SDN Intent Verification for Policy Consistency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex network configurations in software-defined networks (SDNs) lead to error-prone configurations and difficult troubleshooting, as inconsistencies and conflicts between policies can result in unintended network behavior, making it challenging to ensure that the network operates as intended by the operator.

Innovation Solution

A system and method for checking intent specifications in SDNs by obtaining a logical model of the network, performing syntactic and semantic verification of configurations using a hierarchical management information tree, and detecting errors to ensure consistency and accuracy of network policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network operators use a wide array of configuration options to tailor the network to user needs, then network flexibility and control are improved, but network complexity increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidnetwork complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary verification system that acts as a mediator between network configuration intent and implementation. This system includes a policy analysis component that verifies intent specifications against a logical model of the network, and a policy rendering component that translates verified intents into device configurations. This intermediary layer prevents complexity from propagating through the entire network configuration process while maintaining flexibility at the intent level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary verification of intent specifications before network configuration is implemented. The policy analysis component performs syntactic and semantic verification of intent specifications against the logical model prior to rendering configurations. This preliminary action identifies and prevents inconsistencies and conflicts before they propagate through the network, reducing overall complexity while preserving configuration flexibility.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If comprehensive network policies are implemented to control network behavior, then network control is improved, but configuration errors increase

Engineering Contradiction:
Improvenetwork controlVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the policy analysis component continuously verifies intent specifications against the logical model and provides feedback on inconsistencies and conflicts. The system renders policy decisions based on this feedback, ensuring that only verified intents are implemented. This closed-loop feedback process maintains network control while preventing configuration errors from occurring.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by proactively identifying and preventing configuration errors before they occur. The policy analysis component performs verification checks that detect inconsistencies, conflicts, and potential errors in intent specifications before they are rendered into actual network configurations. This preliminary prevention mechanism maintains comprehensive policy control while ensuring configuration accuracy.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of repair

If manual troubleshooting is performed in complex networks, then troubleshooting capability is maintained, but troubleshooting time and difficulty increase

Engineering Contradiction:
Improvetroubleshooting capabilityVSAvoidtroubleshooting time
Core Design Contradiction:
Ease of repairVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-identifying and flagging potential network issues through automated policy analysis before they manifest as actual problems. The system continuously verifies intent specifications and logical model consistency, detecting conflicts and inconsistencies early in the configuration process. This preliminary detection significantly reduces troubleshooting time and effort when issues do occur, as problems are identified at the source rather than requiring manual network-wide investigation.

Inventive Principle:
Principle #10Preliminary action

4Manufacturing precision

If automated policy analysis is implemented, then configuration accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent segments the policy analysis function into distinct, modular components: a policy analysis component for verification, a logical model for network representation, and a policy rendering component for configuration generation. This segmentation allows each component to have a specific, well-defined function, improving configuration accuracy through specialized processing while managing system complexity through modular architecture. The segmented approach enables independent verification and rendering operations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3632041B1Intent specification checks for inconsistencies
Publication Date: 2021.12.08 CISCO TECHNOLOGY INC
  • EP3632041B1 patent drawingFigure 1A
  • EP3632041B1 patent drawingFigure 1B
  • EP3632041B1 patent drawingFigure 2A

AI summary

Systems, methods, and computer-readable media for intent specification checks. In one example, a system obtains, from one or more controllers in a software-defined network, a logical model of the software-defined network, the logical model including configurations of one or more objects in a hierarchical management information tree that defines manageable objects and object properties for the software-defined network. Based on the hierarchical management information tree, the system performs a policy analysis of configurations in the logical model and determines, based on the policy analysis, whether the configurations in the logical model contain one or more errors.