3D Visualization of Group-Based Network Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based networking faces challenges in managing and visualizing conflicting policies across geographically distributed networks, making it difficult to understand and resolve network conflicts effectively.
Innovation Solution
The system visualizes group-based policies using three-dimensional and two-dimensional user interfaces, displaying policy rules related to destination and source IP addresses and access ports, allowing users to intuitively understand policy conflicts and adjust them to prevent overlaps, with real-time traffic flow visualization and automatic conflict resolution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If cloud-based networking policies are implemented across geographically distributed networks, then network coverage and connectivity are improved, but policy management complexity and conflict detection difficulty increase
Solution Approach 1:
The patent applies dimensionality change by representing policies in a multi-dimensional space where each dimension corresponds to a policy parameter (source IP, destination IP, port, protocol). This transformation allows complex policy relationships to be visualized and analyzed geometrically, resolving the contradiction by making hidden conflicts visible through spatial representation rather than traditional flat configuration interfaces.
Solution Approach 2:
The patent introduces a policy visualization interface as an intermediary between network administrators and the complex policy management system. This intermediary translates abstract policy rules into visual representations, allowing administrators to manage distributed network policies without directly confronting the underlying complexity, thus reducing perceived management difficulty while maintaining comprehensive coverage.
2Adaptability or versatility
If multiple policy rules are configured across distributed networks, then network functionality and access control are improved, but policy conflicts and overlaps increase
Solution Approach 1:
The patent implements preliminary anti-action by detecting and visualizing policy conflicts before they take effect in the network. The system analyzes policy relationships in advance, identifies overlapping or contradictory rules, and presents them to administrators for resolution before deployment, preventing harmful conflicts from occurring in the live network environment.
Solution Approach 2:
The patent employs feedback mechanisms by continuously monitoring policy interactions and providing real-time visual feedback about conflicts and overlaps. When policies are modified or new policies are added, the system automatically re-evaluates relationships and notifies administrators of any emerging conflicts, enabling continuous optimization of network functionality while minimizing harmful policy interactions.
3Measurement precision
If detailed policy rules are implemented for precise control, then access control precision is improved, but difficulty in visualizing and managing policies increases
Solution Approach 1:
The patent applies copying by creating visual representations (copies) of detailed policy rules in a simplified graphical format. Instead of requiring administrators to directly manipulate complex text-based policy configurations, the system generates visual copies that preserve the precise control logic while presenting it in an intuitive format, making detailed policies easier to visualize and manage without sacrificing access control precision.
Data Source
AI summary
Systems, methods, and non-transitory computer-readable storage media for visualizing current and historical access policy of a group based policy. A first group based policy and a second group based policy are received at a computing device, where each group based policy includes policy rules defining a range of destination internet protocol addresses, a range of source internet protocol addresses and a range of access ports. The computing device renders a three dimensional representation of the first group based policy, based on the policy rules of the first group based policy. The computing device renders a three dimensional representation of the second group based policy, based on the policy rules of the second group based policy. The computing device displays the representations of the first group based policy and second group based policy on a graphical interface.


