Security Blade Server Virtualizes Network Traffic Flow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security protocols, such as IPsec, are workload intensive and can negatively affect network performance, requiring significant processing resources and complicating maintenance with numerous physical connections.

Innovation Solution

A security blade server within a software-defined environment (SDE) is used to perform security operations on network traffic, virtualizing network devices and creating secure communication channels without reconfiguring routers or switches, utilizing a central secure server to position the secure network channel and implementing protocols like IPsec and cryptographic functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocols like IPsec are implemented to protect sensitive data, then network security is improved, but network performance deteriorates due to workload intensity

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network security function by introducing a dedicated security blade server that handles security operations separately from the main network traffic flow. This segmentation allows security processing to occur in isolation, preventing it from bottlenecking the overall network performance while maintaining security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security blade server acts as an intermediary component between the network devices and the security protocol processing. It intercepts traffic that requires security operations, processes it through dedicated security functions, and returns the secured traffic to the main network flow, thereby protecting sensitive data without degrading overall network performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware is used to implement security protocols, then security operations can be performed, but device complexity increases due to numerous routing cables and physical connections

Engineering Contradiction:
Improvesecurity operation capabilityVSAvoidphysical connections
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security blade server is designed as a universal platform that can perform multiple security functions (IPsec, validation, cryptographic protocols) through software configuration rather than requiring dedicated hardware for each security function. This multi-functionality reduces the need for numerous separate hardware components and their associated physical connections.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of implementing security functions through complex physical hardware connections and routing cables, the patent uses virtualized security blade servers that replicate security capabilities through software. This virtualization approach copies the essential security functions in software form, eliminating the need for numerous physical connections while maintaining security operation capabilities.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10116622B2Secure communication channel using a blade server
Publication Date: 2018.10.30 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10116622B2 patent drawing
  • US10116622B2 patent drawing
  • US10116622B2 patent drawing

AI summary

Systems and methods to manage a network include a security blade server configured to perform a security operation on network traffic, and a controller configured to virtualize a plurality of network devices. The controller is further configured to program the network traffic to flow through the security blade server to create a secure network channel. A software defined environment may includes an application program interface (API) used to program the flow of the network traffic. The controller may use the API to virtually and selectively position the security blade server as waypoint for the network traffic.