Policy-Driven Route Leaking for Isolated Network Segments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network segmentation in enterprise and cloud environments isolates users and services, preventing seamless connectivity and complicating service delivery when multiple segments need to access shared resources.
Innovation Solution
A policy-driven mechanism defines segment resources and their associated subnets or routes, allowing controlled connectivity through a centralized controller that injects routes into the forwarding plane using serialization techniques, enabling bi-directional or uni-directional access while maintaining segment isolation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network segmentation is implemented to isolate users and services, then security and access control are improved, but connectivity between segments deteriorates
Solution Approach 1:
The patent applies network segmentation by dividing the network into isolated segments (e.g., Segment A and Segment B) with distinct routing tables and forwarding planes. Each segment maintains its own isolation boundaries while the system provides controlled connectivity through policy-driven route leaking mechanisms that allow specific traffic flows between segments when authorized.
Solution Approach 2:
The patent introduces a centralized controller as an intermediary component that mediates between isolated segments. This controller receives connectivity requests, evaluates segment resource-share policies, and programmatically injects appropriate routes into the forwarding plane of destination segments. The intermediary enables controlled communication while preserving the isolation benefits of segmentation.
2Reliability
If static network configuration is used to maintain segment isolation, then security is improved, but adaptability to dynamic connectivity needs deteriorates
Solution Approach 1:
The patent transforms static network configuration into a dynamic system where routing policies can be programmatically modified in real-time. The centralized controller receives connectivity requests and dynamically injects routes into the forwarding plane based on current segment resource-share policies. This enables the network to adapt to changing connectivity needs while maintaining security through policy-driven control.
Solution Approach 2:
The patent changes the parameter of route availability dynamically. Instead of static pre-configured routes, the system modifies routing tables by injecting new routes when connectivity is authorized. The controller evaluates policies and selectively adds or removes routes based on current segment resource-share configurations, enabling flexible adaptation without compromising isolation when policies require it.
3Ease of operation
If route leaking is implemented to enable inter-segment access, then connectivity is improved, but network complexity increases
Solution Approach 1:
The patent extracts the route leaking functionality from individual network devices and consolidates it into a centralized controller. Instead of configuring complex routing policies on each device, the controller receives connectivity requests, evaluates policies, and programmatically injects routes into the forwarding plane. This extraction simplifies device configuration while enabling sophisticated inter-segment access control.
Solution Approach 2:
The centralized controller serves multiple functions: it receives connectivity requests from source segments, evaluates segment resource-share policies, determines authorized routes, and programmatically injects routes into destination segments. This multi-functional approach consolidates complexity into a single controller while simplifying individual device operations and enabling flexible inter-segment connectivity.
Data Source
AI summary
Disclosed is a system and a method for managing communication between isolated network segments. The system comprising one or more hardware processors, and a memory storing instructions that, when executed by the one or more hardware processors, cause the system to receive definitions of a first segment resource associated with a first network segment and a second segment resource associated with a second network segment such that each of the first and second segment resources comprises connectors and associated subnets or routes, generate a segment resource-share policy specifying one or more subnets or routes associated with the first segment resource to be leaked into the second network segment, or one or more subnets or routes associated with the second segment resource to be leaked into the first network segment, and distribute the segment resource-share policy in a form accessible to one or more network nodes configured to enforce the policy.


