Policy Management Server Constraint Rules for Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing complex network segmentation policies in large enterprises becomes increasingly challenging due to the complexity of networks and the number of workloads, leading to security risks from overly permissive configurations.

Innovation Solution

A policy management server that enforces segmentation policies by applying constraint rules to identify non-compliant rules, initiating a workflow process to resolve them, and distributing policies to distributed enforcement modules, including features like pre-approval, post-approval, and automatic rule modification to ensure compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a segmentation policy is narrowly tailored to permit only necessary traffic, then security is improved, but configuration complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-service through workflow processes that automatically detect non-compliant rules, initiate approval workflows, and enforce policy constraints without requiring manual security analyst intervention for each rule configuration

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-defining policy constraints and approval workflows before segmentation rules are configured, allowing automated compliance checking and enforcement to occur during rule creation and updates

Inventive Principle:
Principle #10Preliminary action

2Manufacturing precision

If manual configuration of segmentation policies is performed, then policy precision is improved, but time consumption increases

Engineering Contradiction:
Improvepolicy precisionVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system enables automated self-service through workflow processes that automatically detect non-compliant rules, initiate approval workflows, and enforce policy constraints without requiring manual security analyst intervention for each rule configuration

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical configuration processes with automated electronic workflow processes that use algorithms to detect non-compliance, manage approval states, and enforce constraints automatically

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If an overly permissive segmentation policy is used, then ease of configuration is improved, but security risks increase

Engineering Contradiction:
Improveease of configurationVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by pre-defining policy constraints that automatically prevent overly permissive rules from being enforced, and by implementing approval workflows that block non-compliant rules before they can create security vulnerabilities

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system implements feedback mechanisms that automatically monitor segmentation rules for compliance with policy constraints, provide notifications of non-compliance to administrators, and enforce corrective actions through workflow processes

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11647050B2Constraint rules for constraining creation of a segmentation policy
Publication Date: 2023.05.09 ILLUMIO INC
  • US11647050B2 patent drawing
  • US11647050B2 patent drawing
  • US11647050B2 patent drawing

AI summary

A policy management server manages a segmentation policy and policy constraints. The segmentation policy comprises a set of segmentation rules that each permit connections between specified groups of workloads that provide or consume network-based services. The policy constraints comprise a set of constraint rules that determine compliance of the segmentation rules. A workflow process may be initiated to resolve non-compliant rules by enabling an administrator to approve or deny the rule. In a large enterprise managing significant numbers of workloads, the policy constraints may be employed to ensure that overly permissive segmentation rules are not being created. This facilitates creation of a robust and narrowly tailored segmentation policy that reduces exposure of the enterprise to network-based security threats.