Microsegmentation in Heterogeneous Software Defined Networking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Microsegmentation in heterogeneous data centers is limited due to the lack of interoperability among different software-defined network (SDN) solutions and hosts, which hinders effective traffic classification and policy enforcement across various virtualized environments.
Innovation Solution
The method involves classifying endpoints into endpoint groups based on attributes and creating corresponding security groups across different SDN solutions, with network address endpoint groups being generated to enforce policies consistently across diverse virtualized environments, enabling microsegmentation across different types of SDNs, hosts, and virtual switching elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If different SDN solutions and hosts are deployed in a data center, then the data center can support diverse virtualized environments and applications, but microsegmentation is limited due to lack of interoperability among these different platforms
Solution Approach 1:
The patent implements a universal microsegmentation framework that works across multiple SDN platforms (Cisco ACI, VMware NSX, Open vSwitch) and host types (KVM, Hyper-V, Xen, bare metal). The system uses a common policy model and attribute-based endpoint grouping that translates to platform-specific implementations, enabling consistent microsegmentation functionality across heterogeneous environments without requiring platform-specific configurations
Solution Approach 2:
The patent introduces an intermediary layer that sits between the diverse SDN platforms and the microsegmentation policy enforcement mechanism. This intermediary standardizes endpoint attributes, groups endpoints by shared characteristics regardless of underlying platform, and enforces policies uniformly across all platforms, effectively mediating between incompatible systems to achieve coherent microsegmentation
2Reliability
If microsegmentation is implemented with fine granularity control, then security services can be provisioned between application tiers and devices within tiers, but the complexity of managing policies across heterogeneous platforms increases
Solution Approach 1:
The patent changes the parameter space for policy management from platform-specific configurations to a unified attribute-based model. Instead of managing complex platform-specific policies, administrators define policies based on endpoint attributes (application tier, function, security requirements), and the system automatically translates these high-level parameters into platform-specific enforcement rules, dramatically simplifying policy management while maintaining fine-grained security control
3Reliability
If endpoints are classified into groups based on attributes across different virtualized environments, then consistent policy enforcement can be achieved, but the difficulty of detecting and measuring endpoint attributes increases
Solution Approach 1:
The patent implements self-service mechanisms where endpoints automatically advertise their attributes (application tier, function, security requirements) to the microsegmentation system. Hypervisors and SDN agents on each platform automatically collect endpoint information and populate the attribute database without requiring manual configuration or complex detection mechanisms, making the system scalable across heterogeneous platforms
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Microsegmentation in a heterogeneous software-defined network can be performed by classifying endpoints associated with a first virtualized environment into respective endpoint groups based on respective attributes, and classifying endpoints associated with a second virtualized environment into respective security groups based on respective attributes. Each respective endpoint group can correspond to a respective security group having the same attribute. Each respective endpoint group and corresponding security group can be associated with a respective policy model defining rules for processing associated traffic. Each of the respective security groups can be used to generate a respective network attribute endpoint group, which can include the network addresses of those endpoints in the respective security group. Each respective network attribute endpoint group can inherit the policy model of the respective endpoint group corresponding to the respective security group. Traffic between the endpoints can then be processed based on the various classifications and associated rules.