Unified Packet Forwarding Rule Definition System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network interface devices face conflicts and increased latency due to separate implementation of security and traffic management functions, leading to miscommunication and redundant packet classification.
Innovation Solution
A method and apparatus that integrate security and traffic management rules through management and coordination logic, allowing for the definition of rules for packet forwarding devices, reducing conflicts and processor load by enabling simultaneous configuration and notification of security and traffic management engines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If security and traffic management functions are implemented by two separate network devices or logical components configured independently, then each function can be configured separately by different personnel, but miscommunication between personnel leads to conflict during operation and packet classification is performed twice adding to processor load and increasing latency
Solution Approach 1:
The patent combines security rules and traffic management rules into a unified policy set that is configured and stored together in a configuration database. The packet forwarding device integrates both security engine and quality of service engine to process packets through a single classification operation that serves both functions simultaneously, eliminating redundant processing and reducing latency.
Solution Approach 2:
The unified policy configuration system serves multiple functions: it stores both security and traffic management rules, notifies both security and quality of service engines of rule changes, and enables a single packet classification operation to satisfy both security filtering and traffic management requirements.
2Reliability
If security and traffic management functions are implemented by two separate network devices or logical components, then each function can operate independently, but packet classification is performed twice which adds to processor load
Solution Approach 1:
The patent merges security and traffic management into a single integrated system where one packet classification operation feeds both the security engine and quality of service engine. The unified policy configuration and single classification process reduces processor load while maintaining reliable independent operation of both functions through separate engine implementations.
3Adaptability or versatility
If separate configuration of security and traffic management rules is used, then configuration flexibility is maintained, but conflicts occur during operation due to miscommunication between personnel
Solution Approach 1:
The patent combines security and traffic management rule configuration into a unified policy management system. A single configuration process creates both security rules and traffic management rules that are stored together in the configuration database, ensuring consistency and eliminating conflicts that arise from independent configuration by different personnel.
Solution Approach 2:
The system implements feedback mechanisms where the management logic notifies both the security engine and quality of service engine when new rules are stored in the configuration database. This coordinated notification ensures both functions receive consistent configuration information and operate without conflicts.
Data Source
AI summary
There are methods and apparatus, including computer program products, for defining a policy including a set of rules for a packet forwarding device by receiving information sufficient to enable a first rule related to one of security or traffic management to be defined, and based on the received information, enabling a corresponding second rule related to the other one of security or traffic management to be defined.


