Virtual Network Appliance Insertion via Packet Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer networks, physically reconnecting network cables to add or insert network appliances like IPS and WAN accelerators is cumbersome and limits their placement in the data path, especially in dynamic environments.

Innovation Solution

The implementation of a virtual insertion module that allows network appliances to be dynamically inserted into the data path using data taps and application path descriptors, enabling them to receive and reinject packets in their original form without physical re-cabling, utilizing components like virtual insertion modules, interception modules, and forwarding circuitry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network appliances are physically connected to the network using cables, then reliable data transmission is achieved, but flexibility and ease of placement are reduced

Engineering Contradiction:
Improveease of placementVSAvoidphysical re-cabling complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

A network device acts as an intermediary between the data path and network appliances. The network device intercepts data packets and forwards them to network appliances for processing, eliminating the need for physical re-cabling. This mediator approach allows appliances to be dynamically added or removed without disrupting the physical network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a logical copy of the data path through the network device. Instead of physically altering the network topology, the network device copies packets to network appliances while maintaining the original data flow path. This allows multiple appliances to receive identical packet copies without requiring separate physical connections for each appliance.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If network appliances are physically inserted into the data path, then direct packet access is achieved, but adaptability to dynamic environments is reduced

Engineering Contradiction:
Improveadaptability to dynamic environmentsVSAvoidtime for physical reconfiguration
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system implements dynamic placement of network appliances through software configuration rather than fixed physical connections. Network appliances can be dynamically added, removed, or moved between different data paths by modifying routing rules in the network device, allowing rapid adaptation to changing network requirements without time-consuming physical reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The network device pre-establishes interception points and forwarding rules that enable rapid deployment of network appliances. When a new appliance needs to be added, the system can quickly activate pre-configured data taps and routing rules, eliminating the need for time-consuming physical cable reconnections and allowing immediate operational readiness.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If policy based routing is used to forward packets, then packet forwarding flexibility is improved, but packet modification occurs which may not be desired

Engineering Contradiction:
Improvepacket forwarding flexibilityVSAvoidpacket form integrity
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The packet handling process is segmented into distinct stages: interception, forwarding to appliance, and re-injection. The network device intercepts packets at a specific point in the data path, forwards them to network appliances for processing, and then re-injects them back into the data path. This segmentation allows the appliance to receive packets in their original form without policy-based routing modifications, while still achieving flexible forwarding through the interception and re-injection mechanism.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10044643B2Virtual insertion into a network
Publication Date: 2018.08.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10044643B2 patent drawing
  • US10044643B2 patent drawing
  • US10044643B2 patent drawing

AI summary

A network appliance is virtually inserted in a data path within a network. Packet data that matches a criteria is intercepted at a logical point within the data path. The intercepted packet data is forwarded to an application running on the virtually inserted network appliance.