Distributed Policy Enforcement Point for Network Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant datacenter environments, traditional edge appliances acting as single Policy Enforcement Points (PEPs) become bottlenecks due to high traffic processing and policy enforcement, and implementing distributed PEPs is complicated by multiple network address translation (NAT) layers altering traffic parameters, making it difficult to enforce policies across multiple nodes.

Innovation Solution

An edge device dynamically identifies and translates policies based on traffic parameters at intermediate nodes, allowing these nodes to enforce policies, thereby offloading processing from the edge appliance and facilitating distributed policy enforcement across multiple PEP nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single edge appliance is used as the main Policy Enforcement Point (PEP), then policy enforcement is centralized and simple to manage, but the edge appliance becomes a bottleneck and network scalability is hampered

Engineering Contradiction:
Improvepolicy enforcement managementVSAvoidnetwork scalability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent segments the centralized PEP function into multiple distributed PEP points deployed across different network locations. Each PEP point maintains a local policy cache and can independently enforce policies, distributing the enforcement load while maintaining centralized policy management through the policy server.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional layer (policy caching layer) between the central policy server and distributed PEP points. This layer enables policies to be replicated and cached at multiple levels, allowing enforcement at the network edge without requiring constant central server communication, thus improving scalability while maintaining manageability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If multiple PEP points are deployed to improve scalability, then network throughput increases, but implementing distributed policy enforcement becomes complicated due to multiple NAT layers altering traffic parameters

Engineering Contradiction:
Improvenetwork throughputVSAvoiddistributed policy enforcement implementation
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a policy server as an intermediary that acts as the single source of truth for policy definitions. This server communicates with all PEP points, providing them with translated policies that account for NAT transformations. The intermediary simplifies the complexity by centralizing policy translation logic while enabling distributed enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by translating policies based on traffic parameters at intermediate nodes. The system dynamically adjusts policy parameters to account for NAT-induced changes in source/destination addresses and ports, allowing consistent policy enforcement across multiple PEP points despite parameter alterations in the network path.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If policies are enforced at the edge appliance, then security is maintained, but processing delays increase and traffic handling capacity is reduced

Engineering Contradiction:
Improvesecurity enforcementVSAvoidtraffic processing delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-translating and caching policies at distributed PEP points before traffic arrives. Policies are pushed from the central server to PEP points in advance, allowing immediate local enforcement without real-time communication delays with the central server, thus maintaining security while reducing processing delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the policy enforcement function from the overloaded edge appliance and distributes it to multiple PEP points throughout the network. This extraction removes the bottleneck from the edge appliance while maintaining security enforcement capabilities across the distributed network infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9807021B2System and method for distribution of policy enforcement point
Publication Date: 2017.10.31 VMWARE INC
  • US9807021B2 patent drawing
  • US9807021B2 patent drawing
  • US9807021B2 patent drawing

AI summary

The disclosure herein describes an edge device of a network for distributed policy enforcement. During operation, the edge device receives an initial packet for an outgoing traffic flow, and identifies a policy being triggered by the initial packet. The edge device performs a reverse lookup to identify at least an intermediate node that is previously traversed by the initial packet and traffic parameters associated with the initial packet at the identified intermediate node. The edge device translates the policy based on the traffic parameters at the intermediate node, and forwards the translated policy to the intermediate node, thus facilitating the intermediate node in applying the policy to the traffic flow.