Dynamic Prefix Learning for Intent-Based SD-WAN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to implement fine-grained intent-based security policies in software-defined wide area networks (SD-WAN) due to the dynamic learning of LAN segment prefixes, which are not synchronized across sites without manual intervention, leading to potential human errors and misconfigurations.

Innovation Solution

A network service orchestrator controller translates intent-based security policies into segment-specific queries, automatically updating forwarding tables in CPE devices with dynamically learned LAN segment prefixes, enabling distributed synchronization without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual synchronization of network segment prefixes is used, then configuration accuracy is improved, but operation complexity and time consumption increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidsynchronization time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automatic self-synchronization where the network management system automatically queries and updates network segment prefixes at remote sites without requiring manual administrator intervention. The CPE devices autonomously learn and report prefix changes, eliminating manual configuration while maintaining accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback mechanisms where CPE devices monitor network segment prefix changes and automatically report them to the service orchestrator controller. This feedback loop ensures real-time synchronization of network state across all sites without manual intervention.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If manual configuration of security policies is used, then policy precision is improved, but human error increases

Engineering Contradiction:
Improvepolicy precisionVSAvoiderror rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system automatically translates high-level intent-based security policies into detailed technical security rules without manual configuration. The service orchestrator controller autonomously generates and updates security policies based on learned network segment prefixes, eliminating manual policy creation while maintaining precision through automated intent translation.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated prefix learning is used, then operational efficiency is improved, but configuration accuracy deteriorates

Engineering Contradiction:
Improveoperational efficiencyVSAvoidconfiguration accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The automated prefix learning process incorporates continuous feedback verification where the service orchestrator controller receives and validates prefix information from CPE devices. This feedback mechanism ensures that automatically learned prefixes are accurate and properly synchronized across the network, maintaining configuration precision while achieving operational efficiency.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If distributed synchronization without manual intervention is used, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveautomation levelVSAvoidsynchronization complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system merges the synchronization functionality into the existing service orchestrator controller and CPE device architecture. By integrating prefix learning, querying, and updating operations into the existing SD-WAN control plane, the system achieves automated distributed synchronization without adding significant external complexity to the network infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12368757B2Intent-based enterprise security using dynamic learning of network segment prefixes
Publication Date: 2025.07.22 JUNIPER NETWORKS INC
  • US12368757B2 patent drawing
  • US12368757B2 patent drawing
  • US12368757B2 patent drawing

AI summary

In an example, systems and methods enable automatic implementation of intent-based security policies in a network system, such as a software-defined wide area network system, in which network segment prefixes for network segments at one or more sites are dynamically learned. A service orchestrator controller translates an intent-based security policy input by a user to a security policy for a first site. The security policy for the first site specifies a segment-specific queryable resource associated with a second site. To implement the security policy, a device associated with the first site queries the segment-specific queryable resource associated with the second site, and updates one or more forwarding tables of the device with the network segment prefixes associated with one or more network segments at the second site received in response to the query. The first site forwards network traffic to the second site based on the updated forwarding tables.