Router And Cloud Security Orchestration for Unified Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The lack of orchestration across network devices, including both local and cloud environments, leads to inconsistent and inefficient security policy enforcement, requiring manual configuration and expertise in multiple management portals, which can result in duplication and user errors during SASE migration.

Innovation Solution

A method for orchestrating security solutions across network devices by determining device capabilities and intelligently distributing security features between routers and cloud security services, providing a unified management interface to simplify policy implementation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security features are manually configured across multiple management portals, then security policy enforcement can be implemented, but administrative complexity and potential for errors increase

Engineering Contradiction:
Improvesecurity policy enforcement consistencyVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security management portals into a single unified orchestration interface. The system integrates cloud security service management with on-premises network device management, allowing administrators to configure and enforce security policies across hybrid environments through one consolidated portal rather than multiple separate interfaces.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an orchestration system as an intermediary layer between the administrator and the underlying security infrastructure. This orchestration layer translates high-level security policies into device-specific configurations, managing the complexity of enforcing security policies across diverse network devices and cloud services without exposing administrators to the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If security features are distributed across multiple devices and cloud services, then resource utilization is optimized, but configuration and management complexity increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidconfiguration simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent segments security features and distributes them across multiple network devices and cloud services based on capability assessments. The orchestration system evaluates which devices can handle specific security functions and automatically distributes security policies accordingly, optimizing resource utilization while maintaining centralized management through the unified interface.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service capabilities where the orchestration system automatically assesses device capabilities, determines optimal security feature distribution, and configures devices without requiring manual intervention. The system autonomously manages the complexity of distributed security configuration by evaluating device attributes and automatically allocating security functions to appropriate resources.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If capability assessment is performed for each device, then optimal security feature distribution is achieved, but assessment time and computational resources increase

Engineering Contradiction:
Improvesecurity feature distribution optimizationVSAvoidassessment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs capability assessment as a preliminary action during device onboarding or registration with the orchestration system. By assessing device capabilities upfront and storing this information in the orchestration system's database, the system avoids repeated assessments and can quickly make informed decisions about security feature distribution based on pre-collected device attribute information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12388789B2Security solution orchestration
Publication Date: 2025.08.12 CISCO TECHNOLOGY INC
  • US12388789B2 patent drawing
  • US12388789B2 patent drawing
  • US12388789B2 patent drawing

AI summary

This disclosure describes techniques for orchestrating implementation of a security solution among network devices. The techniques include determining capabilities of routers of the network and capabilities of a cloud security service to perform security features of a security solution. Based at least in part on the capabilities, the techniques include configuring a router of the network to execute a first subset of the security features on data traffic of the network, and configuring the cloud security service to execute a second subset of the security features on the data traffic. The techniques may also include causing the security solution to be presented to a security administrator via a display, the display providing representations of the first subset and the second subset of the security features.