Distributed Policy Proxy for Network Resource Overload
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network-based micro-segmentation with highly granular white-listing security policies strains physical resources like TCAM elements, leading to limitations in policy enforcement, prompting the need for offloading security policies to external firewalls or dedicated proxies, which can degrade security or reduce flexibility.
Innovation Solution
A distributed policy proxy system that offloads network policy processing from overloaded network elements to multiple policy proxy elements, using existing network elements to distribute policy rules and redirect traffic, ensuring high resource utilization without requiring new hardware or separate support, maintaining consistent policy enforcement across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network-based micro-segmentation with highly granular white-listing security policies is implemented, then security granularity and coverage are improved, but physical resources like TCAM elements are strained and exceeded
Solution Approach 1:
The patent divides the network elements into multiple shards, where each shard handles a subset of security policies. This segmentation allows the system to enforce granular security policies across the entire network while distributing the TCAM resource consumption across multiple smaller units, thereby maintaining high security granularity without exhausting physical resources at any single point.
Solution Approach 2:
The patent introduces a new dimension of resource organization by creating virtual shards that can be dynamically allocated across physical network elements. Instead of mapping policies directly to physical TCAM resources in a one-to-one fashion, the system creates an additional layer of abstraction where multiple virtual policy entries can be mapped to shared physical resources through hash-based distribution, effectively increasing resource capacity without adding physical hardware.
2Quantity of substance
If security policies are offloaded to an external firewall or dedicated policy proxy, then policy resource capacity is increased, but security may be degraded or flexibility reduced
Solution Approach 1:
The patent enables network elements to serve themselves by implementing local policy enforcement capabilities within each shard. Each network element maintains its own policy evaluation and enforcement mechanisms, eliminating the need for centralized policy proxies or external firewalls. This self-service approach preserves security flexibility and adaptability while providing sufficient policy resource capacity through distributed TCAM resources across multiple shards.
Solution Approach 2:
The patent designs each network element shard to perform multiple functions: policy enforcement, packet forwarding, and dynamic shard membership management. This multi-functionality eliminates the need for dedicated policy proxy devices, allowing standard network elements to handle security policies locally while maintaining the flexibility to adapt to different policy requirements and network conditions.
3Productivity
If policy entries are distributed across multiple network elements, then resource utilization is improved, but system complexity increases
Solution Approach 1:
The patent implements a feedback mechanism where network elements monitor their own policy resource utilization and dynamically adjust shard membership accordingly. When a network element's TCAM resources become saturated, it can signal the need for policy redistribution, and the system automatically re-balances policy entries across available shards. This feedback-driven approach optimizes resource utilization while keeping complexity manageable through automated rather than manual management.
Solution Approach 2:
The patent creates dynamic shards that can be created, modified, and deleted based on real-time network conditions and resource availability. Rather than using static policy distributions, the system continuously adapts shard configurations to match current workload and resource states, improving resource utilization while managing complexity through automated dynamic adjustment rather than fixed complex configurations.
Data Source
AI summary
A distributed policy proxy system offloads network policy processing from an overloaded network element to policy proxy network elements. A network controller detects that policy resources are overloaded at a network element, and assigns a range of endpoints to each policy proxy network element. Each policy proxy network element is assigned to handle policy processing for traffic belonging to a corresponding assigned range of endpoints. The network controller provides instructions to the policy proxy network elements to enable each policy proxy network element to apply the network policy for its assigned range of endpoints. The network controller also provides instructions to the overloaded network element to redirect a packet from the first endpoint to a first policy proxy network element based on a destination of the packet.


