Structured Policy Expressions for Network Appliances

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As network devices provide increasingly complex functions, configuring and managing their policies becomes complex, leading to performance issues, network errors, and security vulnerabilities due to improper configuration, with a need for structured policy expressions and efficient processing of policies, especially in handling undefined policy scenarios.

Innovation Solution

The development of systems and methods for configuring and evaluating object-oriented policies that allow users to specify structured expressions for network traffic, enabling efficient processing of complex data streams, controlling policy execution order, and defining actions for undefined policy elements, using a configuration interface and a policy engine to apply these policies to network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number and complexity of network device functions grow to provide more capabilities, then the functionality and versatility of the network device improve, but the complexity and amount of configuration required increase

Engineering Contradiction:
ImprovefunctionalityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy configuration into distinct components: policy definitions, policy groups, and policy expressions. This segmentation allows administrators to manage complex network device functions by organizing policies into modular units that can be independently configured and combined, reducing overall configuration complexity while maintaining functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces policy expressions as an intermediary layer between the administrator and the actual policy implementation. These expressions provide a structured language for defining policies, acting as a mediator that simplifies the configuration process while enabling complex network device functions through a standardized interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the number of policies required for configuration increases to support more functions, then the versatility of the network device improves, but the difficulty of managing and specifying processing orders increases

Engineering Contradiction:
Improvepolicy capabilityVSAvoidpolicy management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal policy expression framework that can handle multiple policy types and functions through a single standardized mechanism. This universal approach allows the same policy expression structure to manage diverse network functions, reducing the complexity of managing increasing numbers of policies while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements policy groups that allow administrators to pre-organize policies into logical collections with predefined processing orders. This preliminary organization reduces the management burden when dealing with large numbers of policies, as administrators can work with grouped policies rather than individual ones, simplifying the specification of processing orders.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If policies are made more specific to handle undefined scenarios, then the reliability of policy evaluation improves, but the complexity of writing always-defined policies increases

Engineering Contradiction:
Improvepolicy evaluation reliabilityVSAvoidpolicy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent provides default actions that cushion against undefined policy scenarios. When a policy expression does not explicitly match a traffic flow, the system applies a predefined default action, ensuring reliable policy evaluation without requiring administrators to write complex policies that anticipate every possible scenario. This beforehand cushioning maintains reliability while avoiding increased policy complexity.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS7865589B2Systems and methods for providing structured policy expressions to represent unstructured data in a network appliance
Publication Date: 2011.01.04 CITRIX SYSTEMS INC
  • US7865589B2 patent drawing
  • US7865589B2 patent drawing
  • US7865589B2 patent drawing

AI summary

Systems and methods for configuring and evaluating policies that direct processing of one or more data streams are described. A configuration interface is described for allowing users to specify object oriented policies. These object oriented policies may allow any data structures to be applied with respect to a payload of a received packet stream, including any portions of HTTP traffic. A configuration interface may also allow the user to control the order in which policies and policy groups are executed, in addition to specifying actions to be taken if one or more policies are undefined. Systems and methods for processing the policies may allow efficient processing of object-oriented policies by applying potentially complex data structures to unstructured data streams. A device may also interpret and process a number of flow control commands and policy group invocation statements to determine an order of execution among a number of policies and policy groups. These policy configurations and processing may allow configuration and processing of complex network behaviors relating to load balancing, VPNs, SSL offloading, content switching, application security, acceleration, and caching.