Cloud Headend Access Designations for Leaner Routing Tables
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud-based Secure Access Service Edge (SASE) architectures, managing network traffic between numerous endpoints becomes burdensome due to the need for extensive routing and access control, especially when not all endpoints should be able to communicate with each other, leading to inefficient memory and network resource usage.
Innovation Solution
Implementing access designations for endpoints (isolated, shared, private, public) to streamline routing tables, allowing only permitted communications, reducing the number of entries needed in data nodes' routing tables.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all endpoints are allowed to access all other locations in a SASE architecture, then network connectivity and accessibility are maximized, but routing table complexity and memory resource consumption increase significantly
Solution Approach 1:
The patent segments the network access permissions by creating hierarchical groups (enterprise-level, location-level, and endpoint-level groups) with defined access policies. Instead of managing individual endpoint-to-endpoint routing rules, the system organizes endpoints into structured groups with inheritance hierarchies, where parent groups contain child groups and policies cascade down the hierarchy. This segmentation reduces routing table complexity while maintaining comprehensive network connectivity.
Solution Approach 2:
The patent introduces a hierarchical dimension to access control by organizing endpoints into multi-level groups with inheritance relationships. Rather than flat, pairwise access control, the system adds hierarchical layers (enterprise → location → endpoint groups) that enable scalable access management. This dimensional change allows the routing tables to scale efficiently as the network grows.
2Reliability
If extensive routing rules are implemented to control access between specific locations, then security and access control are improved, but network resource usage and processing overhead increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring hierarchical access policies at group levels before endpoints need to communicate. Access permissions are established at the enterprise and location group levels in advance, and these policies are automatically inherited by child groups and endpoints. When endpoints need to communicate, the routing decision is made by checking hierarchical group memberships rather than evaluating extensive individual access rules, significantly reducing processing overhead.
Solution Approach 2:
The patent creates universal access policies at hierarchical group levels that apply to multiple endpoints simultaneously. A single access policy configured at an enterprise group level automatically applies to all location groups and endpoints within that enterprise, eliminating the need to configure and process individual access rules for each endpoint pair. This multi-functionality reduces network resource usage while maintaining comprehensive access control.
3Adaptability or versatility
If the number of endpoints and services headends scales up, then network coverage and service capability are enhanced, but the number of routing entries and propagation burden increase exponentially
Solution Approach 1:
The patent segments the scaling burden by organizing endpoints into hierarchical groups that can be independently managed. As the network scales, new endpoints are added to existing groups or new groups are created within the hierarchical structure, rather than requiring individual routing entries for each new endpoint. This segmentation allows network coverage to expand while routing table entries grow linearly rather than exponentially.
Solution Approach 2:
The patent adds hierarchical grouping as a new dimension to endpoint organization, transforming the scaling problem from managing individual endpoint relationships to managing group relationships. The hierarchical structure (enterprise groups containing location groups containing endpoint groups) allows the system to scale to thousands of endpoints by managing only the group hierarchy and inheritance relationships, dramatically reducing the number of routing table entries needed.
Data Source
AI summary
In one aspect, the present disclosure is directed to a method that includes receiving, at an edge component of a cloud-based secure access service, a corresponding access designation for each of a plurality of endpoints, each access designation specifying a type of access a corresponding endpoint has to remaining ones of the plurality of endpoints and other accessible network resources; based on the corresponding access designation of each of the plurality of endpoints, updating a routing table at the edge component, to include routing information for a subset of the plurality of endpoints having access to at least one other endpoint of the plurality of endpoints or to the other accessible network resources; and enabling routing of network traffic, via the cloud-based secure access service, between any number of the plurality of endpoints based at least in part on the routing table.


