Overlay Network Policy Builder for Secure Gateway Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication protocols face challenges in securing modern distributed networking environments due to the dual use of IP addresses for host identity and location, leading to vulnerabilities like man-in-the-middle attacks and difficulties in deploying overlay networks.
Innovation Solution
Classify entities and network traffic based on characteristics to generate policies for overlay networks, deploy these policies through gateways, and update them based on network traffic, enabling secure access and communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IP addresses are used for both host identity and location, then network communication can be simplified, but security vulnerabilities such as man-in-the-middle attacks, denial of service attacks, and replay attacks increase
Solution Approach 1:
The patent separates the identity function from the location function by introducing overlay network identifiers (such as MAC addresses or other unique identifiers) distinct from IP addresses. Entities in the overlay network are identified by these separate identifiers while routing through IP addresses, thereby eliminating the security vulnerabilities associated with IP address spoofing and man-in-the-middle attacks while maintaining communication simplicity.
2Reliability
If overlay networks are deployed to enhance security and control, then network visibility and policy management improve, but deployment complexity and configuration challenges increase
Solution Approach 1:
The patent introduces gateway computers as intermediary devices that automatically discover overlay network entities and establish connections. These gateways act as mediators between the underlay network and overlay network, automatically handling the complex configuration and policy management tasks. Entities in the underlay network can join the overlay network through these gateways without manual intervention, significantly reducing deployment complexity while maintaining security and control.
3Reliability
If network policies are manually configured for overlay networks, then security control is precise, but configuration time and operational overhead increase
Solution Approach 1:
The patent implements self-service configuration where gateway computers automatically discover overlay network entities, determine appropriate policies, and establish connections without manual administrator intervention. The system autonomously manages policy generation and enforcement based on entity characteristics and network traffic patterns, eliminating the time-consuming manual configuration process while maintaining precise security control through automated policy determination.
4Adaptability or versatility
If entities in overlay networks use ephemeral or non-unique network addresses, then mobility and adaptability improve, but host identity determination becomes unreliable
Solution Approach 1:
The patent separates identity identification from network address assignment by using overlay network identifiers (such as MAC addresses or unique entity identifiers) that remain stable even when IP addresses change. This allows entities to move freely across the network with ephemeral IP addresses while maintaining reliable identity determination through their persistent overlay identifiers, resolving the contradiction between mobility and identity reliability.
Data Source
AI summary
Embodiments are directed to managing communication over a network. Entities may be determined based on network traffic in an underlay network and classified based on characteristics of the entities, portions of the network traffic in the underlay network, or the like. Policies for an overlay network may be generated based on the classified entities or the portions of the network traffic. Policies may be deployed to gateways that may be associated with the entities such that the gateways facilitate access to the overlay network based on the policies. In response to determining other entities in the underlay network based on other network traffic in the overlay network and the network traffic in the underlay network, the one or more policies may be updated based on the other network traffic in the overlay network, the network traffic in the underlay network, or the one or more other entities.


