Microsegmentation in Heterogeneous Software Defined Networking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Microsegmentation in heterogeneous data centers is limited due to the lack of interoperability among different software-defined network (SDN) solutions and hosts, which hinders effective traffic classification and policy enforcement across various virtualized environments.

Innovation Solution

The method involves classifying endpoints into endpoint groups based on attributes and creating corresponding security groups across different SDN solutions, with network address endpoint groups being generated to enforce policies consistently across diverse virtualized environments, enabling microsegmentation across different types of SDNs, hosts, and virtual switching elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If different SDN solutions and hosts are deployed in a data center, then the data center can support diverse virtualized environments and applications, but microsegmentation is limited due to lack of interoperability among these different platforms

Engineering Contradiction:
Improvesupport for diverse virtualized environmentsVSAvoidmicrosegmentation effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a universal microsegmentation framework that works across multiple SDN platforms (Cisco ACI, VMware NSX, Open vSwitch) and host types (KVM, Hyper-V, Xen, bare metal). The system uses a common policy model and attribute-based endpoint grouping that translates to platform-specific implementations, enabling consistent microsegmentation functionality across heterogeneous environments without requiring platform-specific configurations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer that sits between the diverse SDN platforms and the microsegmentation policy enforcement mechanism. This intermediary standardizes endpoint attributes, groups endpoints by shared characteristics regardless of underlying platform, and enforces policies uniformly across all platforms, effectively mediating between incompatible systems to achieve coherent microsegmentation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If microsegmentation is implemented with fine granularity control, then security services can be provisioned between application tiers and devices within tiers, but the complexity of managing policies across heterogeneous platforms increases

Engineering Contradiction:
Improvesecurity service provisioningVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter space for policy management from platform-specific configurations to a unified attribute-based model. Instead of managing complex platform-specific policies, administrators define policies based on endpoint attributes (application tier, function, security requirements), and the system automatically translates these high-level parameters into platform-specific enforcement rules, dramatically simplifying policy management while maintaining fine-grained security control

Inventive Principle:
Principle #35Parameter changes

3Reliability

If endpoints are classified into groups based on attributes across different virtualized environments, then consistent policy enforcement can be achieved, but the difficulty of detecting and measuring endpoint attributes increases

Engineering Contradiction:
Improvepolicy enforcement consistencyVSAvoidendpoint attribute detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements self-service mechanisms where endpoints automatically advertise their attributes (application tier, function, security requirements) to the microsegmentation system. Hypervisors and SDN agents on each platform automatically collect endpoint information and populate the attribute database without requiring manual configuration or complex detection mechanisms, making the system scalable across heterogeneous platforms

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3459215B1Microsegmentation in heterogeneous software defined networking environments
Publication Date: 2021.03.17 CISCO TECHNOLOGY INC
  • EP3459215B1 patent drawingFigure 1
  • EP3459215B1 patent drawingFigure 2
  • EP3459215B1 patent drawingFigure 3

AI summary

Microsegmentation in a heterogeneous software-defined network can be performed by classifying endpoints associated with a first virtualized environment into respective endpoint groups based on respective attributes, and classifying endpoints associated with a second virtualized environment into respective security groups based on respective attributes. Each respective endpoint group can correspond to a respective security group having the same attribute. Each respective endpoint group and corresponding security group can be associated with a respective policy model defining rules for processing associated traffic. Each of the respective security groups can be used to generate a respective network attribute endpoint group, which can include the network addresses of those endpoints in the respective security group. Each respective network attribute endpoint group can inherit the policy model of the respective endpoint group corresponding to the respective security group. Traffic between the endpoints can then be processed based on the various classifications and associated rules.