Low-Level Network Security Configuration via Cumulative Policy Deltas
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems face inefficiencies in managing and deploying device-level security configuration updates due to continuous changes in security intent policy models, leading to excessive use of computing resources and suboptimal performance.
Innovation Solution
A network management system generates delta snapshots to track incremental changes in the security intent policy model, allowing for the efficient generation and deployment of updated device-level security configuration information by maintaining a low-level security intent policy model, thereby reducing resource usage and enabling quick updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the network management system continuously monitors and deploys updates to the security intent policy model in response to frequent changes, then the security configuration remains up-to-date and reliable, but excessive computing resources are consumed and system performance deteriorates
Solution Approach 1:
The patent segments the security intent policy model into multiple hierarchical levels (global policy level, device-level policy level, and rule level). By dividing the monolithic policy model into smaller manageable segments, the system only needs to process and deploy changes at the specific level where modifications occur, rather than continuously monitoring and deploying updates across the entire model. This segmentation reduces the computational overhead while maintaining configuration reliability.
Solution Approach 2:
The patent implements preliminary action by pre-compiling the security intent policy model into a low-level policy model that is optimized for device deployment. The system performs change detection and delta calculation in advance, preparing update packages before actual deployment is needed. This preliminary processing reduces the computational burden during runtime when changes occur, as the heavy lifting of policy translation and validation has already been done.
2Manufacturing precision
If the system generates and deploys updated device-level security configuration information frequently to reflect changes in the security intent policy model, then the configuration accuracy is improved, but the time required for deployment and system overhead increases
Solution Approach 1:
The patent extracts only the necessary changes from the security intent policy model by implementing a change detection mechanism that identifies modified policies and rules. Instead of deploying the entire policy model, the system extracts only the delta portions that need to be updated at the device level. This extraction approach maintains configuration accuracy by ensuring all necessary changes are captured, while significantly reducing deployment time by transmitting and applying only the changed portions.
Solution Approach 2:
The patent applies partial action by implementing selective policy deployment. The system performs change detection at multiple levels (global policy, device-level policy, rules) and only deploys updates for the specific portions of the policy model that have changed. This partial deployment approach avoids the time overhead of deploying complete policy models while ensuring configuration accuracy is maintained for all modified elements.
Data Source
AI summary
A system may identify a security intent policy model associated with an initial time. The system may generate one or more delta snapshots that respectively indicate one or more incremental changes to the security intent policy model at times subsequent to the initial time. The system may determine that the system is to deploy an updated version of the security intent policy model to a device and may thereby determine a previous deployment time at which the system deployed a previous version of the security intent policy model to the device. The system may generate, based on the one or more delta snapshots and the previous deployment time, a cumulative delta snapshot, and may thereby update a low-level security intent policy model associated with the device. The system may generate, based on the low-level security intent policy model, device-level security configuration information for the device.


