Core Network Node Centralized Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise networks face complexity in enforcing user policies due to distributed configuration across multiple layers, requiring manual configuration of network elements and separate implementation for wired and wireless portions, making it difficult for administrators to manage access independently of user location and device type.

Innovation Solution

A core network node is introduced to centrally manage and enforce user policies across both wired and wireless networks, using identifiers to apply common policies to data packets, allowing for unified access management regardless of location or device type, with policies stored in a policy database and applied through MPLS tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If distributed policy management is used across multiple network layers, then user-specific access controls can be implemented at individual network elements, but the complexity of manual configuration increases and policy coordination becomes difficult

Engineering Contradiction:
Improveuser-specific access controlVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A centralized policy server is introduced as an intermediary between network administrators and distributed network elements. The policy server receives policy definitions, translates them into device-specific configurations, and automatically distributes them to appropriate network elements, eliminating manual configuration while maintaining distributed access control capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Policies are defined and validated in advance at the centralized policy server before being deployed to network elements. The system performs preliminary policy compilation, translation, and distribution, so that when policies need to be enforced at distributed network elements, the configuration work has already been completed automatically

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If separate policy implementation is used for wired and wireless network portions, then each network type can be managed independently, but the overall policy management complexity increases

Engineering Contradiction:
Improveindependent network managementVSAvoidpolicy management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The centralized policy server provides a universal policy management interface that handles both wired and wireless network policies through a single system. Administrators define policies once in a unified manner, and the policy server automatically translates and distributes appropriate configurations to wired network elements, wireless network elements, or both, eliminating the need for separate management systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the management of wired and wireless policies into a single centralized policy server that coordinates both network types. While physical network elements remain separate, their policy management is combined at the server level, allowing administrators to manage both network portions through one interface while maintaining the ability to enforce type-specific policies

Inventive Principle:
Principle #5Merging (Combining)

3Manufacturing precision

If manual configuration of network elements is required, then policies can be precisely tailored to physical connectivity, but the administrative burden and time consumption increase

Engineering Contradiction:
Improvepolicy configuration precisionVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The centralized policy server performs preliminary policy translation and device-specific configuration generation automatically. Administrators define policies in a standardized format, and the server pre-processes them into device-specific configurations, automatically distributing them to the correct network elements, thereby maintaining precision while eliminating manual configuration time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Network elements are equipped with self-service capabilities to receive, interpret, and apply policy configurations automatically. The centralized policy server pushes configurations to elements, which then self-configure themselves according to the received policies, eliminating the need for manual configuration while maintaining precise policy enforcement

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9374835B2Methods and apparatus for enforcing a common user policy within a network
Publication Date: 2016.06.21 JUNIPER NETWORKS INC
  • US9374835B2 patent drawing
  • US9374835B2 patent drawing
  • US9374835B2 patent drawing

AI summary

In some embodiments, an apparatus includes a core network node configured to be operatively coupled to a set of wired network nodes and a set of wireless network nodes. The core network node is configured to receive, at a first time, a first data packet to be sent to a wired device operatively coupled to a wired network node from the set of wired network nodes. The core network node is configured to also receive, at a second time, a second data packet to be sent to a wireless device operatively coupled to a wireless network node from the set of wireless network nodes. The core network node is configured to apply a common policy to the first data packet and the second data packet based on an identifier of a user associated with both the wireless device and the wired device.