Dynamic VPN Policy Model for SLA Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Virtual Private Network (VPN) technologies have limitations in dynamically adapting to changes in business-level policies and underlying physical network infrastructure, failing to provide comprehensive and unified enforcement of service-level agreements (SLAs) due to limited abstraction and dynamic policy implementation.
Innovation Solution
An adaptable and dynamic security overlay model with a policy model, a VPN policy resolver, and a closed-loop system that translates high-level business policies into network-level policies, ensuring real-time measurement and adjustment to maintain compliance with SLAs, utilizing a centralized control infrastructure for edge-to-edge IP Overlay Layer 2/3 VPN systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional distributed VPN protocols are used to create VPNs on top of shared network infrastructure, then basic connectivity and security are provided, but the system cannot dynamically adapt to changes in business-level policies and physical network infrastructure
Solution Approach 1:
The patent segments the VPN control system into multiple components: a centralized controller that handles high-level policy decisions, regional controllers that manage local network segments, and network devices that execute specific configurations. This hierarchical segmentation enables dynamic policy adaptation at the controller level while maintaining manageable complexity at each individual device level.
Solution Approach 2:
The patent introduces a centralized controller as an intermediary between business-level policies and network-level implementations. This intermediary translates high-level business requirements into specific network configurations, enabling dynamic adaptation without requiring complex changes at every network device. The controller acts as a mediator that reconciles policy changes with network constraints.
2Reliability
If comprehensive service-level agreement enforcement is implemented across the entire VPN infrastructure, then complete policy compliance is achieved, but the measurement and control overhead increases significantly
Solution Approach 1:
The patent divides SLA enforcement into regional segments managed by local controllers rather than requiring centralized monitoring of all network traffic. Each regional controller measures and enforces policies for its local network segment, achieving comprehensive SLA compliance through distributed measurement that reduces overall control overhead.
Solution Approach 2:
The patent implements measurement and control at appropriate granularities rather than attempting to monitor every packet across the entire network. By focusing measurements on key performance indicators and critical policy violations at regional levels, the system achieves reliable SLA enforcement without excessive measurement overhead.
3Adaptability or versatility
If high-level business policies are directly translated into network-level configurations without abstraction, then policy implementation is straightforward, but the system lacks flexibility to adapt to changing business requirements
Solution Approach 1:
The patent introduces an intermediate abstraction dimension between business-level policies and network-level configurations. The centralized controller operates at this intermediate dimension, translating high-level business intent into specific network parameters. This additional dimensional layer provides flexibility for policy adaptation while maintaining operational simplicity through automated translation.
Solution Approach 2:
The controller serves as an intermediary that maintains policy abstraction layers. It receives high-level business policies, interprets them against current network state, and generates appropriate network-level configurations. This intermediary function preserves policy flexibility while keeping implementation simple through automated policy-to-configuration translation.
4Productivity
If real-time monitoring and dynamic reconfiguration of VPN traffic flows are implemented, then network performance and compliance are optimized, but the processing overhead and response time requirements increase
Solution Approach 1:
The patent segments real-time monitoring into regional responsibilities handled by local controllers rather than requiring centralized processing of all traffic flows. Each regional controller monitors and optimizes traffic within its segment, achieving overall network performance optimization while distributing processing overhead to reduce centralized bottlenecks.
Solution Approach 2:
The system performs preliminary configuration and policy translation in advance through the centralized controller, preparing network devices with pre-computed configurations based on current business policies. This preliminary action reduces real-time processing overhead during traffic flow optimization, as devices can execute pre-prepared configurations with minimal additional processing.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
High-level network policies that represent a virtual private network (VPN) as a high-level policy model are received. The VPN is to provide secure connectivity between connection sites of the VPN based on the high-level network policies. The high-level network policies are translated into low-level device configuration information represented in a network overlay and used for configuring a network underlay that provides the connections sites to the VPN. The network underlay is configured with the device configuration information so that the network underlay implements the VPN in accordance with the high-level policies. It is determined whether the network underlay is operating to direct traffic flows between the connection sites in compliance with the high-level network policies. If it is determined that the network underlay is not operating in compliance, the network underlay is reconfigured with new low-level device configuration information so that the network underlay operates in compliance.