Distributed Policy Store for Intent-Driven Network Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network management approaches require comprehensive knowledge from highly specialized operators and are inflexible, making it difficult for application developers to implement and alter network policies using access control lists (ACLs), which are complex and lack tailored control over network traffic.

Innovation Solution

An intent-driven network management platform that translates user intent statements into network policies, allowing both application owners and network operators to define policies in a more understandable manner, with network agents enforcing these policies across network entities and data flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional ACL-based network management is used, then network security control is achieved, but the complexity of policy management increases and requires highly specialized operators

Engineering Contradiction:
Improvenetwork security controlVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy store as an intermediary component that sits between the network entities and the management interface. This policy store stores network policies in a simplified format and provides an abstraction layer that translates high-level policy statements into low-level ACL rules, thereby reducing management complexity while maintaining security control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network policy management system into distinct components: a policy definition interface for users, a policy store for storage, and a policy enforcement mechanism. This segmentation allows each component to handle specific tasks independently, reducing the overall complexity that users would otherwise face when managing ACLs directly

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If traditional ACL management is used, then network traffic control is achieved, but the ease of operation decreases due to lack of tailored control

Engineering Contradiction:
Improvepolicy definition easeVSAvoidtailored control capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent enables local quality by allowing different parts of the network to have customized policies tailored to their specific needs. The policy store stores context-aware policies that can be customized for different network segments, applications, or entities, providing localized control rather than uniform ACL rules across the entire network

Inventive Principle:
Principle #3Local quality

3Reliability

If comprehensive network knowledge is required for management, then network security is maintained, but the productivity of network management decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service capabilities where the policy store automatically manages policy storage, retrieval, and enforcement without requiring deep network expertise from users. The system handles the complex translations and enforcement automatically, allowing users to define policies in business terms rather than technical network terms, thereby improving management productivity while maintaining security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10250446B2Distributed policy store
Publication Date: 2019.04.02 CISCO TECHNOLOGY INC
  • US10250446B2 patent drawing
  • US10250446B2 patent drawing
  • US10250446B2 patent drawing

AI summary

The disclosed technology relates to a distributed policy store. A system is configured to locate, in an index, an entry for a network entity, determine, based on the entry, a file identifier for a file containing a record for the network entity and an offset indicating a location of the record in the file. The system is further configured to locate the file in a distributed file system using the file identifier, locate the record in the file using the offset, and retrieve the record.