Multi-Cloud Policy Enforcement via Dynamic Flow-Based Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multi-cloud environments face scalability and uniformity limitations due to disparate policy models and configuration restrictions across cloud providers, leading to restricted policy enforcement and security vulnerabilities, especially when integrating public clouds like AWS and Azure.
Innovation Solution
The approach involves policy splitting and distribution across nodes in the multi-cloud environment, allowing for on-demand policy enforcement based on packet information and dynamic deployment of policies, bypassing cloud-native construct limitations, using multi-site controllers and cloud controllers to manage and implement consistent policies across multiple cloud and network environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud providers use large and complex datacenters with numerous switches and routers to handle high network demands, then network capacity and service capability are improved, but device complexity and policy enforcement difficulty increase
Solution Approach 1:
The patent introduces a controller as an intermediary component that centralizes policy management and flow-based enforcement. The controller receives flow information from network devices, determines appropriate policies, and distributes them for enforcement, thereby simplifying the complex network architecture while maintaining high productivity
Solution Approach 2:
The patent replaces traditional mechanical/rigid policy enforcement mechanisms with flow-based dynamic policy enforcement. Instead of static configuration on numerous network devices, the system uses a centralized controller that dynamically determines and distributes policies based on real-time flow information, reducing device complexity
2Reliability
If public clouds apply coarse policy rules to handle container operations, then resource overload is avoided, but security and traffic segmentation capabilities are limited
Solution Approach 1:
The patent changes the granularity parameter of policy rules from coarse to fine by implementing flow-based policy enforcement. The controller analyzes individual flow characteristics and applies specific policies to each flow, enabling fine-grained security and traffic segmentation without causing resource overload through dynamic policy distribution
Solution Approach 2:
The patent introduces dynamic policy enforcement where policies are determined and distributed based on real-time flow information. The controller dynamically adjusts policy application based on current network conditions and flow characteristics, allowing fine-grained security control while maintaining resource stability through on-demand policy deployment
3Reliability
If cloud providers enforce numerous security policies in high-scale environments, then security capability is improved, but scalability and uniformity across multi-cloud environments deteriorate
Solution Approach 1:
The patent creates a universal policy enforcement mechanism that can operate across multiple cloud environments. The controller implements a standardized flow-based policy framework that works consistently across different cloud providers, enabling uniform security enforcement while maintaining scalability through centralized policy management
Solution Approach 2:
The patent segments policy enforcement into two independent components: a centralized controller that handles policy determination and distribution, and network devices that handle local policy execution. This segmentation allows the system to scale across multi-cloud environments while maintaining uniform security capabilities through centralized control
4Reliability
If AWS applies 300 policy rules per VM NIC, then security coverage is improved, but policy granularity and flexibility are restricted
Solution Approach 1:
The patent changes the policy enforcement parameter from static rule-based to dynamic flow-based. Instead of being constrained by the 300-rule limit on VM NICs, the system uses a centralized controller that can determine and enforce policies based on flow characteristics, providing unlimited policy granularity and flexibility while maintaining comprehensive security coverage
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Systems, methods, and computer-readable media for policy splitting in multi-cloud fabrics. In some examples, a method can include discovering a path from a first endpoint in a first cloud to a second endpoint in a second cloud; determining runtime policy table capacities associated with nodes in the path; determining policy distribution and enforcement for traffic from the first endpoint to the second endpoint based on the runtime policy table capacities; based on the policy distribution and enforcement, installing a set of policies for traffic from the first endpoint to the second endpoint across a set of nodes in the path; and applying the set of policies to traffic from the first endpoint in the first cloud to the second endpoint in the second cloud.