Dynamic VPN Policy Model for SLA Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Virtual Private Network (VPN) technologies have limitations in dynamically adapting to changes in business-level policies and underlying physical network infrastructure, failing to provide comprehensive and unified enforcement of service-level agreements (SLAs) due to limited abstraction and dynamic policy implementation.

Innovation Solution

An adaptable and dynamic security overlay model with a policy model, a VPN policy resolver, and a closed-loop system that translates high-level business policies into network-level policies, ensuring real-time measurement and adjustment to maintain compliance with SLAs, utilizing a centralized control infrastructure for edge-to-edge IP Overlay Layer 2/3 VPN systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional distributed VPN protocols are used to create VPNs on top of shared network infrastructure, then basic connectivity and security are provided, but the system cannot dynamically adapt to changes in business-level policies and physical network infrastructure

Engineering Contradiction:
Improvedynamic policy adaptationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the VPN control system into multiple components: a centralized controller that handles high-level policy decisions, regional controllers that manage local network segments, and network devices that execute specific configurations. This hierarchical segmentation enables dynamic policy adaptation at the controller level while maintaining manageable complexity at each individual device level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized controller as an intermediary between business-level policies and network-level implementations. This intermediary translates high-level business requirements into specific network configurations, enabling dynamic adaptation without requiring complex changes at every network device. The controller acts as a mediator that reconciles policy changes with network constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive service-level agreement enforcement is implemented across the entire VPN infrastructure, then complete policy compliance is achieved, but the measurement and control overhead increases significantly

Engineering Contradiction:
ImproveSLA complianceVSAvoidmeasurement and control overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides SLA enforcement into regional segments managed by local controllers rather than requiring centralized monitoring of all network traffic. Each regional controller measures and enforces policies for its local network segment, achieving comprehensive SLA compliance through distributed measurement that reduces overall control overhead.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements measurement and control at appropriate granularities rather than attempting to monitor every packet across the entire network. By focusing measurements on key performance indicators and critical policy violations at regional levels, the system achieves reliable SLA enforcement without excessive measurement overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If high-level business policies are directly translated into network-level configurations without abstraction, then policy implementation is straightforward, but the system lacks flexibility to adapt to changing business requirements

Engineering Contradiction:
Improvepolicy flexibilityVSAvoidpolicy implementation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediate abstraction dimension between business-level policies and network-level configurations. The centralized controller operates at this intermediate dimension, translating high-level business intent into specific network parameters. This additional dimensional layer provides flexibility for policy adaptation while maintaining operational simplicity through automated translation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The controller serves as an intermediary that maintains policy abstraction layers. It receives high-level business policies, interprets them against current network state, and generates appropriate network-level configurations. This intermediary function preserves policy flexibility while keeping implementation simple through automated policy-to-configuration translation.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If real-time monitoring and dynamic reconfiguration of VPN traffic flows are implemented, then network performance and compliance are optimized, but the processing overhead and response time requirements increase

Engineering Contradiction:
Improvenetwork performance optimizationVSAvoidprocessing overhead
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments real-time monitoring into regional responsibilities handled by local controllers rather than requiring centralized processing of all traffic flows. Each regional controller monitors and optimizes traffic within its segment, achieving overall network performance optimization while distributing processing overhead to reduce centralized bottlenecks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary configuration and policy translation in advance through the centralized controller, preparing network devices with pre-computed configurations based on current business policies. This preliminary action reduces real-time processing overhead during traffic flow optimization, as devices can execute pre-prepared configurations with minimal additional processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3338414B1Dynamic VPN policy model with encryption and traffic engineering resolution
Publication Date: 2020.07.29 CISCO TECHNOLOGY INC
  • EP3338414B1 patent drawingFigure 1
  • EP3338414B1 patent drawingFigure 2
  • EP3338414B1 patent drawingFigure 3

AI summary

High-level network policies that represent a virtual private network (VPN) as a high-level policy model are received. The VPN is to provide secure connectivity between connection sites of the VPN based on the high-level network policies. The high-level network policies are translated into low-level device configuration information represented in a network overlay and used for configuring a network underlay that provides the connections sites to the VPN. The network underlay is configured with the device configuration information so that the network underlay implements the VPN in accordance with the high-level policies. It is determined whether the network underlay is operating to direct traffic flows between the connection sites in compliance with the high-level network policies. If it is determined that the network underlay is not operating in compliance, the network underlay is reconfigured with new low-level device configuration information so that the network underlay operates in compliance.