Multi-Cloud Policy Enforcement via Dynamic Flow-Based Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-cloud environments face scalability and uniformity limitations due to disparate policy models and configuration restrictions across cloud providers, leading to restricted policy enforcement and security vulnerabilities, especially when integrating public clouds like AWS and Azure.

Innovation Solution

The approach involves policy splitting and distribution across nodes in the multi-cloud environment, allowing for on-demand policy enforcement based on packet information and dynamic deployment of policies, bypassing cloud-native construct limitations, using multi-site controllers and cloud controllers to manage and implement consistent policies across multiple cloud and network environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud providers use large and complex datacenters with numerous switches and routers to handle high network demands, then network capacity and service capability are improved, but device complexity and policy enforcement difficulty increase

Engineering Contradiction:
Improvenetwork capacityVSAvoiddatacenter complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a controller as an intermediary component that centralizes policy management and flow-based enforcement. The controller receives flow information from network devices, determines appropriate policies, and distributes them for enforcement, thereby simplifying the complex network architecture while maintaining high productivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/rigid policy enforcement mechanisms with flow-based dynamic policy enforcement. Instead of static configuration on numerous network devices, the system uses a centralized controller that dynamically determines and distributes policies based on real-time flow information, reducing device complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If public clouds apply coarse policy rules to handle container operations, then resource overload is avoided, but security and traffic segmentation capabilities are limited

Engineering Contradiction:
Improveresource stabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the granularity parameter of policy rules from coarse to fine by implementing flow-based policy enforcement. The controller analyzes individual flow characteristics and applies specific policies to each flow, enabling fine-grained security and traffic segmentation without causing resource overload through dynamic policy distribution

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic policy enforcement where policies are determined and distributed based on real-time flow information. The controller dynamically adjusts policy application based on current network conditions and flow characteristics, allowing fine-grained security control while maintaining resource stability through on-demand policy deployment

Inventive Principle:
Principle #15Dynamics

3Reliability

If cloud providers enforce numerous security policies in high-scale environments, then security capability is improved, but scalability and uniformity across multi-cloud environments deteriorate

Engineering Contradiction:
Improvesecurity capabilityVSAvoidmulti-cloud scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal policy enforcement mechanism that can operate across multiple cloud environments. The controller implements a standardized flow-based policy framework that works consistently across different cloud providers, enabling uniform security enforcement while maintaining scalability through centralized policy management

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments policy enforcement into two independent components: a centralized controller that handles policy determination and distribution, and network devices that handle local policy execution. This segmentation allows the system to scale across multi-cloud environments while maintaining uniform security capabilities through centralized control

Inventive Principle:
Principle #1Segmentation

4Reliability

If AWS applies 300 policy rules per VM NIC, then security coverage is improved, but policy granularity and flexibility are restricted

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the policy enforcement parameter from static rule-based to dynamic flow-based. Instead of being constrained by the 300-rule limit on VM NICs, the system uses a centralized controller that can determine and enforce policies based on flow characteristics, providing unlimited policy granularity and flexibility while maintaining comprehensive security coverage

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3932022B1Systems and methods for on-demand flow-based policy enforcement in multi-cloud environments
Publication Date: 2023.09.13 CISCO TECHNOLOGY INC
  • EP3932022B1 patent drawingFigure 1
  • EP3932022B1 patent drawingFigure 2
  • EP3932022B1 patent drawingFigure 3A

AI summary

Systems, methods, and computer-readable media for policy splitting in multi-cloud fabrics. In some examples, a method can include discovering a path from a first endpoint in a first cloud to a second endpoint in a second cloud; determining runtime policy table capacities associated with nodes in the path; determining policy distribution and enforcement for traffic from the first endpoint to the second endpoint based on the runtime policy table capacities; based on the policy distribution and enforcement, installing a set of policies for traffic from the first endpoint to the second endpoint across a set of nodes in the path; and applying the set of policies to traffic from the first endpoint in the first cloud to the second endpoint in the second cloud.