Selective Encryption for Call Distribution Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication networks face inefficiencies due to duplicative processing across different network elements, leading to network inefficiencies, especially with the increasing bandwidth demands of user-plane traffic, where most traffic is already encrypted end-to-end, rendering additional encryption between points unnecessary.

Innovation Solution

Implementing systems and methods for selectively applying encryption based on the direction, prior encryption status, and complexity of network traffic, focusing on downstream and upstream traffic, and using hardware accelerators to determine the need for encryption, thereby reducing unnecessary processing and resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied at every network element, then security is improved, but network efficiency deteriorates due to duplicative processing

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the parameter of encryption application from universal (all traffic) to selective (only when needed). By detecting whether traffic is already encrypted and adjusting encryption application accordingly, the system maintains security while eliminating duplicative processing. This parameter change enables the system to adapt encryption behavior based on traffic conditions, resolving the contradiction between security and efficiency.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements self-service by having network elements automatically detect the encryption status of incoming traffic and make independent decisions about whether to apply encryption. This eliminates the need for manual configuration and allows each network element to optimize its own processing based on real-time traffic characteristics, thereby improving efficiency while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If encryption is applied to all network traffic, then security is improved, but processing load increases unnecessarily

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by treating different types of traffic differently based on their specific characteristics. Instead of applying uniform encryption to all traffic, the system examines individual traffic flows to determine their encryption status and applies encryption only where necessary. This localized approach reduces processing load on unnecessary encryption operations while maintaining security where required.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by applying encryption only to the extent necessary - specifically, only to unencrypted traffic that requires protection. By detecting the encryption status and applying encryption selectively rather than universally, the system avoids excessive processing load on already-encrypted traffic while maintaining adequate security coverage for traffic that needs protection.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If network elements apply processing to all traffic, then security coverage is improved, but network bandwidth efficiency deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidbandwidth efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the encryption function from universal application and isolates it to only where needed. By detecting traffic characteristics and extracting encryption processing from the general processing pipeline for already-encrypted traffic, the system maintains security coverage for critical traffic while eliminating unnecessary processing overhead that would consume network bandwidth resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240236659A1Systems and methods for enhancing efficiency in call distribution
Publication Date: 2024.07.11 FORTINET INC
  • US20240236659A1 patent drawing
  • US20240236659A1 patent drawing
  • US20240236659A1 patent drawing

AI summary

Various approaches for call distribution in a communication network are discussed. In some embodiments, systems and methods for enhancing call distribution efficiency are discussed that include selective encryption application.