Packet Labeling for Network Security Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Network Bubble Architecture implementations face challenges in managing large access control lists due to pre-existing IP addressing plans, making it costly and complex to define contiguous address ranges for network security policies.
Innovation Solution
The solution involves a secured network with multiple network bubbles and control points, where outgoing packets are marked with a label indicating their origin bubble, and incoming packets are filtered based on this label to enforce a uniform security policy, using a trusted backbone that does not modify packet labels, and applying this policy across network control points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If source and destination IP addresses are used to define bubble partitions in access control lists, then network security policy can be implemented, but the access control list sizes become large due to pre-existing IP addressing plans
Solution Approach 1:
The patent changes the parameters used in access control lists from source and destination IP addresses to bubble identifiers. This parameter substitution dramatically reduces ACL size because multiple IP addresses within the same bubble can be represented by a single bubble identifier, thereby maintaining security policy enforcement while reducing complexity
Solution Approach 2:
The patent introduces bubble identifiers as an intermediary element between IP addresses and access control lists. These identifiers act as mediators that map multiple IP addresses to single security policy rules, reducing the number of entries needed in ACLs while preserving the ability to enforce granular security policies
2Device complexity
If IP address plan is modified to make contiguous address ranges map to bubble partitions, then access control list complexity is reduced, but the implementation cost becomes expensive
Solution Approach 1:
Instead of modifying the IP address plan to match security requirements, the patent inverts the approach by creating bubble identifiers that map to existing IP address ranges. This allows the security architecture to adapt to the existing IP plan rather than requiring the IP plan to change, thereby reducing implementation cost while simplifying ACL structure
3Stability of the object's composition
If network control points use replicated access control lists to enforce security policies, then security policy consistency is achieved, but the configuration and management complexity increases
Solution Approach 1:
The patent uses bubble identifiers as templates that can be replicated across multiple network control points. Instead of copying and managing complex IP-based ACL rules at each node, a single bubble identifier definition can be replicated, ensuring security policy consistency while reducing configuration management complexity
Data Source
AI summary
A secured network is disclosed configured to carry data, comprising a plurality of network bubbles and a plurality of network control points, wherein each network bubble comprises one or more bubble partitions and each bubble partition comprises at least one networked device configured to transmit and receive data, and all of the network devices corresponding to at least one of the plurality of network bubbles have a common network security policy. At least one network control point, such as a router, is provided with a marker module arranged to mark outgoing packets with a label corresponding to the network bubble from which the packets originate that can be used to enforce the network security policy of the at least one network bubble.


