Network Security Policy Enforcement via Centralized Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies, such as IPsec, face challenges in configuration complexity, scalability, and installation requirements, particularly in large networks, where manual configuration and knowledge of all protected subnets are necessary, and the process is time-consuming and prone to errors.
Innovation Solution
A three-layered approach separates network security functions into Management and Policy Server (MAP) for policy definition, Key Authority Point (KAP) for key generation and distribution, and Policy Enforcement Point (PEP) for enforcement, allowing for simplified policy management, key distribution, and secure enforcement across the network, independent of the underlying infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual configuration and knowledge of all protected subnets are required, then security enforcement can be achieved, but configuration complexity and installation requirements increase significantly
Solution Approach 1:
The patent introduces a Security Policy Server as an intermediary component that centrally manages security policies and distributes them to network devices. This mediator handles the complexity of policy configuration, authentication, and key management, allowing security enforcement without requiring manual configuration at each endpoint. The server acts as the authoritative source for security policies, automatically distributing them to relevant network devices.
Solution Approach 2:
The system enables network devices to automatically receive and enforce security policies without manual intervention. Devices can self-configure by receiving policies from the Security Policy Server, and the system provides automated key distribution and policy updates. This self-service approach eliminates the need for administrators to manually configure each device while maintaining reliable security enforcement.
2Reliability
If manual configuration of security policies is performed, then security can be enforced, but the process is time-consuming and productivity decreases
Solution Approach 1:
The Security Policy Server performs preliminary actions by pre-defining and storing security policies centrally before they are needed for enforcement. Policies are prepared in advance, authenticated, and ready for rapid distribution to network devices. This preliminary configuration at the server side enables quick deployment and updates without time-consuming manual configuration at each device.
Solution Approach 2:
Network devices automatically receive and apply security policies from the server without waiting for manual configuration. The system provides self-service policy distribution, where devices can request and receive updated policies automatically, significantly increasing configuration speed and productivity while maintaining security enforcement.
3Stability of the object's composition
If security policies are centrally managed, then policy consistency is improved, but system complexity increases due to additional infrastructure requirements
Solution Approach 1:
The Security Policy Server serves as a centralized intermediary that maintains policy consistency across the network. All security policies are defined, authenticated, and distributed from this single authoritative source, ensuring that every device enforces the same policies. This centralization guarantees policy consistency without requiring complex distributed configuration management systems.
4Reliability
If existing IPsec technology is used, then security can be provided, but scalability is limited in large networks
Solution Approach 1:
The Security Policy Server provides a universal platform that can serve multiple network devices and enforce multiple security policies simultaneously. The system is designed to scale by allowing the same server infrastructure to support growing numbers of devices and policies without requiring proportional increases in configuration complexity. The centralized architecture enables the system to adapt to large network environments while maintaining security provision.
Data Source
AI summary
A technique for securing message traffic in a data network using various methods for distributing security policies and keys, where policy definition is determined in a Management and Policy (MAP) functional layer that is responsible for policy distribution; a separate Key Authority Point (KAP) that is responsible for key generation, key distribution, and policy distribution; and a separate Policy Enforcement Point (PEP) which is responsible for enforcing the policies and applying the keys.


