Selective Traffic Processing in Distributed Cloud Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed cloud computing networks face challenges in efficiently managing and securing traffic, particularly in protecting against denial of service attacks and ensuring compliance with regional data processing regulations, due to the complexity of routing and processing traffic across geographically distributed servers.

Innovation Solution

The implementation of selective traffic processing in a distributed cloud computing network, where edge servers are configured to process traffic based on specific rules and identities, allowing only permitted servers to handle traffic beyond layer 3 and 4 processing, including decryption and higher-layer services, while ensuring compliance with regional data processing requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If all edge servers in the distributed cloud computing network are configured to process traffic beyond layer 3 and 4, then the network can provide comprehensive higher-layer services and decryption capabilities, but the security risk increases and compliance with regional data processing regulations becomes difficult to ensure

Engineering Contradiction:
Improvetraffic processing capabilityVSAvoidsecurity and compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by configuring different edge servers with different processing capabilities based on their location and authorization status. Some edge servers are authorized to process traffic beyond layer 3 and 4, while others are restricted to lower-layer processing only. This selective configuration ensures that sensitive operations occur only in compliant, authorized locations while maintaining comprehensive service coverage across the distributed network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the traffic processing functionality across different edge servers rather than uniform distribution. By dividing the network into authorized and non-authorized processing zones, the system can provide comprehensive services overall while ensuring that specific sensitive operations occur only in compliant regions, thus resolving the contradiction between versatility and security.

Inventive Principle:
Principle #1Segmentation

2Speed

If edge servers are geographically distributed throughout the world, then content delivery speed increases and latency decreases, but the complexity of managing selective traffic processing and ensuring regional compliance increases

Engineering Contradiction:
Improvecontent delivery speedVSAvoidtraffic management complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling edge servers to autonomously determine their own traffic processing capabilities based on their configuration. Each edge server can independently assess whether it is authorized to process specific types of traffic, eliminating the need for complex centralized real-time coordination and reducing the management overhead despite geographic distribution.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring edge servers with their authorized processing capabilities before traffic arrives. This advance configuration allows servers to make immediate local decisions about traffic processing without requiring complex real-time management, thus maintaining high delivery speed while simplifying ongoing operational complexity.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If edge servers process all types of traffic, then network performance is optimized, but the risk of DDoS attacks and security breaches increases

Engineering Contradiction:
Improvenetwork performanceVSAvoidDDoS attack risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary layer of authorization and configuration management that mediates between traffic sources and edge servers. This intermediary control mechanism determines which servers can process which types of traffic, creating a security filter that maintains network performance by allowing legitimate traffic processing while blocking or redirecting potentially harmful traffic before it reaches vulnerable servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240244078A1Selective traffic processing in a distributed cloud computing network
Publication Date: 2024.07.18 CLOUDFLARE INC
  • US20240244078A1 patent drawing
  • US20240244078A1 patent drawing
  • US20240244078A1 patent drawing

AI summary

A server receives internet traffic from a client device. The server is one of multiple servers of a distributed cloud computing network which are each associated with a set of server identity(ies) including a server/data center certification identity. The server processes, at layer 3, the internet traffic including participating in a layer 3 DDoS protection service. If the traffic is not dropped by the layer 3 DDoS protection service, further processing is performed. The server determines whether it is permitted to process the traffic at layers 5-7 including whether it is associated with a server/data center certification identity that meets a selected criteria for the destination of the internet traffic. If the server does not meet the criteria, it transmits the traffic to another one of the multiple servers for processing the traffic at layers 5-7.