Network Policy Group Optimization via Graph Theory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of network policies due to organizational structure, regulatory requirements, and security threats leads to a significant increase in the number of rules, overwhelming computational and memory resources, causing bottlenecks and degrading network performance.

Innovation Solution

The use of graph theory to model and optimize communications between objects, grouping them into source and destination groups to reduce the number of rules through a generalized group optimization algorithm (G2OA), which translates policies into a simplified tensor and list of 3D vectors, minimizing the storage and processing requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network policies are expanded to cover increasing organizational complexity, regulatory requirements, and security threats, then network security and compliance are improved, but computational and memory resources are overwhelmed causing bottlenecks and degraded network performance

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the large network policy into multiple smaller policy sets, each enforced by different network elements. This division reduces the computational and memory burden on individual network elements while maintaining comprehensive security coverage across the entire network through coordinated enforcement of segmented policies.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the number of network policy rules is increased to address organizational complexity and security threats, then network security coverage is improved, but the size of policies and memory requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy size
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent divides the comprehensive network policy into multiple smaller policy sets that can be distributed across different network elements. This segmentation reduces the policy size stored at each individual element while collectively providing complete security coverage through the coordinated enforcement of all policy sets.

Inventive Principle:
Principle #1Segmentation

3Reliability

If network policies are expanded with more rules, then security compliance is improved, but computational resources needed to process policies increase

Engineering Contradiction:
ImprovecomplianceVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the computationally intensive policy processing task across multiple network elements, with each element enforcing a specific policy set. This distribution reduces the computational resource consumption at each individual element while collectively achieving complete compliance enforcement through coordinated policy execution.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11245729B2Group optimization for network communications
Publication Date: 2022.02.08 SALESFORCE INC
  • US11245729B2 patent drawing
  • US11245729B2 patent drawing
  • US11245729B2 patent drawing

AI summary

Disclosed embodiments are related to grouping sets of intercommunicating objects to minimize the number of rules/policies needed to be stored to enforce those rules/policies. Given a set of objects communicating with each other using different services, embodiments group these objects to minimize the total number of final rules that are implemented. This allows an original set of policies to be reduced into a smaller set of policies, which conserves computational resources. Other embodiments may be described and/or claimed.