Unified Network Proxy Layer for Application Policy Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data networks, the increasing number of network application proxies leads to redundant efforts and inconsistent handling, resulting in undesirable behavior, highlighting the need for a common network proxy layer to provide a consistent and efficient mechanism for processing data.

Innovation Solution

Implementing a network proxy layer that processes data efficiently and consistently across multiple application proxies, involving a method where connection establishment events and data packets are managed through a network interface module, with a state machine to handle client and server connections, and additional processing for security and service policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple network application proxies are deployed to handle different applications, then the network device can provide diverse application services, but redundant efforts and inconsistent handling occur leading to undesirable behavior

Engineering Contradiction:
Improveapplication service diversityVSAvoidhandling consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges multiple application proxies into a unified proxy structure where a single network application proxy handles multiple applications. This is achieved by introducing an application identifier parameter that allows the proxy to distinguish between different applications while maintaining a consistent handling mechanism, thereby eliminating redundant efforts and ensuring uniform processing across all applications.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The network application proxy is designed with multi-functionality to handle diverse applications through a single unified interface. By incorporating application-specific parameters (such as application identifiers) into the universal proxy framework, the system achieves versatility in supporting multiple applications while maintaining consistent and reliable handling through the same proxy mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple network application proxies are deployed to handle different applications, then the network device can provide diverse application services, but redundant processing effort increases

Engineering Contradiction:
Improveapplication service diversityVSAvoidprocessing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent combines multiple application proxies into one unified proxy that processes data for multiple applications simultaneously. This merging eliminates redundant processing efforts by avoiding duplicate data handling and security checks that would occur if separate proxies were used for each application, thereby improving overall processing efficiency while maintaining the ability to serve diverse applications.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified network application proxy is designed to perform multiple functions across different applications through a single processing pipeline. By using application identifiers to route and process data appropriately within the same proxy structure, the system achieves versatile application support without the overhead of multiple separate proxy instances, thus enhancing productivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a common network proxy layer is implemented to provide consistent handling, then processing efficiency and consistency improve, but the device complexity increases

Engineering Contradiction:
Improvehandling consistencyVSAvoidproxy layer structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the proxy functionality by introducing distinct parameters for different applications (such as application identifiers, security policies, and service parameters) while maintaining a unified proxy structure. This segmentation allows the common network proxy layer to handle multiple applications consistently without requiring separate proxy instances, thereby improving reliability while managing complexity through structured parameterization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The unified network application proxy acts as an intermediary between the network and multiple applications, mediating all communication through a single consistent interface. This intermediary approach ensures handling consistency across all applications while managing complexity by centralizing the proxy logic and using parameters to differentiate application-specific requirements, rather than duplicating proxy structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10230770B2Network proxy layer for policy-based application proxies
Publication Date: 2019.03.12 A10 NETWORKS INC
  • US10230770B2 patent drawing
  • US10230770B2 patent drawing
  • US10230770B2 patent drawing

AI summary

A system and method for providing a network proxy layer are disclosed. The network proxy layer may receive a connection establishment event for a client connection of an application session and send the client connection event to an application proxy for the application session, the application proxy being associated with an application of a server. Upon establishment of the client connection, the network proxy layer may receive one or more data packets from the client connection. The network proxy layer may further receive a connection establishment event for a server connection of the application session of the server, and receive one or more data packets from the server connection.