Cloud Headend Access Segmentation for Leaner SASE Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Secure Access Service Edge (SASE) architectures face challenges in managing network traffic between numerous endpoints, requiring extensive routing tables that burden memory and network resources, as every endpoint typically needs to access a subset of other endpoints and resources, leading to inefficient and cumbersome configurations.
Innovation Solution
Implementing access designations for endpoints (isolated, shared, private, public) to optimize routing tables, allowing only permitted communication, reducing the number of entries needed in data nodes' routing tables, and enabling efficient network traffic propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all endpoints are allowed to access all other endpoints in a SASE architecture, then any endpoint can communicate with any other endpoint, but the routing tables become extremely large and consume significant memory and network resources
Solution Approach 1:
The patent segments the endpoint population into different groups or communities with defined access relationships. Instead of maintaining routing entries for all possible endpoint pairs, the system creates routing entries only for permitted communication paths between groups. This segmentation approach reduces the routing table size from O(N²) to O(G) where G is the number of group boundaries, directly resolving the contradiction between universal accessibility and routing table size.
2Reliability
If routing tables maintain entries for all possible endpoint pairs, then complete network connectivity is achieved, but the complexity of maintaining and propagating routing information increases significantly
Solution Approach 1:
The patent extracts and removes unnecessary routing entries from the routing tables by identifying and eliminating prohibited communication paths. The system maintains only the essential routing entries required for permitted communications, extracting the harmful complexity of maintaining full mesh routing information. This reduces routing maintenance complexity while preserving reliable connectivity for authorized endpoint pairs.
3Reliability
If access control rules are applied to prevent unwanted traffic between endpoints, then security is improved, but the number of rules that need to be maintained increases with the number of endpoints
Solution Approach 1:
The patent merges multiple individual access control rules into group-based access policies. Instead of maintaining separate rules for each endpoint pair, the system defines access control at the group level, where endpoints inherit permissions based on their group memberships. This merging approach reduces the number of rules from O(N²) to O(G) where G is the number of group boundaries, improving security while reducing rule maintenance complexity.
Data Source
AI summary
In one aspect, the present disclosure is directed to a method that includes receiving, at an edge component of a cloud-based secure access service, a corresponding access designation for each of a plurality of endpoints, each access designation specifying a type of access a corresponding endpoint has to remaining ones of the plurality of endpoints and other accessible network resources; based on the corresponding access designation of each of the plurality of endpoints, updating a routing table at the edge component, to include routing information for a subset of the plurality of endpoints having access to at least one other endpoint of the plurality of endpoints or to the other accessible network resources; and enabling routing of network traffic, via the cloud-based secure access service, between any number of the plurality of endpoints based at least in part on the routing table.


