Low-Level Network Security Configuration via Cumulative Policy Deltas

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems face inefficiencies in managing and deploying device-level security configuration updates due to continuous changes in security intent policy models, leading to excessive use of computing resources and suboptimal performance.

Innovation Solution

A network management system generates delta snapshots to track incremental changes in the security intent policy model, allowing for the efficient generation and deployment of updated device-level security configuration information by maintaining a low-level security intent policy model, thereby reducing resource usage and enabling quick updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network management system continuously monitors and deploys updates to the security intent policy model in response to frequent changes, then the security configuration remains up-to-date and reliable, but excessive computing resources are consumed and system performance deteriorates

Engineering Contradiction:
Improvesecurity configuration up-to-dateVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the security intent policy model into multiple hierarchical levels (global policy level, device-level policy level, and rule level). By dividing the monolithic policy model into smaller manageable segments, the system only needs to process and deploy changes at the specific level where modifications occur, rather than continuously monitoring and deploying updates across the entire model. This segmentation reduces the computational overhead while maintaining configuration reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-compiling the security intent policy model into a low-level policy model that is optimized for device deployment. The system performs change detection and delta calculation in advance, preparing update packages before actual deployment is needed. This preliminary processing reduces the computational burden during runtime when changes occur, as the heavy lifting of policy translation and validation has already been done.

Inventive Principle:
Principle #10Preliminary action

2Manufacturing precision

If the system generates and deploys updated device-level security configuration information frequently to reflect changes in the security intent policy model, then the configuration accuracy is improved, but the time required for deployment and system overhead increases

Engineering Contradiction:
Improveconfiguration accuracyVSAvoiddeployment time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent extracts only the necessary changes from the security intent policy model by implementing a change detection mechanism that identifies modified policies and rules. Instead of deploying the entire policy model, the system extracts only the delta portions that need to be updated at the device level. This extraction approach maintains configuration accuracy by ensuring all necessary changes are captured, while significantly reducing deployment time by transmitting and applying only the changed portions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by implementing selective policy deployment. The system performs change detection at multiple levels (global policy, device-level policy, rules) and only deploys updates for the specific portions of the policy model that have changed. This partial deployment approach avoids the time overhead of deploying complete policy models while ensuring configuration accuracy is maintained for all modified elements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250240328A1Efficient updating of device-level security configuration based on changes to security intent policy model
Publication Date: 2025.07.24 JUNIPER NETWORKS INC
  • US20250240328A1 patent drawing
  • US20250240328A1 patent drawing
  • US20250240328A1 patent drawing

AI summary

A system may identify a security intent policy model associated with an initial time. The system may generate one or more delta snapshots that respectively indicate one or more incremental changes to the security intent policy model at times subsequent to the initial time. The system may determine that the system is to deploy an updated version of the security intent policy model to a device and may thereby determine a previous deployment time at which the system deployed a previous version of the security intent policy model to the device. The system may generate, based on the one or more delta snapshots and the previous deployment time, a cumulative delta snapshot, and may thereby update a low-level security intent policy model associated with the device. The system may generate, based on the low-level security intent policy model, device-level security configuration information for the device.