Virtualized Security Gateway Cluster for Load Sharing and High Availability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual system clusters face inefficiencies in resource utilization and management overhead due to the need for separate security systems and complex failover configurations, leading to potential service disruptions and increased costs in large enterprise networks.

Innovation Solution

A method for load sharing and high availability between virtual systems in a cluster of computers, where active and standby applications with synchronized state parameters and policies are used across multiple computers, enabling seamless failover and load balancing without managing connections, utilizing unicast data transfer for synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate security systems are deployed for each network segment, then comprehensive security is achieved, but system complexity and management overhead increase

Engineering Contradiction:
Improvecomprehensive securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple security functions (firewall, VPN, intrusion prevention) are merged into a single virtualized security platform that serves multiple network segments through virtual systems, eliminating the need for separate physical security devices for each segment

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The virtualized security platform provides universal security services across different network segments through virtual systems that can be configured to serve various VLANs and network segments with different security policies

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If failover configuration is implemented with standby systems, then high availability is improved, but service disruption risk increases during failover

Engineering Contradiction:
Improvehigh availabilityVSAvoidservice disruption risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Standby virtual systems are pre-configured with synchronized state parameters and policies before failure occurs, enabling immediate takeover without service disruption when primary systems fail

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Virtual systems maintain synchronized copies of state parameters and policies across standby instances, allowing seamless failover where the standby system can immediately assume the role of the failed primary system without loss of connectivity or service disruption

Inventive Principle:
Principle #26Copying

3Productivity

If multiple virtual systems run on same cluster member, then resource utilization improves, but failure impact increases when one virtual system fails

Engineering Contradiction:
Improveresource utilizationVSAvoidfailure impact
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Virtual systems are segmented into independent instances that can fail independently, with each virtual system having its own state parameters and policies that are synchronized separately, limiting the impact of one failure to only that specific virtual system

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7797566B2Application cluster in security gateway for high availability and load sharing
Publication Date: 2010.09.14 CHECK POINT SOFTWARE TECH LTD
  • US7797566B2 patent drawing
  • US7797566B2 patent drawing
  • US7797566B2 patent drawing

AI summary

A method for load sharing and high availability in a cluster of computers. The cluster includes a first computer and a second computer which perform a task An active application runs in the first computer and a standby application is installed in the second computer. The active application and the standby application are included in an application group. A first plurality of applications is installed in the first computer; the first plurality includes the running active application. The active application performs the task and stores in memory of the first computer state parameters and a policy. A synchronized copy of the state parameters and the policy pertaining to the task is maintained by storing in memory of the second computer. Preferably, the cluster is in a security gateway between data networks and performs a task related to security of one or more of the networks.