Embedded MUD URIs for Automated Network Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise networks face challenges in managing complex network access requirements for software applications, leading to over- or under-provisioning of network access due to strict firewall rules and multiple software vendors with unique access requirements, which complicates the deployment of new software versions.
Innovation Solution
The implementation of Manufacturer Usage Description (MUD) files, where uniform resource identifiers (URIs) are embedded in application metadata or code signing certificates, allowing a network policy server to automatically discover and enforce network access rules based on software updates and deployments, enabling enterprise-wide and individual host policies to manage network access efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual firewall rule updates are implemented for each software version, then network security is maintained, but deployment time and administrative effort increase significantly
Solution Approach 1:
The patent embeds firewall rule requirements directly into the software application binary during the build process. This preliminary action ensures that all necessary network access information is prepared in advance, eliminating the need for manual firewall rule updates during deployment. The network policy server can automatically extract and apply these pre-configured rules, maintaining security while reducing deployment time.
Solution Approach 2:
The software application automatically provides its own network access requirements to the network policy server through embedded metadata. This self-service mechanism eliminates the need for administrators to manually configure firewall rules for each software version. The application essentially configures its own network policy, reducing administrative effort and deployment time while maintaining security through automated policy enforcement.
2Adaptability or versatility
If comprehensive network access is provided to all applications, then application functionality is ensured, but network security and firewall effectiveness are compromised
Solution Approach 1:
The patent implements granular, application-specific network policies by embedding unique firewall rule requirements into each software application. Instead of applying blanket network access rules, the network policy server extracts and enforces customized policies for each application based on its specific needs. This local quality approach ensures each application receives only the network access it requires, maintaining security while preserving functionality.
Solution Approach 2:
The patent segments network access policies into application-specific units by embedding individual firewall rule sets within each software binary. This segmentation allows the network policy server to manage and enforce discrete policies for each application rather than applying monolithic network rules. The segmented approach enables precise control over network access, ensuring security while accommodating diverse application functionality requirements.
3Adaptability or versatility
If multiple software vendors are supported with their unique access requirements, then software diversity is maintained, but firewall rule management complexity increases
Solution Approach 1:
The patent creates a universal mechanism for handling diverse vendor requirements by embedding standardized network policy metadata within software applications from any vendor. The network policy server implements a unified process that automatically extracts, validates, and enforces policies from multiple vendors without requiring vendor-specific configuration procedures. This universal approach maintains software diversity while simplifying firewall rule management through automated, consistent policy handling.
Solution Approach 2:
The network policy server acts as an intermediary between multiple software vendors and the firewall infrastructure. It receives embedded policy information from various vendors, processes and validates the rules, and translates them into appropriate firewall configurations. This intermediary role abstracts the complexity of managing diverse vendor requirements, allowing the system to support multiple vendors while maintaining simple, centralized firewall rule management.
Data Source
AI summary
This disclosure describes techniques for providing manufacturer usage description (MUD) solution to automatically update network access policy for client application software. The method may include embedding metadata in the application binary. The metadata may include MUD uniform resource identifiers (URIs) that may point to MUD files describing the application's network access requirements. The MUD files may be hosted by application vendor's MUD servers. The system may include a network policy server that is able discover the MUD URIs. The MUD URIs may be discovered based on extracting the MUD URIs from the metadata and/or being provision with the set of MUD URIs for trusted applications. The method may include enterprise wide policy and individual host policy for implementation of the MUD files.


