Dynamic Security Policy Provisioning for Virtual Machine Mobility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complexity in network configuration and security policy management leads to increased error rates and difficulty in troubleshooting, especially in larger networks with numerous configuration policies and policy modifications.

Innovation Solution

A flexible, on-demand/dynamic security provisioning model is implemented, which automatically provisions and removes blacklist and whitelist rules based on virtual machine mobility, with implicit priority management to ensure secure communication between endpoint groups in a software-defined network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a wide array of configuration options is provided to network operators for tailoring the network, then flexibility and control over the network are improved, but the complexity of the network increases

Engineering Contradiction:
Improveflexibility and controlVSAvoidnetwork complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

An automated policy management system acts as an intermediary between network operators and the complex configuration options. The system receives high-level policy intentions from operators and automatically translates them into specific configuration parameters, thereby maintaining flexibility and control while shielding operators from the underlying complexity of numerous configuration options.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network configuration system performs self-service by automatically generating, validating, and applying configuration parameters based on policy definitions. The system autonomously manages the complexity of multiple configuration options without requiring manual intervention, thereby preserving operator flexibility while eliminating the burden of managing complex configurations.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If a higher volume of configuration policies and policy modifications is implemented in larger networks, then network customization and control are improved, but the configuration process becomes increasingly error prone

Engineering Contradiction:
Improvenetwork customizationVSAvoidconfiguration error rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The automated policy management system implements feedback mechanisms that continuously monitor configuration policies and their applications. The system validates policy modifications before deployment, detects conflicts or errors automatically, and provides feedback to operators for correction, thereby enabling extensive network customization while maintaining high configuration reliability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary validation and verification of configuration policies before they are deployed to the network. By pre-checking policy compatibility, syntax correctness, and logical consistency, the system prevents errors from being introduced into the network configuration, allowing for extensive customization without increasing error rates.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If numerous security policies and configuration options are managed manually in complex networks, then policy granularity and control are improved, but troubleshooting errors and managing policies becomes extremely difficult

Engineering Contradiction:
Improvepolicy granularityVSAvoidtroubleshooting difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of repair

Solution Approach 1:

The automated policy management system implements comprehensive feedback and logging mechanisms that track the lifecycle of each security policy. The system automatically logs policy creations, modifications, and applications, and provides real-time feedback on policy effectiveness and conflicts. This enables fine-grained policy control while dramatically simplifying troubleshooting through automated diagnostics and audit trails.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system acts as an intermediary layer between operators and the complex security policy infrastructure. It provides automated policy deployment, validation, and monitoring capabilities that maintain fine-grained policy control while abstracting away the complexity of managing numerous security policies. The intermediary automatically handles policy propagation, conflict resolution, and troubleshooting, making policy management tractable even in large networks with extensive granularity requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3769471B1On-demand security policy provisioning
Publication Date: 2025.04.16 CISCO TECHNOLOGY INC
  • EP3769471B1 patent drawingFigure 1
  • EP3769471B1 patent drawingFigure 2
  • EP3769471B1 patent drawingFigure 3

AI summary

Systems, methods, and computer-readable media for on-demand security provisioning using whitelist and blacklist rules are provided. A system in a network including a plurality of pods can configure security policies for a first endpoint group (EPG) in a first pod, the security policies including blacklist and whitelist rules defining traffic security enforcement rules for communications between the first EPG and a second EPG in a second pods in the network. The system can assign respective implicit priorities to the one or more security policies based on a respective specificity of each policy, wherein more specific policies are assigned higher priorities than less specific policies. The system can respond to a detected move of a virtual machine associated with the first EPG to a second pod in the network by dynamically provisioning security policies for the first EPG in the second pod and removing security policies from the first pod.