Logical Multi-Dimensional Label Policy for Server Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional server management policies are difficult to express in a fine-grained, abstract, and natural way due to their reliance on low-level constructs like IP addresses and network interfaces, making it challenging to implement effective administrative domain-wide management policies.

Innovation Solution

A method and system for quarantining a managed server within an administrative domain by modifying its description, updating cached actor-sets, and determining relevant updates to enforce a management policy, which isolates the server if a network attack or vulnerability is detected, using a logical multi-dimensional label-based policy model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional policies reference physical devices and low-level constructs like IP addresses, then device identification is straightforward, but policy expression becomes difficult and coarse-grained

Engineering Contradiction:
Improvepolicy expressionVSAvoidpolicy structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a logical dimension layer above the physical device layer. Instead of managing policies solely through physical identifiers (IP addresses, device names), the system adds logical identifiers and abstract policy constructs that operate at a higher level of abstraction. This dimensional addition allows policies to be expressed in terms of logical relationships and functional requirements rather than low-level technical details, resolving the contradiction between ease of policy expression and the inherent complexity of device-level management.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces logical identifiers and abstract policy constructs as intermediaries between the physical device layer and the policy management layer. These intermediaries (logical device names, service identifiers, policy templates) mediate the connection between concrete physical devices and abstract policy requirements, enabling finer-grained and more natural policy expression without directly managing the complexity of physical device identifiers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If policies are expressed in low-level constructs, then implementation is direct, but fine-grained control is difficult to achieve

Engineering Contradiction:
Improvepolicy granularityVSAvoidpolicy writing
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent segments policy management into multiple hierarchical levels: physical device identification, logical device identification, service-level policies, and application-level policies. This segmentation allows each layer to operate at its appropriate level of granularity, with abstract logical constructs handling fine-grained control requirements while physical identifiers provide the foundational layer. The segmented structure enables precise policy control without requiring policymakers to write complex low-level configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

By adding the logical identifier dimension, the system enables fine-grained policy differentiation without increasing the complexity of policy writing. Logical identifiers provide an additional degree of freedom that allows policies to be distinguished and controlled at a finer level (e.g., differentiating between different services or applications on the same device) while maintaining ease of expression through abstract, human-readable constructs.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If server isolation is implemented through physical separation, then security is enhanced, but resource utilization decreases

Engineering Contradiction:
Improveserver isolationVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing isolation policies selectively rather than universally. Instead of physically separating all servers, the system applies isolation measures only to specific servers or services that require enhanced security or compliance. The logical identifier framework enables differentiation of isolation requirements across different servers, allowing critical servers to be isolated while non-critical servers share resources, thus maintaining both security and resource utilization efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic isolation capabilities where the isolation state of servers can be changed based on security requirements, threat levels, or compliance needs. The logical policy framework allows isolation to be adjusted in real-time without physical reconfiguration - servers can be dynamically isolated or reintegrated into shared resource pools based on current security conditions, optimizing both security and resource utilization adaptively.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3066581B1Distributed network security using a logical multi-dimensional label-based policy model
Publication Date: 2019.06.26 ILLUMIO INC
  • EP3066581B1 patent drawingFigure 1
  • EP3066581B1 patent drawingFigure 2
  • EP3066581B1 patent drawingFigure 3

AI summary

A managed server (MS) within an administrative domain is quarantined. The administrative domain includes multiple MSs that use management instructions to configure management modules so that the configured management modules implement an administrative domain- wide management policy that comprises a set of one or more rules. The quarantined MS is isolated from other MSs. A description of the MS is modified to indicate that the MS is quarantined, thereby specifying a description of the quarantined MS. Cached actor-sets are updated to indicate the quarantined MS's changed state, thereby specifying updated actor- sets. A determination is made regarding which updated actor-sets are relevant to an other MS, thereby specifying currently-relevant updated actor-sets. A determination is made regarding whether the currently-relevant updated actor-sets differ from actor-sets previously sent to the other MS. Responsive to determining that the currently-relevant updated actor-sets are identical to the previously-sent actor-sets, no further action is taken.