Network Midpoint Device Segmentation Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional segmentation policies that rely exclusively on host endpoints for enforcement may be insufficient due to inadequate or absent enforcement mechanisms, leading to performance issues and resource constraints, which can compromise network security and efficiency.
Innovation Solution
A system and method that configure a network midpoint device to enforce segmentation policies by generating and applying ingress and egress rules on the device, allowing or blocking communications between workloads based on management instructions, thereby bypassing potential enforcement limitations at host endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If segmentation policy enforcement is performed exclusively at host endpoints, then the segmentation policy can be applied to control communications, but the enforcement mechanism becomes insufficient when host endpoints have inadequate or absent enforcement capabilities, and performance issues arise due to resource constraints
Solution Approach 1:
The patent introduces network midpoint devices as intermediary enforcement points between host endpoints and the network. These midpoint devices receive segmentation policy instructions and enforce them by configuring ingress and egress rules on the midpoint devices themselves, rather than relying solely on the host endpoints. This intermediary approach ensures consistent policy enforcement even when host endpoints have limited enforcement capabilities.
Solution Approach 2:
The patent shifts the enforcement dimension from the host endpoint layer to the network infrastructure layer (midpoint devices). By moving enforcement to network midpoint devices, the system adds a new dimension to policy enforcement that operates independently of host endpoint capabilities, thereby improving both reliability and adaptability across heterogeneous networks.
2Reliability
If segmentation policy enforcement is performed exclusively at host endpoints, then the policy can be enforced on individual hosts, but performance issues occur due to resource constraints on host endpoints and other network constraints
Solution Approach 1:
Network midpoint devices serve as intermediaries that offload enforcement operations from host endpoints. The midpoint devices configure ingress rules to permit or block incoming traffic and egress rules to control outgoing traffic, thereby enforcing segmentation policies at the network infrastructure level rather than consuming host endpoint resources.
Solution Approach 2:
The patent extracts the enforcement function from the host endpoint layer and places it at the network midpoint device layer. This extraction removes the performance burden from resource-constrained host endpoints while maintaining effective policy enforcement through the network infrastructure's greater computational capacity.
Data Source
AI summary
An enforcement module operating on a server or on a network midpoint device obtains a management instruction controlling communications of a target workload. The enforcement module configures a firewall of a network midpoint device upstream from the target workload to enforce the management instruction. The configuration mechanism may be dependent on the particular capabilities and characteristics of the network midpoint device.


