Cloud-Native SDN Policy Generation for Continuous Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software-defined networking (SDN) architectures face challenges in cloud-native adoption due to complexity in life cycle management, scale limitations in configuration modules, and the lack of a command-line interface (CLI)-based interface, making them inefficient for modern cloud-native environments such as 5G mobile networks and enterprise use cases.

Innovation Solution

A cloud-native SDN architecture is introduced, which includes a container-based microservices architecture that supports in-service upgrades, assumes a base container orchestration platform, and integrates with cloud-native monitoring tools, leveraging Kubernetes constructs for scalable and agile network management, and automates network resource provisioning to create highly scalable virtual networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional SDN architecture is used, then network control is centralized and manageable, but life cycle management becomes complex and scalability is limited

Engineering Contradiction:
Improvecloud-native adoption capabilityVSAvoidlife cycle management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the SDN controller into multiple independent microservices that can be deployed, managed, and scaled separately. Each microservice handles specific network control functions, allowing independent lifecycle management and reducing overall system complexity while improving cloud-native adaptability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal container orchestration layer that can manage diverse network workloads and applications across different environments. This multi-functional platform provides standardized interfaces and automation capabilities that work across various cloud-native scenarios, reducing management complexity while enhancing versatility

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If manual network configuration is used, then network policies can be carefully controlled, but deployment efficiency is low and automation is lacking

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidnetwork policy automation
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent implements self-service automation where the system automatically generates, validates, and deploys network policies based on application definitions. The orchestration platform autonomously manages network resource provisioning and policy enforcement without manual intervention, significantly improving deployment efficiency while maintaining proper control through automated validation rules

Inventive Principle:
Principle #25Self-service

3Loss of time

If network policies are manually created and applied, then policy accuracy can be ensured, but time consumption increases and continuous deployment is hindered

Engineering Contradiction:
Improvepolicy deployment timeVSAvoidnetwork policy accuracy
Core Design Contradiction:
Loss of timeVSManufacturing precision

Solution Approach 1:

The patent performs preliminary validation and generation of network policies during the application definition phase. Policies are pre-configured, validated for correctness, and stored in a catalog before deployment, ensuring accuracy is maintained while enabling rapid deployment during continuous integration/continuous deployment (CI/CD) workflows

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements automated feedback mechanisms that validate network policies during deployment and provide real-time feedback on policy correctness. The system monitors policy application status and automatically corrects or alerts on issues, maintaining policy accuracy while minimizing deployment time through iterative validation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12177069B2Network policy generation for continuous deployment
Publication Date: 2024.12.24 JUNIPER NETWORKS INC
  • US12177069B2 patent drawing
  • US12177069B2 patent drawing
  • US12177069B2 patent drawing

AI summary

In an example, a method comprises obtaining, by a policy controller from a first SDN architecture system, flow metadata for packet flows exchanged among workloads of a distributed application deployed to the first SDN architecture system; identifying, using flow metadata for a packet flow of the packet flows, a source endpoint workload and a destination endpoint workload of the packet flow; generating a network policy rule to allow packet flows from the source endpoint workload to the destination endpoint workload of the packet flow; and adding the network policy rule to a configuration repository as configuration data for a second SDN architecture system to cause a deployment system to configure the second SDN architecture system with the network policy rule to allow packet flows from the source endpoint workload to the destination endpoint workload when the distributed application is deployed to the second SDN architecture system.