Overlay Identity Policy Distribution Using Packet Header Indices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Maintaining identity mappings and policies for users across multiple sites in overlay networks, such as SD-WANs, is challenging due to scalability issues, leading to high latency and cost in storing vast amounts of data locally at each network element.

Innovation Solution

A network controller maintains identity mappings and policies, distributing identity indices to network elements, which encapsulate user identity indices in packet headers for cross-site traffic, allowing retrieval from the controller for informed policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If identity mappings and policies are stored locally at each network element, then policy enforcement accuracy is improved, but storage cost and latency worsen

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoidstorage cost
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the identity mapping data by distributing different identity mappings to different network elements based on their local site information. Each network element stores only the identity mappings relevant to its site, rather than maintaining complete global identity mapping tables. This segmentation reduces storage requirements while ensuring accurate policy enforcement for local traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of spatial distribution across multiple sites. Instead of a centralized storage model or complete local replication, identity mappings are distributed across the network topology dimension, with each network element maintaining mappings appropriate to its specific site. This dimensional approach optimizes both storage efficiency and policy enforcement accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If complete identity mappings are stored locally at each network element, then policy enforcement speed is improved, but hardware cost worsens

Engineering Contradiction:
Improvepolicy enforcement speedVSAvoidhardware cost
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the identity mapping storage requirement across the network, so that not every network element needs to store complete identity mapping tables. Each element stores only the subset of mappings needed for its local site, reducing hardware storage requirements while maintaining fast local policy enforcement capability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If identity-based policies are enforced at each network element, then security reliability is improved, but device complexity worsens

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security enforcement function by enabling each network element to independently enforce identity-based policies for local traffic using its stored identity mappings. This distributed enforcement approach maintains high security reliability while avoiding the complexity of centralized control for every policy decision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each network element is equipped with the necessary identity mappings and policy information to autonomously perform security enforcement for local traffic. This self-service capability eliminates the need for complex real-time communication with centralized controllers, reducing device complexity while maintaining security reliability.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If all identity mappings are distributed to all network elements, then policy enforcement accuracy is improved, but data transmission overhead worsens

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoiddata transmission overhead
Core Design Contradiction:
Measurement precisionVSLoss of substance

Solution Approach 1:

The patent segments the identity mapping distribution by sending only the relevant mappings to each network element based on its site. This selective distribution approach maintains policy enforcement accuracy for local traffic while minimizing data transmission overhead by avoiding redundant distribution of unnecessary identity mappings.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12580791B2Scalable distribution of identity information in overlay networks with identity-based policies
Publication Date: 2026.03.17 PALO ALTO NETWORKS INC
  • US12580791B2 patent drawing
  • US12580791B2 patent drawing
  • US12580791B2 patent drawing

AI summary

A network controller in an overlay network maintains collective sets of identity-based policies and identity mappings for onboarded users of the network for informed distribution to network elements across the network. As new users are onboarded, the controller identifies a site of the network at which the user was onboarded and determines identity mappings of the user and applicable policies for distribution to a network element at the identified site. The controller assigns index values to each identity and communicates the indices to network elements with the corresponding identity mappings and policies. The network elements encapsulate cross-site traffic with the index values corresponding to senders so recipient network elements can obtain the index value from encapsulation header formats, query the controller for the corresponding identity mappings, and apply policies to the traffic that are determined to be pertinent based on the sender's identity mappings obtained from the controller.