Dynamic Endpoint Group Assignment via Policy Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern computing networks, manually configuring endpoints with appropriate settings for end point groups is time-consuming and prone to errors, as administrators must assign endpoints to desired groups, which defines policies such as security settings, leading to potential human errors and inefficiencies.

Innovation Solution

A policy controller dynamically assigns endpoints to end point groups based on attribute data, using group selection rules that consider endpoint attributes, geographical, connectivity, temporal, environmental, and third-party attributes, initially placing endpoints in a default group and then reassigning based on collected data, such as MAC addresses, network traffic, and security assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators manually configure endpoints with appropriate settings for endpoint groups, then policy enforcement is achieved, but the process is time-consuming and prone to errors

Engineering Contradiction:
Improveaccuracy of endpoint groupingVSAvoidtime for configuration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables endpoints to automatically register themselves with the policy controller, which then autonomously collects attribute data and performs grouping based on predefined rules. This self-service mechanism eliminates manual administrator intervention while maintaining accurate policy enforcement through automated attribute-based decision making.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The policy controller continuously collects attribute data from endpoints and uses this feedback to dynamically adjust endpoint group assignments. The system monitors changes in endpoint attributes and automatically reassigns endpoints to appropriate groups, ensuring policies remain current without manual intervention.

Inventive Principle:
Principle #23Feedback

2Reliability

If administrators manually assign endpoints to endpoint groups, then policy enforcement is achieved, but human errors may occur

Engineering Contradiction:
Improveaccuracy of policy assignmentVSAvoidsimplicity of configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The automated system performs endpoint grouping without human intervention, eliminating human errors entirely. The policy controller independently evaluates endpoint attributes against predefined rules and makes assignment decisions, ensuring consistent and accurate policy enforcement while simplifying the operator's role to merely defining initial rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces the mechanical process of manual administrator configuration with an automated computational system. The policy controller uses algorithmic processing of endpoint attributes to determine group assignments, substituting human decision-making with rule-based automated logic that eliminates human error while maintaining operational simplicity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Extent of automation

If dynamic attribute-based assignment is implemented, then automation is improved, but system complexity increases

Engineering Contradiction:
Improveautomation of endpoint groupingVSAvoidcomplexity of policy controller
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The policy controller architecture is segmented into distinct functional modules: attribute data collection, attribute processing, rule evaluation, and endpoint group assignment. This modular segmentation manages complexity by organizing the automated system into independent, manageable components that can be developed and maintained separately while working together to achieve high automation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9825814B2Dynamic attribute based application policy
Publication Date: 2017.11.21 CISCO TECHNOLOGY INC
  • US9825814B2 patent drawing
  • US9825814B2 patent drawing
  • US9825814B2 patent drawing

AI summary

Systems, methods, and computer-readable storage media are provided for dynamically setting an end point group for an end point. An endpoint can be assigned a default end point group when added to a network. For example, the default end point group can be a baseline port/security group which is considered an untrusted group. The end point can then be dynamically assigned an end point group based on a set of group selection rules. For example, the group selection rules can identify an end point group based on the MAC address or other attributes. When the end point is added to the network, the MAC address and/or other attributes of the end point can be determined and used to assign an end point group. As another example, an end point group can be assigned based on the amount of traffic or guest operation system.