SD-WAN Policy Header Packet Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network architectures face delays and bandwidth issues when routing SaaS applications through central data centers, and managing access control and security across multiple segments is complex and prone to human error.

Innovation Solution

A system and method for generating and processing wide area networking packets that include policy information, such as network segment, application, and security information, using a policy configuration to validate and encrypt packets, and manage network traffic centrally across software-defined wide area networks (SD-WANs).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packets are routed through central data centers, then centralized control is maintained, but additional delay and bandwidth congestion occur

Engineering Contradiction:
Improvecentralized controlVSAvoidrouting delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments network traffic into different types (SaaS applications, cloud services, traditional enterprise applications) and routes them through different paths. Direct Internet access is provided for SaaS and cloud services, while centralized data center routing is maintained for traditional enterprise applications, thereby reducing delay for time-sensitive traffic while preserving centralized control for other traffic

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary controller or orchestrator is introduced that maintains centralized policy management and control plane functions while allowing distributed data plane operations. This intermediary enables direct Internet access for appropriate traffic types while maintaining centralized oversight through policy enforcement points at branch offices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If direct Internet access is implemented, then routing delay is reduced, but access control and security management complexity increases

Engineering Contradiction:
Improverouting delayVSAvoidaccess control management
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

Multiple security functions (access control, firewall, intrusion prevention, encryption) are merged into unified security policies that are centrally managed and automatically distributed to branch office devices. This consolidation simplifies management by providing a single source of truth for security configurations while maintaining comprehensive security controls across distributed direct Internet access points

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Security policies, access control rules, and encryption parameters are pre-configured and distributed to branch office devices before direct Internet access is established. This preliminary configuration enables automatic enforcement of security controls without requiring complex real-time decision-making at distributed locations, thereby reducing management complexity while maintaining security

Inventive Principle:
Principle #10Preliminary action

3Reliability

If individual access control is configured at each router, then security is enforced, but configuration complexity and human error increase

Engineering Contradiction:
Improvesecurity enforcementVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A universal policy management system is implemented that provides multi-functional security controls (access control, firewall, encryption, intrusion prevention) through a single configuration interface. This universal system eliminates the need for separate individual configurations at each router by providing centralized policy templates that automatically adapt to different branch office environments, thereby maintaining security enforcement while dramatically reducing configuration complexity and human error

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3907964B1Method device and system for policy based packet processing
Publication Date: 2024.07.17 HEWLETT PACKARD ENTERPRISE DEV LP
  • EP3907964B1 patent drawingFigure 1
  • EP3907964B1 patent drawingFigure 2
  • EP3907964B1 patent drawingFigure 3A

AI summary

Provided are methods, apparatus, and system for policy based wide area network. A network of network appliances is configured with a policy configuration. Each network appliance is configured to validate each wide area network packet against the policy configuration. The validation can include verifying that the packets meet the SD-WAN network segment requirements and security rules including verifying that the source and destination address of the packet meet the firewall zone requirements. Each wide area network packet contains a policy header that is checked by the sending and receiving network appliance against the policy configuration.