Cryptographic Identity Network Microsegmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional IP-based network microsegmentation struggles with scalability and flexibility, especially when workloads move between clusters or data centers, as security policies tied to IP addresses become unenforceable due to changing network topologies.
Innovation Solution
A method and system for network microsegmentation using cryptographic identities, where certificates with security attributes are used to establish secure connections, allowing policy actions based on these attributes, independent of IP addresses, and utilizing intermediate certificate authorities for secure and authenticated network connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP-based microsegmentation is used for network security, then security policies can be established for network traffic between clusters, but the system loses flexibility and scalability when workloads move between clusters or data centers
Solution Approach 1:
The patent introduces certificates as an intermediary mechanism that decouples security policy enforcement from IP addresses. Instead of directly binding security policies to IP addresses, the system uses certificates as a mediator that can be dynamically associated with workloads regardless of their IP location, enabling policy enforcement to follow the workload rather than being fixed to network addresses
Solution Approach 2:
The system changes the fundamental parameter for security policy identification from static IP addresses to dynamic certificate-based identities. This parameter change allows security policies to be enforced based on workload identity (certificate) rather than network location (IP address), enabling flexible policy enforcement in dynamic environments where workloads move between clusters and data centers
2Ease of operation
If security policies are tied to IP addresses, then network traffic can be controlled between clusters, but the policies become unenforceable when network topologies change or workloads move
Solution Approach 1:
The patent transitions from static IP address-based security policies to dynamic certificate-based policies. Certificates can be dynamically issued, renewed, and reassigned to workloads as they move, allowing security policies to adapt automatically to changing network topologies and workload locations while maintaining consistent enforcement
Solution Approach 2:
The system performs preliminary action by issuing certificates to workloads before they are deployed or moved to new locations. This advance provisioning of cryptographic identities ensures that security policies can be enforced immediately upon workload deployment or migration without requiring reconfiguration, maintaining continuous policy enforceability
Data Source
AI summary
Methods and network interface devices for establishing a secure and authenticated network connection are provided. The method comprises: receiving, from a requesting entity, a destination IP address and a first certificate that is used to establish a secure network connection, wherein the first certificate comprises a first security attribute that is associated with a source destination IP address; identifying, with aid of one or more processors, a stored second security attribute associated with the destination IP address; and determining, with aid of the one or more processors, a policy action based at least in part on the first security attribute and the second security attribute.


