Security Device Flow ID Extraction for Bandwidth Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In networks with multiple stateful security devices, full flow information exchange generates significant bandwidth and hardware requirements, and alters routing paths, leading to increased latency and complexity.
Innovation Solution
A method where one security device determines if a packet is associated with a flow assigned to another device, allowing it to send the packet for processing without altering routing paths, and reduces bandwidth requirements by not exchanging full flow information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full flow information is exchanged between security devices, then security processing can be distributed across multiple devices, but bandwidth requirements and hardware requirements increase significantly
Solution Approach 1:
The patent extracts only the essential flow identification information (flow ID) from complete flow state information. Instead of exchanging full flow state data between security devices, the system uses a simplified flow ID that can be looked up to retrieve complete flow information locally at each device. This extraction principle reduces the amount of data exchanged while maintaining the ability to perform distributed security processing.
Solution Approach 2:
The patent introduces a flow ID as an intermediary element that mediates between the need for distributed security processing and the need to minimize data exchange. The flow ID acts as a reference key that allows security devices to identify and track flows without exchanging complete flow state information, thus reducing bandwidth requirements while enabling distributed processing.
2Reliability
If full flow information is exchanged between security devices, then security processing can be distributed across multiple devices, but hardware requirements increase significantly
Solution Approach 1:
The patent extracts only the essential flow identification information (flow ID) from complete flow state information. Instead of exchanging full flow state data between security devices, the system uses a simplified flow ID that can be looked up to retrieve complete flow information locally at each device. This extraction principle reduces the amount of data exchanged while maintaining the ability to perform distributed security processing.
Solution Approach 2:
The patent uses a lightweight flow ID copy that references the complete flow information stored locally at each security device. Rather than copying and exchanging entire flow state records, each device maintains local flow information and uses compact flow ID references for inter-device communication, reducing hardware bandwidth requirements while enabling distributed processing.
3Reliability
If security devices synchronize by sending state information, then high availability and reliability are achieved, but routing paths are altered and latency increases
Solution Approach 1:
The patent extracts only the essential flow identification information (flow ID) from complete flow state information. Instead of exchanging full flow state data between security devices, the system uses a simplified flow ID that can be looked up to retrieve complete flow information locally at each device. This extraction principle reduces the amount of data exchanged while maintaining the ability to perform distributed security processing.
4Reliability
If security devices synchronize by sending state information, then high availability and reliability are achieved, but network configuration complexity increases
Solution Approach 1:
The patent extracts only the essential flow identification information (flow ID) from complete flow state information. Instead of exchanging full flow state data between security devices, the system uses a simplified flow ID that can be looked up to retrieve complete flow information locally at each device. This extraction principle reduces the amount of data exchanged while maintaining the ability to perform distributed security processing.
Data Source
AI summary
Methods, systems, and apparatus, including computer program products, featuring receiving at a first security device a packet. The first security device determines that the packet is associated with a flow assigned to a distinct second security device. The first security device sends the packet to the second security device. After the second security device performs security processing using the packet, the first security device receives from the second security device a message regarding the packet. The first security device transmits the packet.


