Network Security Policy Modeling for Readable Cloud Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security policies defined using a domain-specific language (DSL) are abstract and difficult for network security engineers to understand and modify, as the cloud native enforcement artifacts generated from these policies are obscure and not easily interpretable by humans.

Innovation Solution

A policy domain model is generated from the DSL code, incorporating hierarchical, relational, and graph data to provide a human-readable representation of network security policies, allowing users to visualize and modify these policies through a graphical interface, with changes reflected in updated cloud native enforcement artifacts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If cloud native enforcement artifacts are generated from DSL code, then network security policies can be implemented on cloud computing server systems, but the enforcement artifacts become obscure and difficult for network security engineers to understand and modify

Engineering Contradiction:
Improveautomatic policy implementationVSAvoidpolicy understandability
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer consisting of visual policy representations (graphs, diagrams, and structured views) that bridge the gap between high-level DSL policies and low-level cloud native enforcement artifacts. This intermediary allows network security engineers to interact with and understand policies without directly modifying the obscure enforcement artifacts or the abstract DSL code.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates multiple copies and representations of the same policy information in different formats: the original DSL code, visual graphs showing policy relationships, structured policy objects, and enforcement artifacts. Each representation serves different purposes, allowing engineers to work with the format most suitable for their task while maintaining consistency across all representations.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If DSL code is used to define security policies, then policies can be defined using intent-based language accessible to developers, but the DSL specification becomes too abstract for network security engineers to understand and modify

Engineering Contradiction:
Improvedeveloper accessibilityVSAvoidpolicy modifiability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments policy information into distinct components and representations: intent-based DSL statements, structured policy objects with specific properties, visual graphs showing relationships between policy elements, and enforcement artifacts. This segmentation allows network security engineers to work with the structured representations that provide both readability and modifiability while preserving the intent-based nature of the original DSL.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms the one-dimensional DSL code into multiple dimensions of representation including visual graphs (spatial dimension), structured objects (hierarchical dimension), and enforced artifacts (implementation dimension). This multi-dimensional approach allows engineers to interact with policies from different perspectives, making them both understandable and modifiable.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12621348B2Network security policy management
Publication Date: 2026.05.05 SALESFORCE INC
  • US12621348B2 patent drawing
  • US12621348B2 patent drawing
  • US12621348B2 patent drawing

AI summary

Systems, devices, and techniques are disclosed for network security policy management. A file including code written using a Domain Specific Language (DSL) for network security may be received. A cloud native enforcement artifact may be generated from the code written using DSL in the file. A policy domain model including hierarchical data, relational data, and graph data for a network security policy may be generated from the code written using DSL in the file and the cloud native enforcement artifact. The policy domain model may be stored in a persistent storage.