Shared Forwarding Plane for Routing and Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
High-end network devices that combine routing and firewall functions experience high latency due to packets traversing multiple forwarding paths, making it difficult to enforce strict quality of service (QoS) for applications like VoIP and multimedia, and struggle with increased data traffic processing.
Innovation Solution
A high-end network device with a shared forwarding plane that integrates routing and security components, allowing trusted communications to bypass the security component and be processed directly by the routing components, thereby unifying the routing and firewall 'fast path' into a single streamlined forwarding path.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packets are processed through separate forwarding planes for routing and security functions, then security inspection is performed, but latency increases due to multiple traversals
Solution Approach 1:
The patent merges the routing forwarding plane and security forwarding plane into a single unified forwarding plane. This allows packets to be processed through a single path that handles both routing and security functions simultaneously, eliminating the need for multiple traversals and reducing latency while maintaining security inspection capabilities.
Solution Approach 2:
The unified forwarding plane is designed to perform multiple functions - both routing forwarding and security inspection - within a single structure. This multi-functional approach allows the system to handle diverse packet processing requirements without requiring separate dedicated paths, thereby reducing overall forwarding latency.
2Reliability
If multiple service cards process packet flows with detailed inspection, then security services are applied, but forwarding capacity is reduced
Solution Approach 1:
The patent segments packet processing into two categories: new flows that require detailed security inspection and established flows that can use faster forwarding. This segmentation allows the system to apply security services where necessary while maintaining high forwarding capacity for routine traffic, thus balancing security requirements with overall system productivity.
Solution Approach 2:
The system dynamically adjusts packet forwarding paths based on flow state. Initial packets of new flows are directed to service cards for security inspection, while subsequent packets of established flows are forwarded through the optimized unified forwarding plane. This dynamic approach ensures security services are applied when needed while maximizing forwarding capacity for established traffic.
Data Source
AI summary
A network router includes a plurality of interfaces configured to send and receive packets, and a routing component comprising: (i) a routing engine that includes a control unit that executes a routing protocol to maintain routing information specifying routes through a network, and (ii) a forwarding plane configured by the routing engine to select next hops for the packets in accordance with the routing information. The forwarding plane comprises a switch fabric to forward the packets to the interfaces based on the selected next hops. The network router also includes a security plane configured to apply security functions to the packets. The security plane is integrated within the network router to share a streamlined forwarding plane of the routing component.


