Tagged Policy Framework for Virtual Network Traffic Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized data centers, managing network traffic policies across different computing environments is complex and cumbersome, as each environment independently manages its own policies, making it difficult to ensure security, reliability, and quality requirements are met, and upgrading policies across multiple data centers is unmanageable.
Innovation Solution
A scalable, multi-dimensional policy framework is implemented that allows administrators to tag objects across multiple dimensions, enabling distributed policy agents to apply policies based on tags, allowing or denying traffic flow between objects, simplifying policy management and deployment across various environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If each computing environment independently manages its own network traffic policies, then local control and flexibility are maintained, but policy management complexity increases and consistency across multiple data centers deteriorates
Solution Approach 1:
The patent segments policy management into two distinct components: a centralized policy controller that handles policy creation, validation, and distribution, and distributed policy agents that execute policies locally at computing environments. This segmentation allows local flexibility through policy agents while centralizing management complexity through the policy controller, resolving the contradiction between local adaptability and overall management complexity.
Solution Approach 2:
The policy controller acts as an intermediary between administrators and distributed policy agents. It receives policy definitions, validates them against security and compliance requirements, translates them into executable policy rules, and distributes them to appropriate policy agents. This intermediary role simplifies policy management by providing a single point of control while maintaining local execution flexibility through the agent architecture.
2Adaptability or versatility
If policies are managed independently in each data center, then local customization is possible, but upgrading and maintaining consistency across multiple data centers becomes unmanageable
Solution Approach 1:
The policy controller provides universal policy management functionality that serves multiple data centers simultaneously. It maintains a centralized policy repository that stores master policy definitions, validates policies against organization-wide security and compliance requirements, and distributes consistent policy rules to all policy agents across different data centers. This universal approach ensures policy consistency while allowing local customization through the hierarchical policy inheritance model.
Solution Approach 2:
The system implements feedback mechanisms where policy agents report their status, applied policies, and compliance information back to the policy controller. The controller uses this feedback to verify policy deployment consistency, detect deviations, and trigger automated policy updates across all data centers. This feedback loop ensures reliable policy consistency while maintaining the ability for local customization within the established framework.
3Reliability
If a centralized policy management system is implemented, then policy consistency is improved, but system complexity and deployment overhead increase
Solution Approach 1:
The centralized policy management system is segmented into a policy controller for centralized functions and policy agents for distributed execution. This segmentation reduces system architecture complexity by clearly defining boundaries between centralized and distributed components, while maintaining policy consistency through the controller's coordination role.
Solution Approach 2:
Policy agents are designed to autonomously receive, validate, and execute policy rules without requiring manual configuration at each location. They self-configure by listening for policy definitions from the policy controller and automatically applying them to local network traffic. This self-service capability reduces deployment overhead and simplifies the centralized system's operational complexity.
4Reliability
If detailed policy rules are enforced at each computing environment, then security and compliance requirements are met, but processing overhead and performance degradation occur
Solution Approach 1:
The policy controller performs preliminary actions by pre-validating, optimizing, and compiling policy definitions into efficient executable rules before distribution. It performs static analysis of policy requirements, resolves conflicts, and generates optimized policy configurations that reduce runtime processing overhead. This preliminary preparation ensures security and compliance enforcement while minimizing performance degradation during actual traffic filtering.
Solution Approach 2:
The system creates optimized copies of policy rules that are distributed from the policy controller to policy agents. These copied rules are pre-processed and formatted for efficient execution at the network level, allowing detailed security enforcement without the full processing overhead of centralized evaluation for every network packet. The copying mechanism enables localized enforcement with reduced computational burden.
Data Source
AI summary
Techniques are disclosed for implementing scalable policies across a plurality of categories that support application workloads. In one example, a policy controller assigns to the plurality of categories tags specifying one or more of a plurality of dimensions. The policy controller distributes a plurality of policies to policy agents for the plurality of categories. Each policy includes one or more policy rules, and each policy rule includes one or more tags specifying one or more of the plurality of dimensions. For each policy rule, the policy agents allow or deny a traffic flow between objects that belong to categories of the plurality of categories described by the one or more dimensions of a respective tag of the policy rule.


