SASE Network Optimization Controller Dynamic Access Modality Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a distributed and complex network environment, especially with the rise of remote work, it is challenging to maintain a consistent user experience while balancing network performance and security, as users often switch access modalities, leading to variations in network and security performance that can compromise either quality or security.
Innovation Solution
A Secure Access Service Edge (SASE) network optimization controller (SNOC) that utilizes security and network performance metrics to dynamically adjust access modalities, switching between different access methods to optimize network performance while maintaining security controls, by obtaining data sets from SASE devices and configuring policies to manage access based on thresholds and whitelisting applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If users switch access modalities to improve network performance, then network performance is improved, but security control is compromised
Solution Approach 1:
The patent implements dynamic access modality switching where the system automatically transitions between different access methods (VPN, direct internet access, SD-WAN) based on real-time network conditions and security requirements. This dynamic adaptation allows the system to optimize network performance while maintaining security controls by selecting the appropriate access modality for each specific scenario.
Solution Approach 2:
The system changes security and network parameters dynamically by adjusting security policy enforcement levels based on the selected access modality. For example, direct internet access may have reduced deep packet inspection while VPN maintains full security scanning, allowing the system to balance performance and security by modifying security parameters according to the active access method.
2Productivity
If administrators bypass security functions to improve system performance, then system performance is improved, but trust and security are compromised in distributed environments
Solution Approach 1:
The patent applies different security function enforcement at different locations in the network architecture. Security functions such as deep packet inspection, threat intelligence scanning, and URL filtering are selectively applied based on the access modality and traffic type. This local quality approach allows performance optimization for trusted traffic while maintaining security for untrusted traffic paths.
Solution Approach 2:
The system implements feedback mechanisms where security performance metrics and network performance metrics are continuously monitored and used to dynamically adjust security policy enforcement. This feedback loop allows the system to maintain security trust by detecting when performance degradation indicates potential security issues, while also optimizing performance by reducing security scanning for trusted applications.
3Adaptability or versatility
If the network environment size and complexity increase to support remote workforce, then adaptability is improved, but trust management becomes more difficult
Solution Approach 1:
The patent implements a universal security policy framework that works across multiple access modalities and device types. The same security policy engine and trust management mechanisms are applied whether users access through VPN, direct internet, SD-WAN, or mobile networks. This universality simplifies trust management by providing consistent security enforcement across the entire distributed network environment.
Solution Approach 2:
The system implements automated trust assessment and access modality selection that reduces manual trust management complexity. Security policies automatically assess user trust levels, device security postures, and network conditions to determine the appropriate access modality without requiring manual administrator intervention for each connection decision.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A network optimization controller (NOC) performs operations including obtaining, from a secure access service edge (SASE) device executing a security service, a first data set defining a security performance metric provided by the security service, and obtaining, from the SASE, a second data set defining a network performance metric associated with a network device, The operations further include defining a policy based at least in part on the first data set and the second data set, determining if the policy has been violated, and changing a first access modality provided for the network device to access an end host to a second access modality based at least in part on the policy being violated. The first access modality and the second access modality define different methods of access to the end host.