Dynamic Edge Proxy Placement for Policy-Based Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face a dilemma between moving to cloud-delivered solutions or investing in additional on-premise appliances due to the high costs of routing packets to cloud-computing nodes for security functions, leading to unnecessary transit expenses and inefficient bandwidth usage.

Innovation Solution

Techniques for dynamically operationalizing cloud-delivered workload functions at edge network nodes, splitting control and data planes, allowing centralized intent and policy control, and enabling dynamic proxy creation based on first packet inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If packets are routed to cloud-computing nodes for security functions, then centralized security control is achieved, but transit expenses and bandwidth usage increase significantly

Engineering Contradiction:
Improvecentralized security controlVSAvoidtransit expenses and bandwidth usage
Core Design Contradiction:
Extent of automationVSLoss of energy

Solution Approach 1:

The patent segments the security function into two parts: the control plane remains centralized in the cloud, while the data plane (packet processing) is distributed to edge network nodes. This segmentation allows packets to be processed locally at the edge without being routed to the cloud, reducing transit expenses and bandwidth usage while maintaining centralized control over security policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component at the edge network node that acts as a local proxy for security functions. This intermediary receives packets locally, applies security policies received from the centralized cloud controller, and processes packets without requiring them to be routed to the cloud. This intermediary approach maintains centralized control while eliminating the need to route packets to cloud nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If physical appliances are deployed at campus to boost on-premise capacities, then security functions are performed locally, but infrastructure investment and device complexity increase

Engineering Contradiction:
Improveon-premise security capacityVSAvoidinfrastructure investment
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal edge network node that can perform multiple functions including security processing, routing, and policy enforcement. Rather than deploying specialized physical appliances for each function, the system uses multi-functional edge nodes that can dynamically execute different security functions based on policy requirements, reducing infrastructure investment while maintaining on-premise security capacity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic function deployment where security capabilities are not statically configured in physical appliances but are dynamically instantiated at edge network nodes based on real-time policy requirements. This dynamic approach allows the system to adapt security capacity to actual needs without requiring permanent infrastructure investments in specialized hardware.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If cloud-delivered solutions are adopted, then scalability and elasticity are improved, but dependency on cloud connectivity and transit costs increase

Engineering Contradiction:
Improvescalability and elasticityVSAvoidcloud connectivity dependency and transit costs
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cloud-delivered solution into control plane functions (remaining in the cloud for scalability) and data plane functions (executed locally at edge nodes). This segmentation allows the system to maintain scalability and elasticity through centralized cloud management while eliminating the need to route data traffic to the cloud, thereby reducing transit costs and cloud connectivity dependency.

Inventive Principle:
Principle #1Segmentation

4Reliability

If proxies are deployed to enforce security policies, then policy control is enhanced, but additional network hops and latency are introduced

Engineering Contradiction:
Improvepolicy controlVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent positions the proxy function as an intermediary at the edge network node rather than in the cloud or as a separate network appliance. This local intermediary approach enables policy control to be enforced at the packet's first point of contact at the edge, eliminating additional network hops to remote proxies and reducing latency while maintaining enhanced policy control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4483561B1Dynamic proxy placement for policy-based routing
Publication Date: 2026.02.04 CISCO TECHNOLOGY INC
  • EP4483561B1 patent drawingFigure 1
  • EP4483561B1 patent drawingFigure 2
  • EP4483561B1 patent drawingFigure 3

AI summary

Techniques for operationalizing workloads at edge network nodes, while maintaining centralized intent and policy controls. The techniques may include storing, in a cloud‑computing network, a workload image that includes a function capability. The techniques may also include receiving, at the cloud-computing network, a networking policy associated with an enterprise network. Based at least in part on the networking policy, a determination may be made at the cloud-computing network that the function capability is to be operationalized on an edge device of the enterprise network. The techniques may also include sending the workload image to the edge device to be installed on the edge device to operationalize the function capability. In some examples, the function capability may be a security function capability (e.g., proxy, firewall, etc.), a routing function capability (e.g., network address translation, load balancing, etc.), or any other function capability.