Intent-Based Networking Security Posture Alignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In intent-based networking, the security configuration resulting from abstract intents is often complex and difficult for network operators to understand and maintain, as security elements are intertwined with communication configurations, making it hard to ensure the network's security posture aligns with intended operations.

Innovation Solution

A method that determines changes to the security posture from candidate network configurations and compares them to the intended security settings, allowing for amendments to the intent to improve correspondence, using an orchestration engine and security co-pilot to provide transparent and actionable feedback, enabling network operators to explicitly approve or modify security configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If the orchestration engine automatically converts intent to network configuration including security elements, then the security configuration is automatically managed and the operator does not need to spend detailed thoughts on security, but the security configuration becomes a mixture of communication and security elements that is difficult to disentangle for network operators

Engineering Contradiction:
Improveautomatic security configuration managementVSAvoidunderstandability of security configuration
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent segments the configuration into communication elements and security elements by introducing a separate security posture representation. The orchestration engine now produces two distinct outputs: the network configuration for communication and a separate security posture description. This segmentation allows operators to view and understand security configurations independently from communication configurations, resolving the mixing problem while maintaining automatic management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security posture representation that mediates between the automated orchestration engine and the human operator. This intermediary layer translates the automated security decisions into a form that is understandable and maintainable for operators, allowing them to review and approve security changes without needing to understand the complex automated configuration process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the orchestration engine produces concrete network configuration from abstract intent, then the desired communication is realized, but the security consequences are not visible to network operators in the space of intents

Engineering Contradiction:
Improveefficiency of network configurationVSAvoidvisibility of security consequences
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent adds another dimension to the configuration process by introducing a separate security posture dimension. Instead of embedding security information within the communication configuration, the system creates a parallel security posture representation that captures security consequences independently. This dimensional separation makes security consequences visible and reviewable without interfering with the efficient automated configuration process.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent implements feedback by presenting the determined security posture back to the operator for review and approval. The system provides visible feedback about security consequences in a form that operators can understand, allowing them to make informed decisions about whether to proceed with the configuration. This feedback loop ensures security visibility while maintaining operational efficiency.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If default configuration is used to make applications work out of the box, then functionality is achieved with minimum effort, but more access is granted than would be absolutely necessary

Engineering Contradiction:
Improveease of application deploymentVSAvoidexcessive access rights
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies partial action by separating the communication configuration from the security configuration. Instead of using default configurations that grant excessive access, the system generates minimal necessary security rules based on the specific intent. The orchestration engine determines only the security changes necessary to fulfill the communication intent, avoiding unnecessary access grants while still enabling easy deployment.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the parameter of security rule generation from using fixed default configurations to dynamically determining security rules based on the specific communication intent. The system analyzes the intent parameters and generates security configurations that precisely match the required access needs, reducing excessive access rights while maintaining ease of operation through automated parameter-based rule generation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4485850A1Intent-based networking with improved correspondence between intent and security posture
Publication Date: 2025.01.01 ABB (SCHWEIZ) AG
  • EP4485850A1 patent drawingFigure 1
  • EP4485850A1 patent drawingFigure 2
  • EP4485850A1 patent drawing

AI summary

A computer-implemented method (100) for configuring a communication network (1) based on a given intent (2), said intent (2) comprising at least the providing of a given form of communication, the method (100) comprising the steps of: • determining (110), from the given intent (2), by a given orchestration engine (3), a candidate network configuration (4) that, when implemented, causes the given intent (2) to be realized; • determining (120), from the intent (2), and/or from the candidate network configuration (4), one or more changes (5) to the security posture of the network (1) that result from the candidate network configuration (4); • determining (130), based on at least one given criterion, whether there is sufficient correspondence between the intent (2) and the changes (5) to the security posture; • in response to determining that this correspondence is not sufficient, determining (140) at least one amendment (2a) to the given intent (2) such that, when a new candidate network configuration (4a) is determined by the orchestration engine (3) based on this amendment (2a), there is a better correspondence between the amended intent (2, 2a) and the resulting changes (5a) to the security posture of the network (1); and • implementing (160) the new candidate configuration (4a) in the communication network (1).