Inheritance-Based Network Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network management solutions lack effective mechanisms for implementing network-wide policy configurations across groups of devices, requiring manual configuration on each device and leading to inefficiencies and potential errors due to overlapping policies.

Innovation Solution

The methodology involves creating groups of network devices with inherited group policy configurations, allowing for the virtualization of physical attributes, conflict resolution, and version control through redo and undo features, enabling efficient management of large networks by applying policies to groups rather than individual devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If policy configuration is applied to each device individually, then each device can have specific policies, but management effort and time increase substantially

Engineering Contradiction:
Improvedevice-specific policy configurationVSAvoidmanagement time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments the network device population into hierarchical groups (organizational units, device groups, and individual devices). Policy configurations are applied at the group level and automatically inherited by member devices, eliminating the need to configure each device individually while maintaining device-specific policies through group membership segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple devices into single group entities where common policies are defined once at the group level. By combining devices with similar policy requirements into organizational units and device groups, the system reduces redundant configuration efforts while preserving individual device policies through the inheritance mechanism.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If manual policy configuration is performed on each device, then policy coverage can be complete, but errors and inconsistencies increase

Engineering Contradiction:
Improvepolicy configuration accuracyVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-defining policy configurations at the group level before deployment to individual devices. The system prepares and validates policies within the hierarchical group structure, ensuring consistency and accuracy before automatic inheritance by member devices, thereby reducing configuration errors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms that monitor policy inheritance and configuration status across the hierarchical group structure. The system provides feedback on policy application status, enabling detection and correction of inconsistencies, thereby improving configuration accuracy while maintaining ease of operation.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If different physical interfaces are used for identical functions, then device compatibility increases, but policy application complexity increases

Engineering Contradiction:
Improvedevice compatibilityVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified hierarchical group structure that can accommodate devices with different physical interfaces but identical functions. The organizational unit and device group levels provide universal policy containers that work across diverse device types, while the inheritance mechanism handles interface-specific variations automatically.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9137251B2Inheritance based network management
Publication Date: 2015.09.15 FORTINET INC
  • US9137251B2 patent drawing
  • US9137251B2 patent drawing
  • US9137251B2 patent drawing

AI summary

The present invention teaches a methodology for provisioning and managing a network having many network devices. In certain embodiments, groups of member devices are created each having a group policy configuration inherited by member devices. A variety of rules regarding prioritization, versioning, system snapshot, redo and undo are also taught. This embodiment is useful when the network devices can be partitioned into groups of similar type devices for similar applications. Similar physical attributes can also be mapped into identical virtual attributes, enabling policy configurations to be applied to varying devices and physical attribute configurations can be resolved upon device installation.