Overlay Fabric Tag Pointer for Multi-Group Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing application workloads in hybrid data centers are challenged by the complexity of managing multiple security group identities, as virtual machines can belong to multiple groups with different policies, requiring complex workarounds.

Innovation Solution

A method and system that derive multiple tags and apply policies using existing overlay technologies, encapsulating a tag pointer in the flow to carry multi-group identities across the fabric, enabling security, QoS, and service chaining with priority resolution, using a single tag pointer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a VM belongs to multiple security group identities with different policies, then security coverage is improved, but device complexity increases due to requiring extremely complex workarounds

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security group identification into multiple independent tags, where each tag represents a different security group identity. Instead of requiring a single complex identifier, the system divides the identification into multiple manageable tags that can be independently managed and applied to the same VM, thereby improving security coverage without increasing overall system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal tagging mechanism that allows a single VM to simultaneously belong to multiple security groups through multiple tags. This multi-functional approach enables the VM to inherit policies from different security groups without requiring separate workarounds for each group, thus improving security coverage while maintaining system simplicity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If existing solutions allow a VM to belong to only one identity group, then device complexity is reduced, but adaptability deteriorates as it requires extremely complex workarounds to support multi-group intent

Engineering Contradiction:
Improvesystem complexityVSAvoidmulti-group support
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a dynamic tagging system where the number of security group tags associated with a VM can flexibly change based on the VM's role and requirements. Unlike static single-group assignments, the system dynamically adds or removes tags as needed, enabling adaptable multi-group support while keeping the underlying mechanism simple through standardized tag management

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces tags as intermediary elements that mediate between VMs and security groups. These tags serve as a flexible layer that enables multi-group associations without directly complicating the VM-security group relationship, providing adaptability while maintaining system simplicity through the intermediary tagging mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12549604B2Multifaceted security group classification in overlay fabric
Publication Date: 2026.02.10 CISCO TECHNOLOGY INC
  • US12549604B2 patent drawing
  • US12549604B2 patent drawing
  • US12549604B2 patent drawing

AI summary

Techniques for using policies in an overlay communication network are disclosed. These techniques include deriving a plurality of source tags for a flow relating to an overlay communication network, the plurality of source tags relating to one or more policies for the flow. The techniques further include deriving a tag pointer for the flow, the tag pointer corresponding to all of the plurality of source tags, encapsulating the tag pointer in the flow, and transmitting the flow over the overlay communication network, wherein the tag pointer is configured to be used to identify a plurality of policies for the flow on egress from the overlay communication network.