Object-Oriented Policy Configuration for Undefined Network Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As network devices provide increasingly complex functions, configuring and managing their policies becomes complex, leading to performance issues, network errors, and security vulnerabilities due to improper configuration, with a need for structured policy expressions and efficient processing of policies, especially in handling undefined policy scenarios.

Innovation Solution

The implementation of object-oriented policies that allow users to specify structured expressions for network traffic, enabling efficient processing of complex data streams and handling undefined policy elements through a configuration interface that controls policy execution order and specifies actions for undefined conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network devices provide increasingly complex functions, then device capability and functionality are improved, but configuration complexity and administrative overhead increase

Engineering Contradiction:
Improvedevice capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms complex policy configurations into simplified parameter-based expressions. By allowing users to define policies using structured expressions with parameters (such as match conditions, actions, and priorities) rather than complex rule sets, the system maintains high device capability while reducing configuration complexity. The expression-based policy framework enables administrators to configure complex network behaviors through simpler, more intuitive parameter specifications.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the number of policies increases to handle complex functions, then device functionality is improved, but processing overhead and performance decrease

Engineering Contradiction:
Improvepolicy coverageVSAvoidprocessing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments policies into hierarchical groups with defined processing orders. By organizing policies into groups and specifying execution sequences, the system can efficiently process traffic by evaluating groups in order rather than evaluating all individual policies independently. This segmentation reduces processing overhead while maintaining comprehensive policy coverage, as the system can stop processing once a matching policy is found within a group.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by establishing policy group processing orders and evaluation sequences before traffic processing begins. The system pre-configures which groups are evaluated first and which policies within groups take precedence, allowing for efficient runtime processing without requiring complex real-time decision logic. This preliminary structuring enables faster policy evaluation while handling diverse traffic scenarios.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If policies are made more specific to handle undefined scenarios, then policy precision is improved, but configuration complexity increases

Engineering Contradiction:
Improvepolicy precisionVSAvoidpolicy complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a default action mechanism that applies to all undefined policy scenarios. Instead of requiring separate specific policies for each undefined case, a single default action configuration handles multiple undefined scenarios universally. This maintains policy precision by providing defined behavior for edge cases while avoiding the configuration complexity of creating numerous specific policies for every possible undefined scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7853679B2Systems and methods for configuring handling of undefined policy events
Publication Date: 2010.12.14 CITRIX SYSTEMS INC
  • US7853679B2 patent drawing
  • US7853679B2 patent drawing
  • US7853679B2 patent drawing

AI summary

Systems and methods for configuring and evaluating policies that direct processing of one or more data streams are described. A configuration interface is described for allowing users to specify object oriented policies. These object oriented policies may allow any data structures to be applied with respect to a payload of a received packet stream, including any portions of HTTP traffic. A configuration interface may also allow the user to control the order in which policies and policy groups are executed, in addition to specifying actions to be taken if one or more policies are undefined. Systems and methods for processing the policies may allow efficient processing of object-oriented policies by applying potentially complex data structures to unstructured data streams. A device may also interpret and process a number of flow control commands and policy group invocation statements to determine an order of execution among a number of policies and policy groups. These policy configurations and processing may allow configuration and processing of complex network behaviors relating to load balancing, VPNs, SSL offloading, content switching, application security, acceleration, and caching.