Overlay Identity Policy Distribution Using Packet Header Indices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Maintaining identity mappings and policies for users across multiple sites in overlay networks, such as SD-WANs, is challenging due to scalability issues, leading to high latency and cost in storing vast amounts of data locally at each network element.
Innovation Solution
A network controller maintains identity mappings and policies, distributing identity indices to network elements, which encapsulate user identity indices in packet headers for cross-site traffic, allowing retrieval from the controller for informed policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If identity mappings and policies are stored locally at each network element, then policy enforcement accuracy is improved, but storage cost and latency worsen
Solution Approach 1:
The patent segments the identity mapping data by distributing different identity mappings to different network elements based on their local site information. Each network element stores only the identity mappings relevant to its site, rather than maintaining complete global identity mapping tables. This segmentation reduces storage requirements while ensuring accurate policy enforcement for local traffic.
Solution Approach 2:
The patent introduces a new dimension of spatial distribution across multiple sites. Instead of a centralized storage model or complete local replication, identity mappings are distributed across the network topology dimension, with each network element maintaining mappings appropriate to its specific site. This dimensional approach optimizes both storage efficiency and policy enforcement accuracy.
2Productivity
If complete identity mappings are stored locally at each network element, then policy enforcement speed is improved, but hardware cost worsens
Solution Approach 1:
The patent segments the identity mapping storage requirement across the network, so that not every network element needs to store complete identity mapping tables. Each element stores only the subset of mappings needed for its local site, reducing hardware storage requirements while maintaining fast local policy enforcement capability.
3Reliability
If identity-based policies are enforced at each network element, then security reliability is improved, but device complexity worsens
Solution Approach 1:
The patent segments the security enforcement function by enabling each network element to independently enforce identity-based policies for local traffic using its stored identity mappings. This distributed enforcement approach maintains high security reliability while avoiding the complexity of centralized control for every policy decision.
Solution Approach 2:
Each network element is equipped with the necessary identity mappings and policy information to autonomously perform security enforcement for local traffic. This self-service capability eliminates the need for complex real-time communication with centralized controllers, reducing device complexity while maintaining security reliability.
4Measurement precision
If all identity mappings are distributed to all network elements, then policy enforcement accuracy is improved, but data transmission overhead worsens
Solution Approach 1:
The patent segments the identity mapping distribution by sending only the relevant mappings to each network element based on its site. This selective distribution approach maintains policy enforcement accuracy for local traffic while minimizing data transmission overhead by avoiding redundant distribution of unnecessary identity mappings.
Data Source
AI summary
A network controller in an overlay network maintains collective sets of identity-based policies and identity mappings for onboarded users of the network for informed distribution to network elements across the network. As new users are onboarded, the controller identifies a site of the network at which the user was onboarded and determines identity mappings of the user and applicable policies for distribution to a network element at the identified site. The controller assigns index values to each identity and communicates the indices to network elements with the corresponding identity mappings and policies. The network elements encapsulate cross-site traffic with the index values corresponding to senders so recipient network elements can obtain the index value from encapsulation header formats, query the controller for the corresponding identity mappings, and apply policies to the traffic that are determined to be pertinent based on the sender's identity mappings obtained from the controller.


