Stateful Network Security Across Multiple Policy Enforcement Points
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security architectures face challenges in ensuring compliance with access control policies across multiple networks, particularly in cloud-based environments, where stateless architectures are less burdensome but non-compliant, and stateful architectures are costly and burdensome for scalability and reliability.
Innovation Solution
Implementing a stateful network security architecture with a policy decision point (PDP) that maintains aggregated state information for multiple policy enforcement points (PEPs), allowing communication sessions to utilize multiple connection paths and reducing the burden of adding new PEPs by maintaining identical forward and reverse flowspecs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If stateful architecture is used to implement access control policies, then security compliance is improved, but scalability and reliability deteriorate due to cost and burden
Solution Approach 1:
The system segments stateful security functionality into distributed Policy Enforcement Points (PEPs) that operate autonomously across multiple networks. Each PEP maintains local state information and makes independent policy decisions, eliminating the need for a centralized stateful architecture while maintaining security compliance.
Solution Approach 2:
The patent introduces an intermediary mechanism where PEPs exchange synchronization messages and state information through standardized protocols. This intermediary layer enables coordinated policy enforcement across distributed networks without requiring direct complex interactions between all components, reducing overall system complexity.
2Ease of operation
If stateless architecture is used, then scalability and ease of operation are improved, but access control policy compliance deteriorates
Solution Approach 1:
Each Policy Enforcement Point (PEP) is designed to be self-sufficient, maintaining its own state information and making autonomous policy decisions. PEPs independently synchronize with other PEPs through standardized messages, eliminating the need for centralized state management while ensuring access control compliance through self-verification mechanisms.
Solution Approach 2:
The system implements feedback mechanisms where PEPs exchange state synchronization messages and policy decision information. Each PEP receives feedback from other PEPs about network state changes and adjusts its local policy enforcement accordingly, ensuring continuous compliance without requiring centralized control.
3Adaptability or versatility
If multiple connection paths are allowed for communication sessions, then versatility and productivity are improved, but determining permissible paths increases complexity
Solution Approach 1:
The path determination process is segmented and distributed across multiple PEPs, each responsible for evaluating connection paths within their own network. Instead of one centralized entity analyzing all possible paths, each PEP independently assesses paths through its network and contributes to the overall route selection, reducing the complexity burden on any single component.
Data Source
AI summary
A destination host on a first network may attempt to initiate a communication session with a source host on a second network. The attempt may be intercepted by a first policy enforcement point, which may forward a message to the source host associated with the communication session. The source host may send an acknowledgment to the destination host via the first policy enforcement point. A policy decision point may determine that the communication session is permissible. The policy decision point may send a response to the first policy enforcement point and a second policy enforcement point. The response may indicate an approval of the communication session. The source host may respond to the destination host through either a first connection path and the first policy enforcement point or a second connection and the second policy enforcement point.


