Distributed Dual-Authorized Network Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual network implementations lack sufficient security and scalability, particularly in large-scale operations, as they fail to provide reliable isolation and secure communication between virtual machines across multiple physical machines, leading to potential security breaches and synchronization challenges during policy updates.

Innovation Solution

The implementation of dual authorization and distributed connection policy management across multiple connection control nodes, where each node enforces its own view of allowable paths and verifies communication policies with neighboring nodes, ensuring secure and synchronized updates without interrupting service availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines are connected via virtual network interface cards on the same physical machine, then resource utilization improves, but security isolation deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the physical network into multiple virtual networks using virtual routers and virtual network interface cards. Each virtual network provides isolated communication paths for different virtual machines, allowing secure multi-tenant operations while sharing physical infrastructure. The virtual router acts as a segmentation boundary that enforces network policies between different virtual network segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual routers as intermediary devices between virtual machines on the same physical host. These virtual routers mediate network traffic, providing security isolation through virtual network interface cards and enforcing connection policies. The intermediary virtual router prevents direct access between VMs while maintaining controlled communication through authenticated paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If connection policies are updated centrally, then policy consistency improves, but synchronization difficulty increases in distributed networks

Engineering Contradiction:
Improvepolicy consistencyVSAvoidsynchronization difficulty
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent implements local connection policies at each virtual router that are tailored to specific network segments and requirements. Each virtual router maintains its own policy set optimized for its local context, while still contributing to overall network security. This local quality approach allows policy updates to be applied independently at each node, reducing synchronization complexity while maintaining consistency through coordinated policy management.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If all virtual machines can see all traffic on the physical network, then network simplicity improves, but security guarantees deteriorate

Engineering Contradiction:
Improvenetwork simplicityVSAvoidsecurity guarantees
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent adds a virtual network dimension above the physical network infrastructure. Instead of managing security at the physical network level, it creates multiple virtual network layers where traffic isolation is enforced. This dimensional approach maintains physical network simplicity while implementing security isolation in the virtual network space through virtual routers and virtual network interface cards.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10165009B2Distributed network connection policy management
Publication Date: 2018.12.25 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10165009B2 patent drawing
  • US10165009B2 patent drawing
  • US10165009B2 patent drawing

AI summary

A connection policy for a communications network has a local connection policy indicating which paths between a given one of the nodes (computer A, router A, host 898) and others of the nodes (computers B, C, filters B1, B2, C1, C2, hosts 890, 892) are allowable paths, by a symbolic expression of ranges endpoint addresses and other local connection policies in respect of other nodes. It is implemented in a distributed manner by determining, for the given node, which of the allowable paths, are dual authorized as allowable by the other local connection policy relating to the other node at the other end of that path, by Boolean operations on the symbolic expressions. For a given message for a given path between two of the nodes having their own local connection policies, both of these nodes determine whether the given path is currently dual authorized. This can provide reassurance that changes in versions of the connection policy won't transiently open a risk of undetected unwanted communication.