Unified Packet Forwarding Rule Definition System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network interface devices face conflicts and increased latency due to separate implementation of security and traffic management functions, leading to miscommunication and redundant packet classification.

Innovation Solution

A method and apparatus that integrate security and traffic management rules through management and coordination logic, allowing for the definition of rules for packet forwarding devices, reducing conflicts and processor load by enabling simultaneous configuration and notification of security and traffic management engines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security and traffic management functions are implemented by two separate network devices or logical components configured independently, then each function can be configured separately by different personnel, but miscommunication between personnel leads to conflict during operation and packet classification is performed twice adding to processor load and increasing latency

Engineering Contradiction:
ImproveIndependent configuration of security and traffic management functionsVSAvoidLatency due to redundant packet classification
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent combines security rules and traffic management rules into a unified policy set that is configured and stored together in a configuration database. The packet forwarding device integrates both security engine and quality of service engine to process packets through a single classification operation that serves both functions simultaneously, eliminating redundant processing and reducing latency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified policy configuration system serves multiple functions: it stores both security and traffic management rules, notifies both security and quality of service engines of rule changes, and enables a single packet classification operation to satisfy both security filtering and traffic management requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security and traffic management functions are implemented by two separate network devices or logical components, then each function can operate independently, but packet classification is performed twice which adds to processor load

Engineering Contradiction:
ImproveIndependent operation of security and traffic management functionsVSAvoidProcessor load from redundant classification
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges security and traffic management into a single integrated system where one packet classification operation feeds both the security engine and quality of service engine. The unified policy configuration and single classification process reduces processor load while maintaining reliable independent operation of both functions through separate engine implementations.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If separate configuration of security and traffic management rules is used, then configuration flexibility is maintained, but conflicts occur during operation due to miscommunication between personnel

Engineering Contradiction:
ImproveConfiguration flexibility of security and traffic management rulesVSAvoidOperational conflicts from miscommunication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent combines security and traffic management rule configuration into a unified policy management system. A single configuration process creates both security rules and traffic management rules that are stored together in the configuration database, ensuring consistency and eliminating conflicts that arise from independent configuration by different personnel.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where the management logic notifies both the security engine and quality of service engine when new rules are stored in the configuration database. This coordinated notification ensures both functions receive consistent configuration information and operate without conflicts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8069244B2Method for defining a set of rules for a packet forwarding device
Publication Date: 2011.11.29 BARRACUDA NETWORKS INC
  • US8069244B2 patent drawing
  • US8069244B2 patent drawing
  • US8069244B2 patent drawing

AI summary

There are methods and apparatus, including computer program products, for defining a policy including a set of rules for a packet forwarding device by receiving information sufficient to enable a first rule related to one of security or traffic management to be defined, and based on the received information, enabling a corresponding second rule related to the other one of security or traffic management to be defined.