Overlay Fabric Tag Pointer for Multi-Group Security Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for securing application workloads in hybrid data centers are challenged by the complexity of managing multiple security group identities, as virtual machines can belong to multiple groups with different policies, requiring complex workarounds.
Innovation Solution
A method and system that derive multiple tags and apply policies using existing overlay technologies, encapsulating a tag pointer in the flow to carry multi-group identities across the fabric, enabling security, QoS, and service chaining with priority resolution, using a single tag pointer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a VM belongs to multiple security group identities with different policies, then security coverage is improved, but device complexity increases due to requiring extremely complex workarounds
Solution Approach 1:
The patent segments the security group identification into multiple independent tags, where each tag represents a different security group identity. Instead of requiring a single complex identifier, the system divides the identification into multiple manageable tags that can be independently managed and applied to the same VM, thereby improving security coverage without increasing overall system complexity
Solution Approach 2:
The patent creates a universal tagging mechanism that allows a single VM to simultaneously belong to multiple security groups through multiple tags. This multi-functional approach enables the VM to inherit policies from different security groups without requiring separate workarounds for each group, thus improving security coverage while maintaining system simplicity
2Device complexity
If existing solutions allow a VM to belong to only one identity group, then device complexity is reduced, but adaptability deteriorates as it requires extremely complex workarounds to support multi-group intent
Solution Approach 1:
The patent introduces a dynamic tagging system where the number of security group tags associated with a VM can flexibly change based on the VM's role and requirements. Unlike static single-group assignments, the system dynamically adds or removes tags as needed, enabling adaptable multi-group support while keeping the underlying mechanism simple through standardized tag management
Solution Approach 2:
The patent introduces tags as intermediary elements that mediate between VMs and security groups. These tags serve as a flexible layer that enables multi-group associations without directly complicating the VM-security group relationship, providing adaptability while maintaining system simplicity through the intermediary tagging mechanism
Data Source
AI summary
Techniques for using policies in an overlay communication network are disclosed. These techniques include deriving a plurality of source tags for a flow relating to an overlay communication network, the plurality of source tags relating to one or more policies for the flow. The techniques further include deriving a tag pointer for the flow, the tag pointer corresponding to all of the plurality of source tags, encapsulating the tag pointer in the flow, and transmitting the flow over the overlay communication network, wherein the tag pointer is configured to be used to identify a plurality of policies for the flow on egress from the overlay communication network.


