Overlay Network Policy Builder for Secure Gateway Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication protocols face challenges in securing modern distributed networking environments due to the dual use of IP addresses for host identity and location, leading to vulnerabilities like man-in-the-middle attacks and difficulties in deploying overlay networks.

Innovation Solution

Classify entities and network traffic based on characteristics to generate policies for overlay networks, deploy these policies through gateways, and update them based on network traffic, enabling secure access and communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IP addresses are used for both host identity and location, then network communication can be simplified, but security vulnerabilities such as man-in-the-middle attacks, denial of service attacks, and replay attacks increase

Engineering Contradiction:
Improvenetwork communication simplicityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent separates the identity function from the location function by introducing overlay network identifiers (such as MAC addresses or other unique identifiers) distinct from IP addresses. Entities in the overlay network are identified by these separate identifiers while routing through IP addresses, thereby eliminating the security vulnerabilities associated with IP address spoofing and man-in-the-middle attacks while maintaining communication simplicity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If overlay networks are deployed to enhance security and control, then network visibility and policy management improve, but deployment complexity and configuration challenges increase

Engineering Contradiction:
Improvenetwork security and controlVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces gateway computers as intermediary devices that automatically discover overlay network entities and establish connections. These gateways act as mediators between the underlay network and overlay network, automatically handling the complex configuration and policy management tasks. Entities in the underlay network can join the overlay network through these gateways without manual intervention, significantly reducing deployment complexity while maintaining security and control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network policies are manually configured for overlay networks, then security control is precise, but configuration time and operational overhead increase

Engineering Contradiction:
Improvesecurity control precisionVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service configuration where gateway computers automatically discover overlay network entities, determine appropriate policies, and establish connections without manual administrator intervention. The system autonomously manages policy generation and enforcement based on entity characteristics and network traffic patterns, eliminating the time-consuming manual configuration process while maintaining precise security control through automated policy determination.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If entities in overlay networks use ephemeral or non-unique network addresses, then mobility and adaptability improve, but host identity determination becomes unreliable

Engineering Contradiction:
Improvehost mobilityVSAvoidhost identity determination
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent separates identity identification from network address assignment by using overlay network identifiers (such as MAC addresses or unique entity identifiers) that remain stable even when IP addresses change. This allows entities to move freely across the network with ephemeral IP addresses while maintaining reliable identity determination through their persistent overlay identifiers, resolving the contradiction between mobility and identity reliability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12634232B2Policy builder for overlay networks
Publication Date: 2026.05.19 TYCO FIRE & SECURITY GMBH
  • US12634232B2 patent drawing
  • US12634232B2 patent drawing
  • US12634232B2 patent drawing

AI summary

Embodiments are directed to managing communication over a network. Entities may be determined based on network traffic in an underlay network and classified based on characteristics of the entities, portions of the network traffic in the underlay network, or the like. Policies for an overlay network may be generated based on the classified entities or the portions of the network traffic. Policies may be deployed to gateways that may be associated with the entities such that the gateways facilitate access to the overlay network based on the policies. In response to determining other entities in the underlay network based on other network traffic in the overlay network and the network traffic in the underlay network, the one or more policies may be updated based on the other network traffic in the overlay network, the network traffic in the underlay network, or the one or more other entities.