Network Security Policy Control Plane for Cloud Policy Reconciliation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge of reconciling a large number of diverse and changing security policies defined by developers for applications on a cloud computing server system, while ensuring compliance with a unified security posture and preventing conflicts or breaches.

Innovation Solution

Utilizing a Domain Specific Language (DSL) for intent-based network security policy definition, combined with a configuration realization control plane that generates cloud-native enforcement artifacts, ensures compliance with baseline policies, and implements a hierarchical model with guardrails to manage policy integration and distribution across cloud components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple developers define security policies using DSL for their applications, then application-specific security requirements are met, but policy complexity and conflict risk increase

Engineering Contradiction:
Improveapplication-specific security policy customizationVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a control plane as an intermediary between developers and the cloud infrastructure. This control plane receives DSL policies from multiple developers, reconciles them against guardrail policies, and generates unified cloud-native enforcement artifacts. The intermediary absorbs the complexity of policy reconciliation, allowing developers to focus on application-specific requirements without managing policy conflicts directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security policies into two distinct layers: guardrail policies (system-level constraints) and DSL policies (application-specific requirements). This segmentation allows independent management of each policy type, with guardrail policies providing a stable foundation and DSL policies enabling flexible application-level customization without direct interference between them.

Inventive Principle:
Principle #1Segmentation

2Productivity

If security policies are continuously updated to reflect changing application requirements, then policy relevance and effectiveness improve, but reconciliation overhead and processing time increase

Engineering Contradiction:
Improvepolicy update responsivenessVSAvoidpolicy reconciliation time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent establishes guardrail policies in advance as pre-defined system-level constraints. These preliminary policies are configured once and serve as a stable foundation, eliminating the need to re-evaluate them during every policy update. When DSL policies change, the system only needs to reconcile against the pre-established guardrails, significantly reducing reconciliation time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The control plane implements continuous monitoring and automatic reconciliation of DSL policies against guardrail policies. This continuous action ensures that policy updates are processed immediately without manual intervention, maintaining policy relevance while automating the reconciliation process to minimize time loss.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If a unified security posture is enforced across all applications, then system-wide security compliance improves, but flexibility for application-specific security needs decreases

Engineering Contradiction:
Improvesystem-wide security complianceVSAvoidapplication-specific security flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adds a hierarchical dimension to security policy enforcement, operating at two levels: system-wide guardrail policies and application-specific DSL policies. This dimensional approach allows simultaneous enforcement of unified security postures at the guardrail level while permitting application-specific flexibility at the DSL level, resolving the contradiction between compliance and adaptability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If comprehensive policy validation and conflict detection are implemented, then security policy reliability improves, but processing overhead and system complexity increase

Engineering Contradiction:
Improvepolicy conflict detection accuracyVSAvoidpolicy processing system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary validation of DSL policies against guardrail policies during the policy creation and update process. This early detection mechanism identifies conflicts before they propagate through the system, ensuring reliability while containing validation overhead to specific policy changes rather than requiring comprehensive system-wide analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250247434A1Network security policy generation and distribution
Publication Date: 2025.07.31 SALESFORCE INC
  • US20250247434A1 patent drawing
  • US20250247434A1 patent drawing
  • US20250247434A1 patent drawing

AI summary

Systems, devices, and techniques are disclosed for network security policy generation and distribution. A security policy written using a Domain Specific Language (DSL) for network security may be received. The security policy may be associated with a service owner and a control plane. A representation of the security policy may be generated from the security policy. A configuration bundle of the service owner may be updated with the representation of the security policy. The security policy may be determined to be approved. A rule set may be generated from the representation of the security policy. A differential between the rule set and a current rule set may be determined. A security component associated with the control plane based on the differential may be configured.