Shared Forwarding Plane for Routing and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High-end network devices that combine routing and firewall functions experience high latency due to packets traversing multiple forwarding paths, making it difficult to enforce strict quality of service (QoS) for applications like VoIP and multimedia, and struggle with increased data traffic processing.

Innovation Solution

A high-end network device with a shared forwarding plane that integrates routing and security components, allowing trusted communications to bypass the security component and be processed directly by the routing components, thereby unifying the routing and firewall 'fast path' into a single streamlined forwarding path.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packets are processed through separate forwarding planes for routing and security functions, then security inspection is performed, but latency increases due to multiple traversals

Engineering Contradiction:
Improvesecurity inspectionVSAvoidpacket forwarding latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the routing forwarding plane and security forwarding plane into a single unified forwarding plane. This allows packets to be processed through a single path that handles both routing and security functions simultaneously, eliminating the need for multiple traversals and reducing latency while maintaining security inspection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified forwarding plane is designed to perform multiple functions - both routing forwarding and security inspection - within a single structure. This multi-functional approach allows the system to handle diverse packet processing requirements without requiring separate dedicated paths, thereby reducing overall forwarding latency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple service cards process packet flows with detailed inspection, then security services are applied, but forwarding capacity is reduced

Engineering Contradiction:
Improvesecurity servicesVSAvoidforwarding capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments packet processing into two categories: new flows that require detailed security inspection and established flows that can use faster forwarding. This segmentation allows the system to apply security services where necessary while maintaining high forwarding capacity for routine traffic, thus balancing security requirements with overall system productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts packet forwarding paths based on flow state. Initial packets of new flows are directed to service cards for security inspection, while subsequent packets of established flows are forwarded through the optimized unified forwarding plane. This dynamic approach ensures security services are applied when needed while maximizing forwarding capacity for established traffic.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8339959B1Streamlined packet forwarding using dynamic filters for routing and security in a shared forwarding plane
Publication Date: 2012.12.25 JUNIPER NETWORKS INC
  • US8339959B1 patent drawing
  • US8339959B1 patent drawing
  • US8339959B1 patent drawing

AI summary

A network router includes a plurality of interfaces configured to send and receive packets, and a routing component comprising: (i) a routing engine that includes a control unit that executes a routing protocol to maintain routing information specifying routes through a network, and (ii) a forwarding plane configured by the routing engine to select next hops for the packets in accordance with the routing information. The forwarding plane comprises a switch fabric to forward the packets to the interfaces based on the selected next hops. The network router also includes a security plane configured to apply security functions to the packets. The security plane is integrated within the network router to share a streamlined forwarding plane of the routing component.