Endpoint-Aware Local Policy Enforcement for Real-Time Network Decisions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized policy enforcement models struggle with scalability and efficiency due to their inability to track local information, leading to suboptimal performance and difficulty in making real-time policy decisions for diverse endpoints.

Innovation Solution

Implementing a local policy enforcement system with a co-located policy controller and enforcement engine near endpoints, which retrieves and applies endpoint-specific policies based on metadata, enabling real-time decision-making and improved resource utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If centralized policy enforcement models are used, then policy decisions can be made uniformly across all endpoints, but scalability is limited and real-time local information cannot be tracked

Engineering Contradiction:
Improvepolicy decision adaptabilityVSAvoidsystem scalability
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized policy enforcement system into distributed policy enforcement points located at network edges and endpoints. Each policy enforcement point independently evaluates local metadata and applies policies, eliminating the single-point bottleneck of centralized models while maintaining policy consistency through standardized metadata schemas and enforcement rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by enabling policy enforcement decisions to be made at the local endpoint or network edge based on endpoint-specific metadata (e.g., device type, location, user role). This allows policies to be customized for local conditions while maintaining overall system coherence, resolving the contradiction between uniform policy application and local adaptability.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If centralized policy enforcement models are used, then uniform policy application is achieved, but efficiency is reduced due to inability to access local information

Engineering Contradiction:
Improvepolicy application uniformityVSAvoidpolicy decision efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent introduces metadata as an intermediary that carries endpoint-specific information (device characteristics, location, user context) from endpoints to policy enforcement points. This intermediary mechanism enables efficient local policy decisions by providing necessary context without requiring centralized processing of all endpoint data, thus maintaining uniformity while improving efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables policy enforcement points and endpoints to self-evaluate and self-enforce policies based on local metadata and predefined policy rules. This self-service capability eliminates the need for centralized real-time decision-making for each policy evaluation, significantly improving efficiency while maintaining consistent policy application through standardized enforcement logic.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If centralized policy enforcement is implemented, then general policy information is available, but real-time local information tracking is impossible

Engineering Contradiction:
Improvepolicy information availabilityVSAvoidlocal information tracking
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The patent adds a new dimension to policy enforcement by incorporating endpoint-specific metadata (device type, location, user role, temporal context) alongside traditional policy information. This multi-dimensional information structure enables both comprehensive policy availability and precise local information tracking simultaneously, as enforcement decisions consider both general policy requirements and specific endpoint characteristics.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12360781B2On-path dynamic policy enforcement and endpoint-aware policy enforcement for endpoints
Publication Date: 2025.07.15 CISCO TECHNOLOGY INC
  • US12360781B2 patent drawing
  • US12360781B2 patent drawing
  • US12360781B2 patent drawing

AI summary

Systems, methods, and computer-readable media for locally applying endpoint-specific policies to an endpoint in a network environment. A network device local to one or more endpoints in a network environment can receive from a centralized network controller one or more network-wide endpoint policies. A first endpoint of the one or more endpoints can be configured to inject policy metadata into first data traffic. Policy metadata injected into the first traffic data can be received from the first endpoint. The network device can determine one or more first endpoint-specific polices for the first endpoint by evaluation the first policy metadata with respect to the one or more network-wide endpoint policies. As follows, the one or more first endpoint-specific policies can be applied to control data traffic associated with the first endpoint.