Automated Network Security Policy Rendering and Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manually creating or updating network security policies in cloud computing systems is time-consuming, prone to errors, and can lead to data breaches and network outages, especially in multi-substrate cloud environments where changes across different hosting environments are not adequately accounted for.

Innovation Solution

Implementing a zero-touch automation (ZeTA) policy-as-a-service functionality that uses a declarative user interface to create or update network security policies, which are then automatically rendered into access control lists (ACLs) and deployed across diverse substrates through a rendering and deployment sub-system, decoupling services from the underlying policy implementation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual creation or updating of network security policies is performed, then policy customization and control are improved, but time consumption and error rates increase significantly

Engineering Contradiction:
Improvepolicy customization controlVSAvoidtime consumption
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables self-service automation where the network security policy management system automatically retrieves service instance information, generates ACLs, and deploys policies without requiring manual human intervention. The system serves itself by automatically updating policies when service instances change, eliminating the time-consuming manual processes while maintaining policy control through automated service discovery and ACL generation.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If manual creation or updating of network security policies is performed, then policy customization and control are improved, but error rates and security risks increase

Engineering Contradiction:
Improvepolicy customization controlVSAvoiderror rate
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces manual mechanical processes with automated computational systems. The system automatically discovers service instances, retrieves their network security settings, generates corresponding ACLs, and deploys policies through API calls. This substitution of manual operations with automated system processes eliminates human errors while maintaining precise policy control through programmatic service instance management and ACL generation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If automated policy rendering and deployment is implemented, then productivity and speed are improved, but system complexity increases

Engineering Contradiction:
Improvepolicy deployment speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The network security policy management system performs multiple functions through a single integrated automated platform: it discovers service instances, retrieves network security settings, generates ACLs, and deploys policies across multiple substrates. This multi-functional approach consolidates what would otherwise require separate manual processes into one unified system, managing complexity through integration while achieving high productivity through automation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If automated policy rendering and deployment is implemented, then policy consistency across multi-substrate environments is improved, but implementation complexity increases

Engineering Contradiction:
Improvepolicy consistencyVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the policy deployment process into distinct automated stages: service instance discovery, network security settings retrieval, ACL generation, and policy deployment to multiple substrates. Each segment handles a specific aspect of policy management, allowing the system to maintain consistency across diverse hosting environments by processing each substrate through the same standardized automated workflow, thereby managing implementation complexity through structured segmentation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250211622A1Systems and methods for automatically rendering and deploying network security policies
Publication Date: 2025.06.26 SALESFORCE INC
  • US20250211622A1 patent drawing
  • US20250211622A1 patent drawing
  • US20250211622A1 patent drawing

AI summary

Methods, systems, and devices for data processing in a computing system are described. The computing system may receive a notification of an update to network security objects hosted in diverse substrates within the computing system. The computing system may retrieve a network security policy for a service instance impacted by the update. The computing system may update the network security policy for the service instance according to a network security configuration of the hosting substrate. The computing system may translate the updated network security policy into access control lists (ACLs) for network entities managing communications between service instances within the computing system. The computing system may store the ACLs in respective data repositories that are accessible to the network entities. The computing system may transmit a notification that the ACLs are available for deployment, thereby causing the network entities to retrieve the ACLs from the respective data repositories.