Natural Language Security Policy Setup for Ambiguous Intent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to creating and managing intent-based security policies involve cumbersome guided interactive workflows, requiring administrators to repeatedly select from hundreds of entities and parameters, making the process laborious and time-consuming, especially in large enterprise networks.

Innovation Solution

A system that allows administrators to configure security policies using natural language, leveraging AI to interpret and clarify intents, generate policy clauses, and automate the process, reducing the need for manual selection and simplifying policy creation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional guided interactive workflows are used to configure security policies, then policy configuration can be performed with structured guidance, but the process becomes laborious and time-consuming when repeated hundreds of times

Engineering Contradiction:
ImprovePolicy configuration easeVSAvoidTime required for policy creation
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces the mechanical interactive workflow system with an AI-based natural language processing system. Instead of requiring administrators to manually navigate guided workflows and select from hundreds of entities, the system uses NLP to interpret natural language requests and automatically generate security policies, substituting manual mechanical operations with automated AI processing

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service policy configuration where administrators can directly express their security needs in natural language without requiring extensive training on complex configuration interfaces. The AI system automatically handles the translation from natural language to structured policy format, allowing users to perform configuration tasks independently without manual intervention in the policy generation process

Inventive Principle:
Principle #25Self-service

2Manufacturing precision

If administrators manually select from hundreds of entities and parameters, then precise policy control is achieved, but the process becomes cumbersome and reduces productivity

Engineering Contradiction:
ImprovePolicy configuration precisionVSAvoidPolicy creation efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent replaces the mechanical selection process with AI-based natural language understanding. Instead of manually navigating through hundreds of entities and parameters, the system uses NLP to interpret the administrator's intent from natural language and automatically generates precise policies, maintaining configuration precision while eliminating the cumbersome manual selection process

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an AI intermediary layer between the administrator and the policy configuration system. This intermediary translates natural language requests into precise structured policies, acting as a mediator that bridges the gap between simple user input and complex policy requirements, thereby maintaining precision without requiring manual selection from numerous options

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12477009B2Intent-based policy configuration using natural language
Publication Date: 2025.11.18 CISCO TECHNOLOGY INC
  • US12477009B2 patent drawing
  • US12477009B2 patent drawing
  • US12477009B2 patent drawing

AI summary

Techniques are described for providing a natural language network security policy assistant for allowing a network administrator to implement network security policies using natural language security policy requests. A natural language request can be received by a user and can be translated using Artificial Intelligence into one or more security policy clauses. If the natural language security policy request leads to ambiguities with regard to intended security policies, one or more clarifying questions can be generated as natural language questions and sent to the user for clarification. One or more security policies can be implemented based on the one or more security policy clauses generated in response to the natural language security policy request and/or the natural language response to the clarifying questions.