Customer-Network Traffic Tagging for Target-Service Egress Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud environments lack effective mechanisms to enforce egress traffic policies, particularly in multi-tenant scenarios, leading to risks of data exfiltration and unauthorized data transfer.

Innovation Solution

Implementing egress traffic policy enforcement at a target service by tagging traffic with network location information, such as identifiers and IP addresses, and using a policy evaluator to determine and enforce customer-defined actions based on these tags.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If egress traffic policy enforcement is implemented at target service, then data security and compliance are improved, but system complexity increases due to tagging and policy evaluation mechanisms

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network location tags traffic with network location information (such as gateway identifiers) in advance before the traffic reaches the target service. This preliminary tagging action enables the target service to enforce egress policies without needing to implement complex evaluation logic, thereby improving data security while minimizing the increase in system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a policy evaluator as an intermediary component that receives policy evaluation requests from target services and returns enforcement decisions. This intermediary handles the complex policy matching and evaluation logic centrally, allowing target services to enforce policies simply by querying the evaluator, thus improving security enforcement while containing system complexity in a dedicated component.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If network location tagging is performed on all egress traffic, then policy enforcement accuracy is improved, but processing overhead increases

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The network location tags traffic with identifying information at the point of egress (at the gateway) before the traffic traverses the network to reach the target service. This preliminary tagging ensures that when the target service receives the traffic, the network location information is already available for immediate policy enforcement without requiring additional processing or querying, thereby achieving high policy enforcement accuracy while minimizing processing overhead at the target service.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12395532B2Egress traffic policy enforcement at target service on traffic from customer network
Publication Date: 2025.08.19 ORACLE INT CORP
  • US12395532B2 patent drawing
  • US12395532B2 patent drawing
  • US12395532B2 patent drawing

AI summary

Techniques for enforcing an egress policy at a target service are described. In an example, traffic is generated for a customer, where the traffic is generated by a customer network of the customer, such as a customer tenancy or an on-premise network. The traffic can be destined to the target service. The traffic can be tagged by the customer network (e.g., by a gateway of the customer network). The customer network can be associated with the egress policy. The target service can determine the egress policy based on the information tagged to the traffic and can enforce the egress policy on the traffic that the target service is receiving.