Packet-Level Data-Centric Policy Enforcement in Zero-Trust Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing environments face challenges in protecting data due to the complexity of perimeter-based security architectures, which can lead to breaches when the perimeter is compromised, and existing security controls like firewalls and network access policies are difficult to maintain and configure, often resulting in misconfigurations that expose sensitive data.

Innovation Solution

Implementing data-centric, intent-based policies enforced at various enforcement points within the network, using a zero-trust software-defined network that authenticates, authorizes, and encrypts network interactions, and assigns unique Origin IDs to resources for secure data movement across multiple environments, allowing for granular control of data flow based on predefined policies and assertions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If perimeter-based security architectures are used, then network security coverage is provided, but security reliability deteriorates when the perimeter is compromised

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidbreach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security enforcement from perimeter-based to packet-level data centric enforcement. Instead of relying on a single perimeter boundary, security policies are enforced at multiple distributed enforcement points throughout the network infrastructure, including virtual network functions, network devices, and cloud infrastructure components. This segmentation ensures that compromise of one perimeter does not expose the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy enforcement mechanism that acts as an intermediary between data traffic and network resources. This intermediary evaluates packets against security policies at enforcement points, mediating access control decisions based on data-centric rules rather than perimeter location. The intermediary layer provides security validation without requiring traditional perimeter boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional firewall and network access policies are implemented, then basic security control is achieved, but device complexity and maintenance difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal policy enforcement framework that can be deployed across multiple enforcement points including virtual network functions, network devices, and cloud infrastructure. The same data-centric security policies are evaluated and enforced consistently across diverse infrastructure components, eliminating the need for separate security configurations at each layer and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the fundamental parameter of security enforcement from location-based (perimeter/firewall) to data-based (packet-level data centric). By evaluating security policies based on data characteristics, source, destination, and context rather than network perimeter location, the system simplifies policy management while maintaining comprehensive security control across heterogeneous infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If network rules and policies are created to protect data, then security coverage is improved, but time and resources for maintenance increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service capabilities where the policy enforcement system automatically evaluates packets against security policies at distributed enforcement points without requiring manual intervention. The system autonomously makes access control decisions based on data-centric policies, eliminating the need for continuous manual rule updates and reducing maintenance time while maintaining comprehensive security coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary security policy evaluation and enforcement decisions before data breaches can occur. By pre-configuring data-centric security policies and enforcing them at multiple enforcement points in advance, the system proactively prevents unauthorized access rather than requiring reactive maintenance and rule updates after security incidents.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If skilled network administrators create multiple rules and policies, then security protection is enhanced, but misconfiguration risk increases exposing sensitive data

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary policy evaluation mechanism that sits between network administrators' security intentions and actual packet enforcement. This intermediary automatically translates high-level data-centric security policies into enforceable rules at multiple enforcement points, reducing the risk of manual misconfiguration while maintaining comprehensive security protection. The intermediary ensures consistent policy interpretation across the entire network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal policy enforcement mechanism that handles security evaluation consistently across diverse enforcement points and infrastructure types. This universal approach reduces misconfiguration risk by eliminating variations in policy interpretation and enforcement that occur when different administrators configure separate security devices with the same security intent.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250094575A1Packet level data centric protection enforcement
Publication Date: 2025.03.20 ORACLE INT CORP
  • US20250094575A1 patent drawing
  • US20250094575A1 patent drawing
  • US20250094575A1 patent drawing

AI summary

Techniques are described for performing packet level data centric protection enforcement. Instead of being restricted to perimeter-based security and defining and creating rules that are difficult to maintain, techniques described herein allow users to create data-centric, intent-based policies that are enforced at different enforcement points within one or more networks. In some examples, a method comprises receiving a packet at an enforcement point (EP) within one or more networks that include a plurality of enforcement points (EPs); accessing enforcement data that indicates allowed communications between the EP and one or more other EPs, wherein the data are generated from a policy that specifies how traffic flows the one or more networks and a determination of possible data movements between at least two of EPs in the plurality of EPs; and enforcing the flow of the packet at the EP based on the data.