Security Device Flow ID Extraction for Bandwidth Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networks with multiple stateful security devices, full flow information exchange generates significant bandwidth and hardware requirements, and alters routing paths, leading to increased latency and complexity.

Innovation Solution

A method where one security device determines if a packet is associated with a flow assigned to another device, allowing it to send the packet for processing without altering routing paths, and reduces bandwidth requirements by not exchanging full flow information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full flow information is exchanged between security devices, then security processing can be distributed across multiple devices, but bandwidth requirements and hardware requirements increase significantly

Engineering Contradiction:
Improvesecurity processing distributionVSAvoidbandwidth requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential flow identification information (flow ID) from complete flow state information. Instead of exchanging full flow state data between security devices, the system uses a simplified flow ID that can be looked up to retrieve complete flow information locally at each device. This extraction principle reduces the amount of data exchanged while maintaining the ability to perform distributed security processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a flow ID as an intermediary element that mediates between the need for distributed security processing and the need to minimize data exchange. The flow ID acts as a reference key that allows security devices to identify and track flows without exchanging complete flow state information, thus reducing bandwidth requirements while enabling distributed processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full flow information is exchanged between security devices, then security processing can be distributed across multiple devices, but hardware requirements increase significantly

Engineering Contradiction:
Improvesecurity processing distributionVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential flow identification information (flow ID) from complete flow state information. Instead of exchanging full flow state data between security devices, the system uses a simplified flow ID that can be looked up to retrieve complete flow information locally at each device. This extraction principle reduces the amount of data exchanged while maintaining the ability to perform distributed security processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses a lightweight flow ID copy that references the complete flow information stored locally at each security device. Rather than copying and exchanging entire flow state records, each device maintains local flow information and uses compact flow ID references for inter-device communication, reducing hardware bandwidth requirements while enabling distributed processing.

Inventive Principle:
Principle #26Copying

3Reliability

If security devices synchronize by sending state information, then high availability and reliability are achieved, but routing paths are altered and latency increases

Engineering Contradiction:
Improvehigh availabilityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the essential flow identification information (flow ID) from complete flow state information. Instead of exchanging full flow state data between security devices, the system uses a simplified flow ID that can be looked up to retrieve complete flow information locally at each device. This extraction principle reduces the amount of data exchanged while maintaining the ability to perform distributed security processing.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If security devices synchronize by sending state information, then high availability and reliability are achieved, but network configuration complexity increases

Engineering Contradiction:
Improvehigh availabilityVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential flow identification information (flow ID) from complete flow state information. Instead of exchanging full flow state data between security devices, the system uses a simplified flow ID that can be looked up to retrieve complete flow information locally at each device. This extraction principle reduces the amount of data exchanged while maintaining the ability to perform distributed security processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9391954B2Security processing in active security devices
Publication Date: 2016.07.12 PALO ALTO NETWORKS INC
  • US9391954B2 patent drawing
  • US9391954B2 patent drawing
  • US9391954B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer program products, featuring receiving at a first security device a packet. The first security device determines that the packet is associated with a flow assigned to a distinct second security device. The first security device sends the packet to the second security device. After the second security device performs security processing using the packet, the first security device receives from the second security device a message regarding the packet. The first security device transmits the packet.