Dynamic Security Scaling for Spine Leaf Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In spine leaf network models, deploying and scaling security solutions is challenging due to the lack of traditional inspection points, leading to manual configuration complexities, latency issues, and inefficiencies in traffic processing and security enforcement, which hinder the ability to maintain low latency and optimize capacity in data centers.

Innovation Solution

Dynamic Security Scaling (DSS) integrates network, security, and orchestration components to automate security provisioning, monitor network and security devices, and dynamically balance traffic processing, using modules like the Network Control Plane, Network Analytics, Network Orchestration, Security Plane Protocol, and Security Data Plane Orchestration to optimize security and network operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration and monitoring of security devices is used, then security policies can be deployed to each appliance, but the provisioning process becomes time-consuming and complex requiring coordination among multiple teams

Engineering Contradiction:
Improvesecurity policy deploymentVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the security management platform automatically provisions and configures security policies across multiple appliances without requiring manual intervention from administrators or coordination between different teams. The platform autonomously monitors device status, detects configuration needs, and deploys appropriate security policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A centralized security management platform acts as an intermediary between network administrators and multiple security appliances. This platform consolidates the configuration management function, allowing administrators to deploy security policies through a single interface while the platform handles the complex coordination and deployment to individual appliances automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple components are configured manually for security deployment, then security coverage can be achieved across the network, but the process requires coordination among network, security, and application IT teams exacerbating lead time

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the configuration management of multiple security appliances and components into a single unified security management platform. This consolidation integrates what would otherwise require separate manual configurations across network, security, and application teams into one automated process, reducing coordination complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security management platform provides universal functionality to manage diverse security appliances and network components through a single interface. It can deploy security policies, monitor device status, and configure multiple types of network security devices simultaneously, eliminating the need for separate configuration processes for different device types and teams.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If static security configuration is used, then security policies can be deployed, but the network cannot be fine-tuned or balanced to keep latency low and optimize capacity

Engineering Contradiction:
Improvesecurity enforcementVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system transitions from static security configurations to dynamic, real-time configuration management. The security management platform continuously monitors network conditions, device capacity, and traffic patterns, automatically adjusting security policy deployment and device resource allocation to optimize performance while maintaining security enforcement. This enables the network to be fine-tuned dynamically rather than relying on fixed configurations.

Inventive Principle:
Principle #15Dynamics

4Reliability

If manual security provisioning is performed, then security policies can be configured, but it blocks the ability to fine tune or balance the network and security infrastructure to optimize capacity

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidnetwork optimization capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security management platform implements continuous feedback loops by monitoring network performance metrics, device capacity utilization, and security policy effectiveness in real-time. Based on this feedback, the system automatically adjusts security configurations and resource allocation to optimize network capacity and reduce latency while maintaining security enforcement, enabling continuous fine-tuning rather than static manual provisioning.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11824897B2Dynamic security scaling
Publication Date: 2023.11.21 PALO ALTO NETWORKS INC
  • US11824897B2 patent drawing
  • US11824897B2 patent drawing
  • US11824897B2 patent drawing

AI summary

An indication that a change associated with adjusting capacity to provide security services to network traffic in a network environment is received. In response to receiving the indication, a set of instructions for configuring at least one of: a network device and a security appliance is determined. As a result of applying the instructions, at least one of: an amount of network traffic provided by the network device to the security appliance will increase, or at least a portion of network traffic that would otherwise be provided by the network device to the security appliance will instead be provided to another security appliance. The set of instructions is transmitted.