Logical Multi-Dimensional Label Policy for Server Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional server management policies struggle with expressing fine-grained, abstract, and natural rules due to their reliance on low-level constructs like IP addresses and network interfaces, making it difficult to manage servers within an administrative domain effectively.

Innovation Solution

A method and system that quarantine a managed server by modifying its description, updating cached actor-sets, and determining relevant updates to isolate it within the administrative domain, using a logical multi-dimensional label-based policy model to implement an administrative domain-wide management policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional policies reference physical devices and use low-level constructs such as IP addresses and network interfaces, then device identification is precise, but policy expression becomes complex and difficult to manage

Engineering Contradiction:
Improvepolicy expressionVSAvoidpolicy structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a logical dimension layer above the physical device layer. Instead of managing policies solely through physical constructs (IP addresses, network interfaces), the system adds logical constructs (labels, groups, roles) that organize devices conceptually. This dimensional transformation allows policies to be expressed in terms of logical relationships rather than low-level technical details, simplifying policy creation and management while maintaining precise device identification through the mapping between logical and physical layers.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Manufacturing precision

If fine-grained policies are expressed using low-level constructs, then device control is precise, but policy writing becomes difficult and abstract

Engineering Contradiction:
Improvepolicy controlVSAvoidpolicy writing
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent introduces logical constructs as intermediary elements between the policy writer and the physical devices. Labels, groups, and roles serve as mediators that translate high-level policy intentions into precise device control actions. For example, instead of writing policies that directly reference IP addresses and network interfaces, administrators define logical groups representing device categories or roles, and policies are then written in terms of these groups. The system automatically maps these logical references to the underlying physical devices, maintaining precise control while simplifying the policy writing process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If servers are managed individually using conventional methods, then device-specific control is achieved, but domain-wide management efficiency decreases

Engineering Contradiction:
Improvemanagement efficiencyVSAvoiddevice-specific control
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent creates a multi-functional policy management system that simultaneously handles both individual device control and domain-wide management. Logical constructs serve multiple purposes: they enable bulk policy application across groups of devices (improving efficiency) while also supporting device-specific policies through individual labeling. The same logical framework can express policies that apply to all servers, to specific subsets based on roles or locations, or to individual devices, providing universal applicability across different management granularities without sacrificing adaptability to specific device needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11503042B2Distributed network security using a logical multi-dimensional label-based policy model
Publication Date: 2022.11.15 ILLUMIO INC
  • US11503042B2 patent drawing
  • US11503042B2 patent drawing
  • US11503042B2 patent drawing

AI summary

A managed server (MS) within an administrative domain is quarantined. The administrative domain includes multiple MSs that use management instructions to configure management modules so that the configured management modules implement an administrative domain-wide management policy that comprises a set of one or more rules. The quarantined MS is isolated from other MSs. A description of the MS is modified to indicate that the MS is quarantined, thereby specifying a description of the quarantined MS. Cached actor-sets are updated to indicate the quarantined MS's changed state, thereby specifying updated actor-sets. A determination is made regarding which updated actor-sets are relevant to an other MS, thereby specifying currently-relevant updated actor-sets. A determination is made regarding whether the currently-relevant updated actor-sets differ from actor-sets previously sent to the other MS. Responsive to determining that the currently-relevant updated actor-sets are identical to the previously-sent actor-sets, no further action is taken.