing and transmission. By transmitting only essential fields with reduced packet sizes, the time spent on encryption and decryption operations is minimized, as there is less data to protect and process. This directly addresses the contradiction by reducing both transmission delays and encryption overhead simultaneously.
Data Source
AI summary
A flow identifier is described for packet sequences through a secure tunnel of an SD-WAN in a tunnel-less mode. A method includes receiving from a first client packets of a same flow, facilitating a secure tunnel between the first hub and the second hub, assigning a flow identifier to the packets, associating fields of a header of a start packet with the flow identifier, sending the start packet with the flow identifier through the secure tunnel, receiving an acknowledgement of the flow identifier, updating a state of the secure tunnel, removing the associated fields from a header of a second packet to form a reduced packet in response to 10 receiving the acknowledgment, encapsulating the reduced packet in a wrapper that includes the flow identifier, and sending encapsulated reduced packet.


