Cross-Plane Telemetry via Authentication Intent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current monitoring solutions for network analytics and assurance face challenges in providing end-to-end visibility across different network planes for every online application and user session due to scalability issues and require significant policy configuration, lacking user-centricity.

Innovation Solution

An access policy enforcement service identifies telemetry collection intent from user authentication requests and configures telemetry collection agents to collect data from both control and data planes, using header signaling and augmented local state entries to correlate data across layers, ensuring user-centric and dynamic telemetry collection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If monitoring solutions collect telemetry data across all network planes for every online application and user session, then end-to-end visibility is improved, but system complexity and resource consumption increase significantly

Engineering Contradiction:
Improveend-to-end visibilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements user-centric monitoring by assigning different monitoring policies to different users and applications. The access policy enforcement service determines specific monitoring policies based on user authentication requests, enabling telemetry collection only where needed rather than uniformly across all network planes for all applications. This selective approach maintains end-to-end visibility for relevant traffic while reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The monitoring system is segmented into multiple independent components: telemetry collection agents deployed at different network planes (data plane, control plane), an access policy enforcement service, and a monitoring policy database. Each component operates independently and communicates through standardized interfaces, allowing the system to scale without proportionally increasing complexity.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If comprehensive telemetry collection is implemented across all network planes, then measurement precision is improved, but policy configuration effort increases significantly

Engineering Contradiction:
Improvetelemetry measurement precisionVSAvoidpolicy configuration ease
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The access policy enforcement service automatically determines monitoring policies based on user authentication requests and application identifiers. Instead of requiring manual configuration of complex monitoring policies, the system self-configures by extracting relevant information from authentication requests and matching them with appropriate policies stored in the database. This automation eliminates the need for extensive manual policy configuration while maintaining precise telemetry measurement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Monitoring policies are pre-configured and stored in the monitoring policy database before runtime. The access policy enforcement service retrieves and applies these pre-defined policies based on user authentication results, eliminating the need for real-time policy creation and configuration. This preliminary preparation of policies simplifies the operational complexity while ensuring precise measurement capabilities are available when needed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If telemetry collection agents are configured for every user session, then data accuracy is improved, but scalability deteriorates

Engineering Contradiction:
Improvetelemetry data accuracyVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a universal telemetry collection architecture where a single type of multi-functional agent operates across all network planes (data plane, control plane, application plane). These agents can collect various types of telemetry data depending on their deployment location and configured policies, eliminating the need for separate specialized agents for each plane. This universal approach improves scalability while maintaining data accuracy through consistent collection methodologies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system configures telemetry collection selectively based on user-centric policies rather than universally for all users and sessions. The access policy enforcement service determines the appropriate level of monitoring for each user based on authentication results and application requirements, enabling partial action only where necessary. This approach maintains data accuracy for relevant traffic while improving scalability by avoiding unnecessary telemetry collection for unrelated traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240430309A1Cross-plane monitoring intent and policy instantiation for network analytics and assurance
Publication Date: 2024.12.26 CISCO TECHNOLOGY INC
  • US20240430309A1 patent drawing
  • US20240430309A1 patent drawing
  • US20240430309A1 patent drawing

AI summary

In one embodiment, an access policy enforcement service receives a user authentication request from an end-user device. The access policy enforcement service identifies a telemetry collection intent from the user authentication request. The access policy enforcement service determines a monitoring policy based on the telemetry collection intent identified from the user authentication request. The access policy enforcement service configures, according to the monitoring policy, one or more telemetry collection agents to collect telemetry for traffic associated with the end-user device.