Stateful Network Security Across Multiple Policy Enforcement Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security architectures face challenges in ensuring compliance with access control policies across multiple networks, particularly in cloud-based environments, where stateless architectures are less burdensome but non-compliant, and stateful architectures are costly and burdensome for scalability and reliability.

Innovation Solution

Implementing a stateful network security architecture with a policy decision point (PDP) that maintains aggregated state information for multiple policy enforcement points (PEPs), allowing communication sessions to utilize multiple connection paths and reducing the burden of adding new PEPs by maintaining identical forward and reverse flowspecs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stateful architecture is used to implement access control policies, then security compliance is improved, but scalability and reliability deteriorate due to cost and burden

Engineering Contradiction:
Improveaccess control policy complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments stateful security functionality into distributed Policy Enforcement Points (PEPs) that operate autonomously across multiple networks. Each PEP maintains local state information and makes independent policy decisions, eliminating the need for a centralized stateful architecture while maintaining security compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where PEPs exchange synchronization messages and state information through standardized protocols. This intermediary layer enables coordinated policy enforcement across distributed networks without requiring direct complex interactions between all components, reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If stateless architecture is used, then scalability and ease of operation are improved, but access control policy compliance deteriorates

Engineering Contradiction:
ImprovescalabilityVSAvoidaccess control policy compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Each Policy Enforcement Point (PEP) is designed to be self-sufficient, maintaining its own state information and making autonomous policy decisions. PEPs independently synchronize with other PEPs through standardized messages, eliminating the need for centralized state management while ensuring access control compliance through self-verification mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where PEPs exchange state synchronization messages and policy decision information. Each PEP receives feedback from other PEPs about network state changes and adjusts its local policy enforcement accordingly, ensuring continuous compliance without requiring centralized control.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple connection paths are allowed for communication sessions, then versatility and productivity are improved, but determining permissible paths increases complexity

Engineering Contradiction:
Improveconnection path flexibilityVSAvoidpath determination complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The path determination process is segmented and distributed across multiple PEPs, each responsible for evaluating connection paths within their own network. Instead of one centralized entity analyzing all possible paths, each PEP independently assesses paths through its network and contributes to the overall route selection, reducing the complexity burden on any single component.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12634344B2Methods and systems for stateful network security
Publication Date: 2026.05.19 COMCAST CABLE COMM LLC
  • US12634344B2 patent drawing
  • US12634344B2 patent drawing
  • US12634344B2 patent drawing

AI summary

A destination host on a first network may attempt to initiate a communication session with a source host on a second network. The attempt may be intercepted by a first policy enforcement point, which may forward a message to the source host associated with the communication session. The source host may send an acknowledgment to the destination host via the first policy enforcement point. A policy decision point may determine that the communication session is permissible. The policy decision point may send a response to the first policy enforcement point and a second policy enforcement point. The response may indicate an approval of the communication session. The source host may respond to the destination host through either a first connection path and the first policy enforcement point or a second connection and the second policy enforcement point.