ACL Policy Compression for Intent-Based Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security policies based on IP Access Control Lists (ACLs) are inefficient for migration to intent-based management systems like Cisco's Digital Network Architecture Centers (DNA-C), as they require manual conversion and are difficult to manage and configure, especially in large networks with heavy traffic.
Innovation Solution
An iterative compression scheme is applied to conventional IP-based Access Control Entries to convert them into Object-Group or Security-Group based Access Control Entries, reducing the need for individual IP address and protocol definitions, thereby simplifying configuration and improving network performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If IP-based ACLs are used for network security policies, then detailed packet-level control is achieved, but policy complexity and difficulty of management increase significantly
Solution Approach 1:
The patent segments the complex policy management task into two distinct layers: (1) High-level intent-based policy definitions that capture security objectives in natural language, and (2) Automated conversion to detailed IP-based ACL rules. This segmentation allows administrators to work at the simpler intent layer while the system handles the complex translation to packet-level rules.
Solution Approach 2:
The patent introduces an intermediary conversion mechanism that translates between intent-based policies and traditional IP-based ACLs. This intermediary layer acts as a mediator that automatically converts high-level security intents into detailed packet-level rules, eliminating the need for administrators to manually configure complex ACLs while maintaining precise packet-level control.
2Manufacturing precision
If manual conversion of ACLs to intent-based policies is performed, then policy accuracy is maintained, but migration time and operational overhead increase
Solution Approach 1:
The patent performs preliminary analysis and classification of existing ACL rules before conversion. By pre-processing the ACL data to identify patterns, groupings, and relationships, the system prepares the information in advance for accurate intent-based policy generation, ensuring both precision and efficiency in the migration process.
Solution Approach 2:
The patent creates automated templates and models for policy conversion that can be repeatedly applied. Once the conversion logic is established, it can be copied and applied to multiple ACL sets, maintaining consistency and accuracy across migrations while significantly reducing the time required for each conversion operation.
3Measurement precision
If individual IP addresses and protocols are defined in ACLs, then granular security control is achieved, but storage requirements and processing overhead increase
Solution Approach 1:
The patent merges multiple individual IP address definitions and protocol specifications into consolidated intent-based policy groups. By grouping related security rules and consolidating redundant definitions, the system maintains granular control capabilities while significantly reducing the volume of configuration data that needs to be stored and processed.
Solution Approach 2:
The patent creates universal intent-based policy templates that can serve multiple specific security requirements. A single intent-based policy definition can encompass multiple individual IP and protocol rules, making the policy multi-functional and reducing overall configuration data volume while maintaining the ability to apply granular security control across different contexts.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Present technology is directed to a system and method for implementing an offline scheme to automatically and efficiently transform a set of conventional IP-based Access Control Entries in a supplied configuration into compressed form that can then be represented as Object-Group based Access Control Entries. The compression is performed on contiguous blocks of the supplied Access Control List having a common prescribed filtering access. The compression is performed by iteratively selecting a data field with mismatching data values across the ACEs and merging the data values into a corresponding data field of the output ACE. The common values of other data fields are then imported to the corresponding data fields of the output ACE. The process is repeated in an iterative manner by assigning a different data field as the selected data field for each iteration round.