Network Security Policy Enforcement via Centralized Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies, such as IPsec, face challenges in configuration complexity, scalability, and installation requirements, particularly in large networks, where manual configuration and knowledge of all protected subnets are necessary, and the process is time-consuming and prone to errors.

Innovation Solution

A three-layered approach separates network security functions into Management and Policy Server (MAP) for policy definition, Key Authority Point (KAP) for key generation and distribution, and Policy Enforcement Point (PEP) for enforcement, allowing for simplified policy management, key distribution, and secure enforcement across the network, independent of the underlying infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration and knowledge of all protected subnets are required, then security enforcement can be achieved, but configuration complexity and installation requirements increase significantly

Engineering Contradiction:
Improvesecurity enforcementVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Security Policy Server as an intermediary component that centrally manages security policies and distributes them to network devices. This mediator handles the complexity of policy configuration, authentication, and key management, allowing security enforcement without requiring manual configuration at each endpoint. The server acts as the authoritative source for security policies, automatically distributing them to relevant network devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables network devices to automatically receive and enforce security policies without manual intervention. Devices can self-configure by receiving policies from the Security Policy Server, and the system provides automated key distribution and policy updates. This self-service approach eliminates the need for administrators to manually configure each device while maintaining reliable security enforcement.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration of security policies is performed, then security can be enforced, but the process is time-consuming and productivity decreases

Engineering Contradiction:
Improvesecurity enforcementVSAvoidconfiguration speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The Security Policy Server performs preliminary actions by pre-defining and storing security policies centrally before they are needed for enforcement. Policies are prepared in advance, authenticated, and ready for rapid distribution to network devices. This preliminary configuration at the server side enables quick deployment and updates without time-consuming manual configuration at each device.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Network devices automatically receive and apply security policies from the server without waiting for manual configuration. The system provides self-service policy distribution, where devices can request and receive updated policies automatically, significantly increasing configuration speed and productivity while maintaining security enforcement.

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If security policies are centrally managed, then policy consistency is improved, but system complexity increases due to additional infrastructure requirements

Engineering Contradiction:
Improvepolicy consistencyVSAvoidinfrastructure complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The Security Policy Server serves as a centralized intermediary that maintains policy consistency across the network. All security policies are defined, authenticated, and distributed from this single authoritative source, ensuring that every device enforces the same policies. This centralization guarantees policy consistency without requiring complex distributed configuration management systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If existing IPsec technology is used, then security can be provided, but scalability is limited in large networks

Engineering Contradiction:
Improvesecurity provisionVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The Security Policy Server provides a universal platform that can serve multiple network devices and enforce multiple security policies simultaneously. The system is designed to scale by allowing the same server infrastructure to support growing numbers of devices and policies without requiring proportional increases in configuration complexity. The centralized architecture enables the system to adapt to large network environments while maintaining security provision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8082574B2Enforcing security groups in network of data processors
Publication Date: 2011.12.20 CERTES NETWORKS INC
  • US8082574B2 patent drawing
  • US8082574B2 patent drawing
  • US8082574B2 patent drawing

AI summary

A technique for securing message traffic in a data network using various methods for distributing security policies and keys, where policy definition is determined in a Management and Policy (MAP) functional layer that is responsible for policy distribution; a separate Key Authority Point (KAP) that is responsible for key generation, key distribution, and policy distribution; and a separate Policy Enforcement Point (PEP) which is responsible for enforcing the policies and applying the keys.