Packet Labeling for Network Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Network Bubble Architecture implementations face challenges in managing large access control lists due to pre-existing IP addressing plans, making it costly and complex to define contiguous address ranges for network security policies.

Innovation Solution

The solution involves a secured network with multiple network bubbles and control points, where outgoing packets are marked with a label indicating their origin bubble, and incoming packets are filtered based on this label to enforce a uniform security policy, using a trusted backbone that does not modify packet labels, and applying this policy across network control points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If source and destination IP addresses are used to define bubble partitions in access control lists, then network security policy can be implemented, but the access control list sizes become large due to pre-existing IP addressing plans

Engineering Contradiction:
Improvenetwork security policy enforcementVSAvoidaccess control list size
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters used in access control lists from source and destination IP addresses to bubble identifiers. This parameter substitution dramatically reduces ACL size because multiple IP addresses within the same bubble can be represented by a single bubble identifier, thereby maintaining security policy enforcement while reducing complexity

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces bubble identifiers as an intermediary element between IP addresses and access control lists. These identifiers act as mediators that map multiple IP addresses to single security policy rules, reducing the number of entries needed in ACLs while preserving the ability to enforce granular security policies

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If IP address plan is modified to make contiguous address ranges map to bubble partitions, then access control list complexity is reduced, but the implementation cost becomes expensive

Engineering Contradiction:
Improveaccess control list structureVSAvoidimplementation cost
Core Design Contradiction:
Device complexityVSEase of manufacture

Solution Approach 1:

Instead of modifying the IP address plan to match security requirements, the patent inverts the approach by creating bubble identifiers that map to existing IP address ranges. This allows the security architecture to adapt to the existing IP plan rather than requiring the IP plan to change, thereby reducing implementation cost while simplifying ACL structure

Inventive Principle:
Principle #13The other way round (Inversion)

3Stability of the object's composition

If network control points use replicated access control lists to enforce security policies, then security policy consistency is achieved, but the configuration and management complexity increases

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidconfiguration management
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The patent uses bubble identifiers as templates that can be replicated across multiple network control points. Instead of copying and managing complex IP-based ACL rules at each node, a single bubble identifier definition can be replicated, ensuring security policy consistency while reducing configuration management complexity

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8578441B2Enforcing network security policies with packet labels
Publication Date: 2013.11.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8578441B2 patent drawing
  • US8578441B2 patent drawing
  • US8578441B2 patent drawing

AI summary

A secured network is disclosed configured to carry data, comprising a plurality of network bubbles and a plurality of network control points, wherein each network bubble comprises one or more bubble partitions and each bubble partition comprises at least one networked device configured to transmit and receive data, and all of the network devices corresponding to at least one of the plurality of network bubbles have a common network security policy. At least one network control point, such as a router, is provided with a marker module arranged to mark outgoing packets with a label corresponding to the network bubble from which the packets originate that can be used to enforce the network security policy of the at least one network bubble.