ACL Policy Compression for Intent-Based Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security policies based on IP Access Control Lists (ACLs) are inefficient for migration to intent-based management systems like Cisco's Digital Network Architecture Centers (DNA-C), as they require manual conversion and are difficult to manage and configure, especially in large networks with heavy traffic.

Innovation Solution

An iterative compression scheme is applied to conventional IP-based Access Control Entries to convert them into Object-Group or Security-Group based Access Control Entries, reducing the need for individual IP address and protocol definitions, thereby simplifying configuration and improving network performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If IP-based ACLs are used for network security policies, then detailed packet-level control is achieved, but policy complexity and difficulty of management increase significantly

Engineering Contradiction:
Improvepacket-level control precisionVSAvoidpolicy configuration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex policy management task into two distinct layers: (1) High-level intent-based policy definitions that capture security objectives in natural language, and (2) Automated conversion to detailed IP-based ACL rules. This segmentation allows administrators to work at the simpler intent layer while the system handles the complex translation to packet-level rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary conversion mechanism that translates between intent-based policies and traditional IP-based ACLs. This intermediary layer acts as a mediator that automatically converts high-level security intents into detailed packet-level rules, eliminating the need for administrators to manually configure complex ACLs while maintaining precise packet-level control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If manual conversion of ACLs to intent-based policies is performed, then policy accuracy is maintained, but migration time and operational overhead increase

Engineering Contradiction:
Improvepolicy conversion accuracyVSAvoidmigration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis and classification of existing ACL rules before conversion. By pre-processing the ACL data to identify patterns, groupings, and relationships, the system prepares the information in advance for accurate intent-based policy generation, ensuring both precision and efficiency in the migration process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates automated templates and models for policy conversion that can be repeatedly applied. Once the conversion logic is established, it can be copied and applied to multiple ACL sets, maintaining consistency and accuracy across migrations while significantly reducing the time required for each conversion operation.

Inventive Principle:
Principle #26Copying

3Measurement precision

If individual IP addresses and protocols are defined in ACLs, then granular security control is achieved, but storage requirements and processing overhead increase

Engineering Contradiction:
Improvesecurity control granularityVSAvoidconfiguration data volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent merges multiple individual IP address definitions and protocol specifications into consolidated intent-based policy groups. By grouping related security rules and consolidating redundant definitions, the system maintains granular control capabilities while significantly reducing the volume of configuration data that needs to be stored and processed.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal intent-based policy templates that can serve multiple specific security requirements. A single intent-based policy definition can encompass multiple individual IP and protocol rules, making the policy multi-functional and reducing overall configuration data volume while maintaining the ability to apply granular security control across different contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3884641B1Apparatus and method for migrating existing access control list policies to intent based policies and vice versa
Publication Date: 2024.01.10 CISCO TECHNOLOGY INC
  • EP3884641B1 patent drawingFigure 1
  • EP3884641B1 patent drawingFigure 2
  • EP3884641B1 patent drawingFigure 3

AI summary

Present technology is directed to a system and method for implementing an offline scheme to automatically and efficiently transform a set of conventional IP-based Access Control Entries in a supplied configuration into compressed form that can then be represented as Object-Group based Access Control Entries. The compression is performed on contiguous blocks of the supplied Access Control List having a common prescribed filtering access. The compression is performed by iteratively selecting a data field with mismatching data values across the ACEs and merging the data values into a corresponding data field of the output ACE. The common values of other data fields are then imported to the corresponding data fields of the output ACE. The process is repeated in an iterative manner by assigning a different data field as the selected data field for each iteration round.