Agent-Less Micro-Segmentation Policy Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Micro-segmentation policies in networks are limited to virtualized computing environments and are less effective when applied to physical computing systems without agents, as they do not extend beyond the virtual portion of the network.

Innovation Solution

A method that converts micro-segmentation policies from a virtual computing environment format to a format usable by domain controllers on physical computing systems, allowing for agent-less implementation across both virtualized and physical elements by leveraging policy enforcement components built into the operating systems of physical computing elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If micro-segmentation policies are implemented only in virtualized computing environments, then policy enforcement is effective within virtual guests, but micro-segmentation cannot be applied to physical computing systems

Engineering Contradiction:
Improvemicro-segmentation applicabilityVSAvoidpolicy enforcement effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies universality by making micro-segmentation policies multi-functional across different computing environments. The policy conversion mechanism transforms virtual-environment-specific policies into a universal format that can be executed by domain controllers on both virtualized and physical computing systems, eliminating the need for separate policy implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary policy conversion mechanism that acts as a mediator between virtual computing environment policies and physical computing system domain controllers. This intermediary component translates policies into a compatible format, enabling cross-environment policy enforcement without requiring agents on physical systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If agents are deployed on physical computing systems to enforce micro-segmentation policies, then policy coverage is extended to physical systems, but system complexity and deployment overhead increase

Engineering Contradiction:
Improvemicro-segmentation coverageVSAvoidagent deployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling domain controllers on physical computing systems to autonomously enforce micro-segmentation policies without requiring external agents. The policies are converted to a format that domain controllers can natively understand and execute, allowing the physical systems to self-manage their own policy enforcement using built-in capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the policy enforcement capability from external agents and relocates it to the domain controllers that are already present on physical computing systems. By removing the need for separate agent software and utilizing existing domain controller functionality, the solution reduces deployment complexity while maintaining policy coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

3Manufacturing precision

If policy formats are environment-specific, then policies can be precisely tailored to virtual computing environments, but policies cannot be distributed to physical computing systems

Engineering Contradiction:
Improvepolicy definition precisionVSAvoidpolicy distribution scope
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies parameter changes by transforming the format parameters of micro-segmentation policies. The conversion mechanism changes the structural parameters of policies from virtual-environment-specific formats to a standardized format compatible with domain controllers, enabling the same policies to be distributed and enforced across both virtual and physical computing systems while preserving their enforcement precision.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10652213B2Agent-less micro-segmentation of a network
Publication Date: 2020.05.12 VMWARE INC
  • US10652213B2 patent drawing
  • US10652213B2 patent drawing
  • US10652213B2 patent drawing

AI summary

The technology disclosed herein enables the micro-segmentation of a network without agents. In a particular embodiment, a method provides, in a packet-handler controller of a virtual computing environment, determining one or more policies in a first format that identify one or more packet characteristics and how packets with the one or more packet characteristics should be handled within the virtual computing environment. The method further provides converting the one or more policies from the first format to a second format used by a domain controller for one or more computing systems outside of the virtual computing environment. Also, the method provides distributing the one or more policies in the second format to at least one of the one or more computing systems.