SASE Network Optimization Controller Dynamic Access Modality Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a distributed and complex network environment, especially with the rise of remote work, it is challenging to maintain a consistent user experience while balancing network performance and security, as users often switch access modalities, leading to variations in network and security performance that can compromise either quality or security.

Innovation Solution

A Secure Access Service Edge (SASE) network optimization controller (SNOC) that utilizes security and network performance metrics to dynamically adjust access modalities, switching between different access methods to optimize network performance while maintaining security controls, by obtaining data sets from SASE devices and configuring policies to manage access based on thresholds and whitelisting applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If users switch access modalities to improve network performance, then network performance is improved, but security control is compromised

Engineering Contradiction:
Improvenetwork performanceVSAvoidsecurity control
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements dynamic access modality switching where the system automatically transitions between different access methods (VPN, direct internet access, SD-WAN) based on real-time network conditions and security requirements. This dynamic adaptation allows the system to optimize network performance while maintaining security controls by selecting the appropriate access modality for each specific scenario.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security and network parameters dynamically by adjusting security policy enforcement levels based on the selected access modality. For example, direct internet access may have reduced deep packet inspection while VPN maintains full security scanning, allowing the system to balance performance and security by modifying security parameters according to the active access method.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If administrators bypass security functions to improve system performance, then system performance is improved, but trust and security are compromised in distributed environments

Engineering Contradiction:
Improvesystem performanceVSAvoidsecurity trust
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies different security function enforcement at different locations in the network architecture. Security functions such as deep packet inspection, threat intelligence scanning, and URL filtering are selectively applied based on the access modality and traffic type. This local quality approach allows performance optimization for trusted traffic while maintaining security for untrusted traffic paths.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback mechanisms where security performance metrics and network performance metrics are continuously monitored and used to dynamically adjust security policy enforcement. This feedback loop allows the system to maintain security trust by detecting when performance degradation indicates potential security issues, while also optimizing performance by reducing security scanning for trusted applications.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the network environment size and complexity increase to support remote workforce, then adaptability is improved, but trust management becomes more difficult

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidtrust management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security policy framework that works across multiple access modalities and device types. The same security policy engine and trust management mechanisms are applied whether users access through VPN, direct internet, SD-WAN, or mobile networks. This universality simplifies trust management by providing consistent security enforcement across the entire distributed network environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements automated trust assessment and access modality selection that reduces manual trust management complexity. Security policies automatically assess user trust levels, device security postures, and network conditions to determine the appropriate access modality without requiring manual administrator intervention for each connection decision.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4222920B1Dynamic optimization of client application access via a secure access service edge (SASE) network optimization controller (NOC)
Publication Date: 2024.10.16 CISCO TECHNOLOGY INC
  • EP4222920B1 patent drawingFigure 1
  • EP4222920B1 patent drawingFigure 2
  • EP4222920B1 patent drawingFigure 3

AI summary

A network optimization controller (NOC) performs operations including obtaining, from a secure access service edge (SASE) device executing a security service, a first data set defining a security performance metric provided by the security service, and obtaining, from the SASE, a second data set defining a network performance metric associated with a network device, The operations further include defining a policy based at least in part on the first data set and the second data set, determining if the policy has been violated, and changing a first access modality provided for the network device to access an end host to a second access modality based at least in part on the policy being violated. The first access modality and the second access modality define different methods of access to the end host.