Distributed Policy Enforcement Point for Network Scalability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant datacenter environments, traditional edge appliances acting as single Policy Enforcement Points (PEPs) become bottlenecks due to high traffic processing and policy enforcement, and implementing distributed PEPs is complicated by multiple network address translation (NAT) layers altering traffic parameters, making it difficult to enforce policies across multiple nodes.
Innovation Solution
An edge device dynamically identifies and translates policies based on traffic parameters at intermediate nodes, allowing these nodes to enforce policies, thereby offloading processing from the edge appliance and facilitating distributed policy enforcement across multiple PEP nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single edge appliance is used as the main Policy Enforcement Point (PEP), then policy enforcement is centralized and simple to manage, but the edge appliance becomes a bottleneck and network scalability is hampered
Solution Approach 1:
The patent segments the centralized PEP function into multiple distributed PEP points deployed across different network locations. Each PEP point maintains a local policy cache and can independently enforce policies, distributing the enforcement load while maintaining centralized policy management through the policy server.
Solution Approach 2:
The patent introduces a new dimensional layer (policy caching layer) between the central policy server and distributed PEP points. This layer enables policies to be replicated and cached at multiple levels, allowing enforcement at the network edge without requiring constant central server communication, thus improving scalability while maintaining manageability.
2Productivity
If multiple PEP points are deployed to improve scalability, then network throughput increases, but implementing distributed policy enforcement becomes complicated due to multiple NAT layers altering traffic parameters
Solution Approach 1:
The patent introduces a policy server as an intermediary that acts as the single source of truth for policy definitions. This server communicates with all PEP points, providing them with translated policies that account for NAT transformations. The intermediary simplifies the complexity by centralizing policy translation logic while enabling distributed enforcement.
Solution Approach 2:
The patent applies parameter changes by translating policies based on traffic parameters at intermediate nodes. The system dynamically adjusts policy parameters to account for NAT-induced changes in source/destination addresses and ports, allowing consistent policy enforcement across multiple PEP points despite parameter alterations in the network path.
3Reliability
If policies are enforced at the edge appliance, then security is maintained, but processing delays increase and traffic handling capacity is reduced
Solution Approach 1:
The patent implements preliminary action by pre-translating and caching policies at distributed PEP points before traffic arrives. Policies are pushed from the central server to PEP points in advance, allowing immediate local enforcement without real-time communication delays with the central server, thus maintaining security while reducing processing delays.
Solution Approach 2:
The patent extracts the policy enforcement function from the overloaded edge appliance and distributes it to multiple PEP points throughout the network. This extraction removes the bottleneck from the edge appliance while maintaining security enforcement capabilities across the distributed network infrastructure.
Data Source
AI summary
The disclosure herein describes an edge device of a network for distributed policy enforcement. During operation, the edge device receives an initial packet for an outgoing traffic flow, and identifies a policy being triggered by the initial packet. The edge device performs a reverse lookup to identify at least an intermediate node that is previously traversed by the initial packet and traffic parameters associated with the initial packet at the identified intermediate node. The edge device translates the policy based on the traffic parameters at the intermediate node, and forwards the translated policy to the intermediate node, thus facilitating the intermediate node in applying the policy to the traffic flow.


