WAN Accelerator Bridging Mechanism for Security Gateway Interoperability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network packet processing devices operating at different levels of the network stack, such as WAN accelerators and security gateways, are not interoperable, preventing seamless communication and policy application across layers.

Innovation Solution

A method and system that bridge network packet processing between a WAN acceleration program operating at the data link layer and a security gateway program operating at the network layer, allowing packets to traverse and be processed at upper layers, ensuring transparency and concurrent operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a WAN acceleration device intercepts network communications at layer 2 of the network stack, then transparent packet forwarding is achieved, but the device cannot interoperable with security gateway devices operating at layer 3

Engineering Contradiction:
Improvetransparent packet forwardingVSAvoidinteroperability with security gateway
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a bridging mechanism that acts as an intermediary between layer 2 WAN acceleration and layer 3 security gateway operations. The system modifies packet handling to enable cross-layer communication, allowing layer 2 accelerated packets to be forwarded to layer 3 security processing and vice versa, thus resolving the interoperability issue while maintaining transparency

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intermediary device is designed to perform multiple functions across different network layers simultaneously. It can intercept and accelerate packets at layer 2 while also processing and applying security policies at layer 3, making the device adaptable to both WAN acceleration and security gateway operations without requiring separate dedicated devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If network processing programs operate at different levels of the network stack, then specialized functionality is achieved, but interoperability between programs is prevented

Engineering Contradiction:
Improvespecialized functionalityVSAvoidinteroperability complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a bridging layer that mediates between layer 2 and layer 3 processing programs. This intermediary component translates and forwards packets between different network stack levels, enabling specialized layer 2 acceleration and layer 3 security processing to work together without direct complex interactions between the specialized programs

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network packet processing into distinct layer 2 and layer 3 processing stages, with each stage handling its specialized function independently. The bridging mechanism connects these segmented stages, allowing each program to maintain its specialized functionality while enabling controlled interaction through the bridge

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9210081B2Systems and methods for bridging a WAN accelerator with a security gateway
Publication Date: 2015.12.08 CITRIX SYSTEMS INC
  • US9210081B2 patent drawing
  • US9210081B2 patent drawing
  • US9210081B2 patent drawing

AI summary

The solution described herein provides systems and methods for the interoperability of network processing programs that process network packets at different levels of the network stack. This solution bridges the communications of a network packet between a first network processing program operating at a first level of a network stack in an intermediary and a second network processing program operating at a second level of the network stack of the intermediary. The first network processing program may modify an incoming network packet so that the packet may traverse the network stack to an upper level of the stack to the second network processing program. After processing the network packet at the upper layers of the stack or by the second network processing program, the first network processing program modifies the network pack in order to transmit the packet to the intended destination while traversing the intermediary.