Proxy Service Group-Based Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network virtualization technologies, such as VXLAN, face challenges in enforcing Group-Based Policies (GBP) across heterogeneous networks, particularly in environments with switches that do not support VXLAN or GBP policy enforcement, and in controller-less wireless deployments.

Innovation Solution

A proxy service is deployed on network devices to intercept and manage network access requests, using a common Anycast IP address to simplify authentication and apply GBP to network traffic, ensuring policy enforcement for both wired and wireless clients across the network, even on switches or access points that do not support GBP.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VXLAN and GBP policy enforcement are implemented on switches, then network segmentation and policy control are improved, but device compatibility and ease of deployment deteriorate due to requirements for specialized hardware support

Engineering Contradiction:
Improvepolicy enforcementVSAvoidswitch compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a controller as an intermediary component that performs GBP policy enforcement functions. The controller intercepts VXLAN traffic and applies policy decisions centrally, allowing standard switches without GBP support to participate in the network. This mediator approach transfers the complex policy enforcement logic from individual switches to a centralized controller, resolving the contradiction between reliable policy enforcement and broad switch compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces hardware-based GBP enforcement mechanisms with software-based implementation on the controller. Instead of requiring specialized ASICs or hardware features in switches, the policy enforcement is achieved through software processing of VXLAN headers and metadata, substituting mechanical/hardware constraints with flexible software solutions that work across diverse switch platforms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If GBP is enforced at the controller in wireless networks, then policy control is improved, but deployment complexity increases due to requirements for controller infrastructure

Engineering Contradiction:
Improvepolicy controlVSAvoidcontroller infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the controller to perform multiple functions: it acts as both the centralized GBP policy enforcement point and the VXLAN tunnel endpoint. The controller handles authentication, policy decision-making, and traffic forwarding functions in one unified component, reducing overall system complexity despite the presence of controller infrastructure. This multi-functionality approach consolidates responsibilities that would otherwise require separate components

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If switches without VXLAN support are used in the network, then ease of deployment and cost are improved, but network virtualization capabilities deteriorate

Engineering Contradiction:
Improvedeployment simplicityVSAvoidvirtualization support
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments the network into control plane and data plane functions. Standard switches handle only the data plane (forwarding traffic), while the controller handles the control plane (policy enforcement, VXLAN header manipulation). This segmentation allows inexpensive, simple switches to be deployed throughout the network while virtualization capabilities are maintained through the controller's processing of VXLAN-encapsulated traffic

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The controller serves as an intermediary that translates between standard Ethernet frames and VXLAN-encapsulated packets. It adds VXLAN headers with appropriate metadata for policy enforcement, allowing traffic from switches without native VXLAN support to be virtualized and managed through the controller. This intermediary function enables gradual migration to virtualization without requiring all switches to support VXLAN

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240283798A1Applying a group based policy to network traffic from a client
Publication Date: 2024.08.22 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20240283798A1 patent drawing
  • US20240283798A1 patent drawing
  • US20240283798A1 patent drawing

AI summary

Some examples relate to a proxy service on a network device for applying a group based policy (GBP) to network traffic from a client. In an example, a proxy service on a network device is used to intercept a network access request message, pertaining to a client, from an access device. The proxy service forwards the network access request message to an authentication server. The server responds by sending a network access response message to the access device. The proxy service intercepts the network access response message from the authentication server and obtains the role information of the client from the network access response message. In response to receiving network traffic from the client, the proxy service identifies a GBP corresponding to the role information of the client and applies the GBP to the network traffic from the client.