Autonomous Security Service Migration via Session Table Copying
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for scaling security services in communication networks are labor-intensive and often result in disruptions to services, making them undesirable for network operators due to the time and effort required to transfer security services from one access point to another.
Innovation Solution
A method and system for autonomously migrating security services from one service edge to another within a communication network, utilizing a session table and priority values to maintain continuous communication sessions and minimize disruptions, allowing for seamless scaling of security services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If security services are migrated from one service edge to another using traditional methods, then service scaling is achieved, but labor intensity and service disruption increase
Solution Approach 1:
The system enables autonomous service migration where the network infrastructure automatically copies session tables and migrates security service instances between service edges without requiring manual administrator intervention. The migration process is self-executed through automated provisioning systems that handle service edge selection, session table copying, and service instance migration.
Solution Approach 2:
The invention utilizes session table copying as a core mechanism to enable service migration. The session table, which contains communication information about active sessions, is copied from the source service edge to the target service edge, allowing seamless service continuity during migration without requiring manual reconfiguration.
2Adaptability or versatility
If security services are migrated from one service edge to another using traditional methods, then service scaling is achieved, but service disruption increases
Solution Approach 1:
The system performs preliminary actions by copying the session table to the target service edge before actually migrating the security service instance. This ensures that all session information is prepared in advance, and the migration can proceed seamlessly without disrupting active communications. The target service edge is pre-configured with necessary session data before taking over service responsibilities.
Solution Approach 2:
The invention maintains continuous service availability during migration by ensuring that session tables and active communication sessions remain uninterrupted. The migration process is designed to preserve service continuity where the target service edge assumes responsibilities from the source service edge without breaking active sessions, thereby maintaining reliable and continuous network security services.
3Ease of operation
If security services are consolidated to one network access point, then service management is simplified, but migration complexity and service disruption increase
Solution Approach 1:
The invention creates a universal migration framework that can be applied regardless of the number of service edges or their geographic distribution. The automated provisioning system and session table copying mechanism provide a standardized approach that works for consolidating services to a single access point or distributing them across multiple access points, making the migration process consistent and manageable regardless of the target architecture.
Data Source
AI summary
Apparatus, systems, methods, and the like, for autonomous scaling of security and other network services through initialization of a service from a network service device and/or migration of such services from one service device to another is provided. Such network scaling may allow for migration of services from existing service edges to other service edges. A security management system may coordinate the migration of services provided to a secondary network from one or more service edges to another, separate service edge while providing session synchronization during the migration. To migrate the services from the first service edge to a second service edge, a session table may be shared between the service edges and the first and second service edges may advertise service routes or endpoints with one or more priority values to control or otherwise determine which service edge is selected by a service-receiving device to receive the services.


