Cooperative Security Fabric for Consistent Multi-Device Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face challenges in maintaining consistent and cost-effective security configurations across multiple network security devices, leading to potential security holes due to complexity and the need for manual, isolated implementations.
Innovation Solution
A cooperative security fabric is implemented as a unified object for configuration, using an intent-based approach to distribute and apply security policies across interconnected network security devices, with a root node managing and enforcing policies through a hierarchical structure and bi-directional tunnels for communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If multiple network security devices are configured manually and isolated, then each device can be configured independently, but security consistency deteriorates and security holes increase
Solution Approach 1:
The patent merges multiple network security devices into a unified security fabric where devices cooperate through standardized interfaces and protocols. This allows independent configuration capabilities to be maintained while achieving security consistency through centralized policy distribution and coordinated enforcement across all devices in the fabric.
Solution Approach 2:
The patent implements a universal security fabric architecture that can accommodate different types of network security devices (firewalls, IDS/IPS, SD-WAN, etc.) through standardized interfaces. This multi-functionality enables diverse devices to work together cooperatively, maintaining individual device independence while achieving unified security policy enforcement across the entire network.
2Reliability
If network security complexity increases to cover more devices, then security coverage improves, but the risk of unintended security holes increases
Solution Approach 1:
The patent segments the complex network security system into modular functional components including security fabric agents, policy management modules, and device-specific security functions. This segmentation allows comprehensive security coverage across multiple devices while managing complexity through standardized, interchangeable security modules that can be independently configured and maintained.
Solution Approach 2:
The patent introduces security fabric agents as intermediary components that mediate between centralized policy management and individual network security devices. These agents simplify complexity by providing standardized communication protocols and coordination mechanisms, enabling comprehensive security coverage without requiring direct complex interactions between all devices.
3Adaptability or versatility
If manual configuration of each security device is performed, then configuration flexibility is maintained, but time consumption and costs increase
Solution Approach 1:
The patent implements preliminary action through centralized security policy creation and validation before deployment. Security policies are defined, validated, and prepared in advance at the fabric level, then automatically distributed to relevant network security devices. This preliminary configuration action maintains flexibility through centralized policy design while dramatically reducing deployment time through automated distribution and enforcement.
Solution Approach 2:
The patent implements feedback mechanisms where security fabric agents continuously monitor device configurations and policy enforcement status. This feedback enables automatic detection of configuration drift or violations, allowing the system to maintain configuration flexibility through adaptive policy adjustment while reducing time consumption by eliminating manual verification steps across multiple devices.
Data Source
AI summary
Systems, devices, and methods are discussed for treating a number of network security devices in a cooperative security fabric as a unified object for configuration purposes.


