Fabric Policy Enforcement via Control Plane Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems face challenges in consistently enforcing service device policies across distributed networks, particularly in scenarios where service devices become unreachable, leading to security vulnerabilities and disruptions in traffic management.

Innovation Solution

The method involves translating service device policies into network device rules that can be interpreted and enforced by a network device fabric, allowing the fabric to assume enforcement responsibilities through fabric-wide deployment, with fail-safe mechanisms for unreachability scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service devices are used to enforce policies in distributed networks, then traffic management and access services can be provided, but network security vulnerabilities arise when service devices become unreachable

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a control plane service (CPS) as an intermediary between service devices and the network fabric. The CPS translates service device policies into network device rules and manages their deployment across the fabric-wide network devices. This mediator ensures that when service devices become unreachable, the network fabric can continue to enforce policies consistently through the CPS-managed rules, thereby maintaining network security while reducing dependency on individual service devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service device policies are enforced locally at service devices, then policy enforcement is simple, but consistent policy enforcement across the network cannot be guaranteed when service devices are unreachable

Engineering Contradiction:
Improveconsistent policy enforcementVSAvoidpolicy deployment complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges policy enforcement capabilities from individual service devices into a unified network fabric-wide enforcement mechanism. The CPS consolidates policy management by translating service device policies into standardized network device rules that are deployed across multiple network devices simultaneously. This merging ensures consistent policy enforcement throughout the network, eliminating gaps that occur when service devices are unreachable, while the automated translation and deployment processes reduce operational complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If fabric-wide deployment of network device rules is implemented, then network security is maintained even when service devices are unreachable, but the complexity of rule translation and deployment increases

Engineering Contradiction:
Improvenetwork securityVSAvoidrule translation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control plane service implements self-service automation in the policy translation and deployment process. The CPS automatically translates service device policies into network device rules without requiring manual intervention, and autonomously manages the fabric-wide deployment across network devices. This self-service approach maintains network security through consistent fabric-wide enforcement while reducing the operational complexity burden on network administrators, as the system handles the translation and deployment complexity automatically.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11349715B2Method and system for consistent policy enforcement through fabric offloading
Publication Date: 2022.05.31 ARISTA NETWORKS INC
  • US11349715B2 patent drawing
  • US11349715B2 patent drawing
  • US11349715B2 patent drawing

AI summary

Methods and systems for managing network device fabrics. The methods and systems may entail the re-assignment of enforcement responsibilities, pertinent to one or more traffic management and/or access rules, from a service device to a network device fabric.