SPB Security Group Policy Using SGIDs for Scalable Traffic Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security policies in communication networks, such as those based on VLANs and VRFs, become complex and cumbersome as network elements increase, necessitating a more efficient and scalable approach for traffic forwarding decisions.
Innovation Solution
Implementing a security group policy that assigns source and target security group identifiers (IDs) to frames based on ingress and egress ports, MAC addresses, or VLANs, and applies forwarding decisions using a communication matrix to determine allowed traffic flows, enabling flexible security infrastructure beyond per-service segmentation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VLANs and VRFs are used for network security grouping, then network security can be implemented, but the filter policies become very complex when network elements increase
Solution Approach 1:
The patent segments network security policy into two independent layers: (1) security group membership assignment based on network elements (devices, ports, VLANs), and (2) security group policy rules defining allowed traffic flows. This segmentation allows the policy structure to remain simple while handling large numbers of network elements, as the system automatically manages the complexity of mapping elements to groups and groups to policies.
Solution Approach 2:
The patent introduces security group identifiers (SGIDs) as intermediary objects between network elements and security policies. Instead of directly configuring complex filter policies for each network element combination, administrators assign elements to security groups and define policies between groups. The system automatically handles the intermediary mapping and policy application, significantly reducing configuration complexity.
2Reliability
If traditional VLAN-based security grouping is used, then network segmentation is achieved, but scalability becomes limited as network elements increase
Solution Approach 1:
The patent creates a universal security group policy framework that works across multiple network infrastructures including VLANs, VRFs, and SPBM networks. Security groups can encompass network elements from different infrastructure types, and a single policy set applies universally across the entire network regardless of the underlying infrastructure. This multi-functionality enables seamless scalability as the network grows and evolves.
Solution Approach 2:
The patent adds a new dimension to network security by overlaying security group identifiers as an additional tagging layer on top of existing network infrastructure identifiers (VLAN IDs, VRFs). This dimensional addition allows security grouping to operate independently of the underlying infrastructure, enabling scalable security policies that can accommodate any number of network elements without being constrained by traditional VLAN limitations.
3Ease of operation
If security policies are applied at individual network element level, then precise control is achieved, but the number of policies increases exponentially with network size
Solution Approach 1:
The patent merges multiple individual network element security configurations into unified security group policies. Instead of managing separate policies for each device-to-device communication, the system combines elements into security groups and applies single policies between groups. This merging reduces the number of policies from exponential (n×m individual element pairs) to linear (g×h group pairs, where g and h are the number of source and destination groups).
Data Source
AI summary
Disclosed herein are system, method, and computer program product aspects for implementing a security group policy. Some aspects of this disclosure relate to a method for applying a security group policy. The method includes receiving a first frame from a source device and assigning a source security group identifier (ID) to the first frame. The method further includes generating a second frame based on the first frame and the source security group ID and identifying a target security group ID for the second frame. The method also includes applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID.


