Intent-Based Orchestration Platform for SASE Network Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SASE platforms face complexity in coordinating and provisioning network and security services across multiple vendors and locations, requiring sophisticated orchestration and automation to manage diverse network devices and security systems.

Innovation Solution

A cloud-based orchestration and automation (O&A) platform that retrieves change requests from remote work queues, categorizes them into specific change classes, and assigns automation engines to perform tasks on configurable endpoints, including SASE platforms, to effectuate the changes without requiring specific knowledge of the endpoints or vendors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a web interface presents an abstracted set of security and network controls to simplify user interactions, then ease of operation is improved, but device complexity increases as the platform must coordinate and provision many technologies across multiple vendors and locations

Engineering Contradiction:
Improveuser interaction simplicityVSAvoidplatform coordination complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

An orchestration layer is introduced as an intermediary between the simplified web interface and the complex underlying infrastructure. This orchestration layer handles the coordination and provisioning of multiple technologies across different vendors and locations, allowing users to interact with simple abstracted controls while the complex coordination tasks are performed automatically in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional layers: a user-facing web interface layer that provides simplified controls, an orchestration layer that handles coordination logic, and an infrastructure layer that manages the actual network and security technologies. This segmentation allows each layer to be optimized independently, with the orchestration layer absorbing the coordination complexity away from the user interface.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the platform pushes complexities of coordination and provisioning onto the SASE platform, then ease of operation for users is improved, but the system requires sophisticated orchestration and automation infrastructure

Engineering Contradiction:
Improveuser interface simplicityVSAvoidorchestration automation requirement
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The orchestration platform implements self-service capabilities through automated workflows that can independently coordinate and provision technologies without requiring manual intervention. The system automatically translates high-level user requests into specific configuration tasks, executes them across the infrastructure, and manages the provisioning process autonomously, reducing the need for expert human operators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The platform performs preliminary actions by pre-configuring orchestration workflows and automation rules in advance. When users submit requests through the simplified interface, the pre-established automation frameworks are already in place to handle the coordination tasks, eliminating the need for complex real-time decision-making and reducing the sophistication required at runtime.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the platform manages diverse network devices and security systems from multiple vendors, then adaptability is improved, but device complexity and integration challenges increase

Engineering Contradiction:
Improvemulti-vendor supportVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The orchestration platform implements a universal abstraction layer that can interface with multiple different vendor technologies through standardized protocols and APIs. This universal layer translates vendor-specific commands into a common internal representation, allowing the system to manage diverse network devices and security systems from different vendors through a single unified interface, thereby supporting multi-vendor environments without proportionally increasing integration complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12333335B2Intent-based orchestration of independent automations
Publication Date: 2025.06.17 FORTINET INC
  • US12333335B2 patent drawing
  • US12333335B2 patent drawing
  • US12333335B2 patent drawing

AI summary

Systems and methods for intent-based orchestration of independent automations are provided. Examples described herein alleviate the complexities and technical challenges associated with deploying, provisioning, configuring, and managing configurable endpoints, including network devices, network security systems, cloud-based security services (e.g., provided by or representing a Secure Access Service Edge (SASE) platform), and other infrastructure, on behalf of numerous customers (or tenants). For example, customer intent may be automatically translated into concrete jobs and tasks that operate to make changes to one or more of the configurable endpoints so as to insulate the user from being required to know which configurable endpoint(s) need(s) to change, which vendor supports a given configurable endpoint, and/or vendor specific issues involved in changing the configurable endpoints.