Template-Based Service Rules for Cloud Firewall Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing enterprise firewall policy model is inadequate for supporting private cloud and automation scenarios, leading to scalability and performance issues due to rule and dynamic group overload, as well as management complexity, especially when handling hundreds of application instances created from the same template.

Innovation Solution

Introducing cloud template awareness in the service policy framework with service rule processing engines that support template-specific dynamic groups and rules, allowing for dynamic security tags and seamless association of data compute nodes with dynamic component groups, enabling efficient processing and management of firewall rules across multiple instances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional firewall policy model is used for each template instance, then instance-specific security control is achieved, but rule quantity and dynamic group overload occurs leading to scalability issues

Engineering Contradiction:
Improveinstance-specific security controlVSAvoidrule quantity and dynamic group overload
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces template-level firewall rules that apply universally across all instances of a template. Instead of creating separate rules for each instance, a single template rule can control security policies for hundreds of instances simultaneously. The system maintains instance-specific control through instance-level overrides when needed, but defaults to universal template-level rules for scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges instance-specific security requirements with template-level generalization. By combining template-level rule definitions with instance-level override capabilities, the system achieves both scalability through universal rules and adaptability through selective instance-specific modifications when necessary.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If individual firewall rules are created for each template instance, then precise security control is achieved, but rule management complexity increases significantly

Engineering Contradiction:
Improvesecurity control precisionVSAvoidrule management complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Template-level firewall rules provide a universal mechanism for managing security policies across multiple instances. Administrators can define, modify, and delete rules at the template level, and these changes automatically propagate to all instances. This maintains security control precision while dramatically reducing management complexity from thousands of individual rules to a manageable number of template rules.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service rule propagation where template rule changes automatically apply to all instances without manual intervention. The firewall system itself handles the distribution and application of rules, reducing the administrative burden on operators while maintaining precise security control.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If firewall rules are updated for each template instance individually, then instance-specific policy updates are achieved, but rule churn overwhelms policy change systems

Engineering Contradiction:
Improveinstance-specific policy updatesVSAvoidpolicy change system performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

Template-level rule updates provide a universal mechanism for propagating policy changes to all instances simultaneously. When a rule is modified at the template level, the system efficiently distributes the update across all instances in a single operation rather than individually updating each instance, thereby reducing policy churn and protecting policy change systems from being overwhelmed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adapts rule propagation based on instance-specific needs. While template rules provide universal updates, the system allows instances to dynamically override rules when instance-specific policies are required. This dynamic approach reduces unnecessary policy churn by applying universal updates only where applicable while maintaining instance-specific flexibility when needed.

Inventive Principle:
Principle #15Dynamics

4Reliability

If comprehensive firewall rules are deployed for all instances, then security coverage is improved, but firewall performance degrades due to rule processing overhead

Engineering Contradiction:
Improvesecurity coverageVSAvoidfirewall processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Template-level firewall rules provide a universal mechanism for achieving comprehensive security coverage across all instances without the processing overhead of individual instance rules. The firewall processing engine optimizes template rule evaluation, applying security policies efficiently at the template level while maintaining comprehensive coverage for all instances. This approach preserves security coverage while significantly improving processing speed by reducing the total number of rules that must be evaluated.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10469450B2Creating and distributing template based service rules
Publication Date: 2019.11.05 VMWARE INC
  • US10469450B2 patent drawing
  • US10469450B2 patent drawing
  • US10469450B2 patent drawing

AI summary

Some embodiments of the invention introduce cloud template awareness in the service policy framework. Some embodiments provide one or more service rule processing engines that natively support (1) template-specific dynamic groups and template-specific rules, and (2) dynamic security tag concepts. A service rule processing engine of some embodiments natively supports template-specific dynamic groups and rules as it can directly process service rules that are defined in terms of dynamic component groups, template identifiers, template instance identifiers, and/or template match criteria. Examples of such services can include any kind of middlebox services, such as firewalls, load balancers, network address translators, intrusion detection systems, intrusion prevention systems, etc.