Security Group Definition for Multi-Site Network Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing logical networks across multiple federated sites, such as datacenters, is challenging due to the need for coordinated security policies and machine group definitions that span multiple sites while maintaining site autonomy and efficient data transfer.

Innovation Solution

A method is introduced to define a group of machines with a span specifying the sites where the group is used, along with criteria for inclusion, such as location, machine characteristics, and metadata, which is distributed to each site for local determination and application in security policies, allowing for site-specific rules without requiring explicit network addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are defined using individual machine addresses across multiple sites, then precise traffic control is achieved, but administrative complexity and difficulty of management increase significantly

Engineering Contradiction:
Improvetraffic control precisionVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual machine addresses into a single security group object that can be referenced across multiple sites. Instead of managing individual IP addresses in security policies, administrators create a security group that automatically aggregates member machines based on criteria, reducing the number of objects to manage while maintaining precise traffic control capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security group object serves multiple functions: it acts as a traffic selector in security policies, a container for machine organization across sites, and a dynamic collection that automatically updates based on membership criteria. This multi-functionality eliminates the need for separate management mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If separate security policies are maintained at each site, then site autonomy is preserved, but coordination and consistency across federated sites become difficult

Engineering Contradiction:
Improvesite autonomyVSAvoidpolicy consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security group definition acts as an intermediary object that is distributed to multiple sites. Each site maintains its own security policies locally, but they all reference the same security group definitions that are propagated from a central management system. This intermediary mechanism enables both local autonomy and global consistency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security group definitions are pre-configured and distributed to all sites before policy enforcement. The central management system prepares the group definitions with membership criteria and distributes them in advance to each site's network controllers, ensuring consistency is established before operational decisions are made at each site.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If machines are dynamically added or removed from security groups, then security policies remain current, but the overhead of continuous synchronization across sites increases

Engineering Contradiction:
Improvepolicy currencyVSAvoidsynchronization overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Instead of synchronizing complete security group definitions across all sites for every change, the system implements selective updates where only affected sites receive notifications about membership changes. Network controllers at each site independently evaluate whether local machines match updated criteria, reducing unnecessary synchronization traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Each site's network controllers independently evaluate security group membership criteria against local machine inventories to determine current members. This self-service approach eliminates the need for centralized membership determination and reduces synchronization overhead, as each site autonomously maintains accurate group membership information.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11777793B2Location criteria for security groups
Publication Date: 2023.10.03 VMWARE INC
  • US11777793B2 patent drawing
  • US11777793B2 patent drawing
  • US11777793B2 patent drawing

AI summary

Some embodiments provide a method for distributing a group definition for a group of machines. The method receives the group definition, which includes (i) a span of the group that specifies a set of sites at which the group is to be used and (ii) a set of criteria for machines to be included in the group. The set of criteria includes at least a location criteria specifying one or more sites. The method distributes the group definition to each site in the set of sites. At each site in the set of sites, a local network control system of the site determines a set of machines in the group based on the set of criteria. Only machines in the one or more sites specified by the location criteria are determined to be in the group.