I2NSF YANG Data Model for Centralized NSF Capability Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security management systems lack a centralized method to effectively manage and integrate various capabilities of network security functions (NSFs), leading to inefficiencies in policy enforcement and conflict resolution across heterogeneous NSF vendors.

Innovation Solution

A YANG data model and framework for the Interface to Network Security Functions (I2NSF) that allows for centralized management of NSF capabilities, including time, event, condition, action, resolution strategy, and default action capabilities, enabling secure policy rule execution and conflict resolution through a standardized interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a centralized management system for NSF capabilities is implemented, then the ability to manage and integrate various NSF capabilities is improved, but the system complexity increases

Engineering Contradiction:
Improvecapability managementVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a capability information model as an intermediary layer between the security controller and diverse NSF vendors. This model standardizes capability representation using structured data elements (time capability, event capability, condition capability, action capability, resolution strategy capability, default action capability), allowing the system to manage heterogeneous NSF capabilities without direct complex interactions with each vendor's proprietary interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If heterogeneous NSF vendors are integrated without standardization, then vendor diversity and capability options increase, but policy enforcement efficiency decreases

Engineering Contradiction:
Improvevendor diversityVSAvoidpolicy enforcement efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent creates a universal capability information model that can represent multiple types of NSF capabilities (time, event, condition, action, resolution strategy, default action) through a common structured framework. This universal model enables the security controller to efficiently manage and enforce policies across diverse NSF vendors without requiring vendor-specific processing logic, thereby maintaining both vendor diversity and policy enforcement efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If manual management of NSF capabilities is used, then system complexity is reduced, but administrative burden and time consumption increase

Engineering Contradiction:
Improvemanagement complexityVSAvoidadministrative time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent implements a structured capability information model that enables automated capability registration, representation, and matching. The system automatically processes capability information from NSF vendors, structures it according to the standardized model, and facilitates automated policy enforcement decisions. This self-service mechanism reduces the need for manual administrative intervention while maintaining manageable system complexity through structured data organization.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11516258B2I2NSF capability YANG data model
Publication Date: 2022.11.29 RES & BUSINESS FOUND SUNGKYUNKWAN UNIV
  • US11516258B2 patent drawing
  • US11516258B2 patent drawing
  • US11516258B2 patent drawing

AI summary

The present disclosure is a method for managing capabilities of network security functions (NSF) by a security controller in a security management system.