Composite Network Policy Generation via Conflict Resolution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network policy graphs lack support for performance-oriented and dynamic policies that adapt to network environment conditions such as traffic, time, and state, leading to conflicts and inefficiencies in managing network infrastructures.
Innovation Solution
The introduction of an extended policy graph model and composition method that allows for the combination of diverse policies, including Quality-of-Service (QoS), stateful, and temporal policies, enabling conflict resolution and dynamic policy adjustments based on relationships between metrics, thereby generating a composite network policy that is conflict-free and adaptable.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional policy graph abstraction is used to manage network policies, then basic access control policies can be represented, but performance-oriented policies and dynamic run-time policies cannot be supported
Solution Approach 1:
The patent segments the policy representation into distinct components: static policy graphs for access control and dynamic policy graphs for performance-oriented and run-time policies. This segmentation allows each type of policy to be managed independently with appropriate representations, avoiding the need to support all policy types within a single rigid framework.
Solution Approach 2:
The patent introduces dynamic policy graphs that can be modified at run-time based on network conditions, traffic patterns, and performance metrics. This dynamic capability allows the policy system to adapt to changing network environments without requiring complete re-composition of all policies.
2Adaptability or versatility
If multiple diverse policies are combined into a single policy graph, then comprehensive network management is achieved, but conflicts between policies arise
Solution Approach 1:
The patent introduces a policy composition engine as an intermediary that mediates between multiple diverse policies. This engine detects conflicts, analyzes policy relationships, and resolves contradictions by prioritizing critical policies and adjusting less critical ones, ensuring the final composite policy is conflict-free while maintaining comprehensive coverage.
Solution Approach 2:
The patent modifies policy parameters dynamically during composition, adjusting metrics such as priority levels, time windows, and resource allocations to resolve conflicts. By changing these parameters, the system can reconcile contradictory requirements from different policies without losing their essential functions.
3Adaptability or versatility
If policy composition is performed frequently to adapt to dynamic network conditions, then policy adaptability improves, but re-composition overhead increases
Solution Approach 1:
The patent performs preliminary policy composition during off-peak periods or when network conditions are stable, pre-computing policy combinations and storing them for quick deployment. This preliminary action reduces the need for frequent re-composition when dynamic adjustments are actually needed.
Solution Approach 2:
The patent implements incremental policy composition that updates only the affected portions of the policy graph when network conditions change, rather than re-composing the entire policy set. This dynamic update approach maintains adaptability while significantly reducing re-composition overhead.
4Measurement precision
If detailed metrics are tracked for each policy to enable precise conflict resolution, then conflict resolution accuracy improves, but system complexity and processing overhead increase
Solution Approach 1:
The patent extracts and focuses on tracking only the critical metrics necessary for conflict resolution, such as policy priority, resource utilization, and performance impact, rather than monitoring all possible parameters. This selective extraction reduces complexity while maintaining sufficient precision for effective conflict resolution.
Data Source
AI summary
Example method includes: receiving, by a network device in a network, a first network policy and a second network policy configured by a network administrator, wherein the first network policy comprises a first metric and the second network policy comprises a second and different metric; detecting, by the network device, a conflict between the first network policy and the second network policy; determining, by the network device, a relationship between the first metric and the second metric; modifying, by the network device, at least one of the first network policy and the second network policy to resolve the conflict based on the relationship between the first metric and the second metric; and combining, by the network device, the first network policy and the second network policy to generate a composite network policy that is represented on a single policy graph.


