Correlation Policy Engine Event Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing event-driven architecture (EDA) systems face challenges in efficiently correlating and managing events across complex networks, leading to difficulties in pinpointing important events amidst a vast number of events.

Innovation Solution

A correlation and policy engine (CPE) is designed to aggregate, normalize, and analyze event data, enabling event correlation and applying predefined policies to manage network resources effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If event-driven architecture is used to manage complex networks, then system scalability and flexibility are improved, but event correlation complexity and difficulty in pinpointing important events increase

Engineering Contradiction:
Improvesystem scalabilityVSAvoidevent correlation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments event correlation into multiple independent correlation engines, each responsible for specific event types or networks. This divides the complex correlation task into manageable units, reducing overall system complexity while maintaining scalability across multiple networks and event types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a correlation engine as an intermediary component between event collection and policy enforcement. This mediator aggregates events from multiple sources, performs correlation analysis, and filters important events before they reach policy engines, simplifying the overall architecture and reducing direct complexity in event correlation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If more event data is collected and analyzed, then event correlation accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveevent correlation accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary event aggregation and correlation in dedicated correlation engines before events reach policy enforcement points. By pre-processing and filtering events upfront, the system reduces the volume of data that requires full processing, thereby improving accuracy while reducing overall processing time through early elimination of irrelevant events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial correlation analysis focused on specific event patterns and time windows rather than exhaustive analysis of all events. This selective correlation approach maintains sufficient accuracy for identifying important events while significantly reducing processing time and computational resources compared to complete event analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Extent of automation

If predefined policies are applied to manage network resources, then automated response capability is improved, but policy management complexity increases

Engineering Contradiction:
Improveautomated response capabilityVSAvoidpolicy management complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The system segments policy management into separate policy engines that handle specific network functions or event types independently. Each policy engine manages its own policy set, reducing the complexity of managing a single monolithic policy system while maintaining comprehensive automated response capabilities across multiple domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal policy engine framework that can handle multiple types of policies (security, performance, compliance) through a common architecture. This multi-functional design simplifies policy management by providing unified tools and processes while enabling sophisticated automated responses across diverse network scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12223263B2Correlation and policy engine policy creation system and method of operation
Publication Date: 2025.02.11 RAKUTEN MOBILE INC
  • US12223263B2 patent drawing
  • US12223263B2 patent drawing
  • US12223263B2 patent drawing

AI summary

A system includes processing circuitry; and a memory connected to the processing circuitry, wherein the memory is configured to store executable instructions that, when executed by the processing circuitry, facilitate performance of operations, including receive a policy template identifier; receive network element selections; receive network element filter parameters; receive network event parameters; receive conjunctive operation parameters; receive action configuration parameters; and create a network policy template to monitor event messages and perform an action based on the action configuration parameters.