Traffic Midpoint Device for End-to-End Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security policies for managing computer servers in administrative domains are cumbersome due to their reliance on low-level constructs like IP addresses, making it difficult to enforce fine-grained policies and adapt to changing network configurations.
Innovation Solution
A method and system that generate management instructions based on an administrative domain-wide policy, using a traffic midpoint device to enforce rules between a provider managed server and user devices, allowing for abstract and natural policy expression independent of physical devices and network topologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional security policies reference physical devices and low-level constructs like IP addresses, then policy enforcement is tied to specific network configurations, but it becomes difficult to write fine-grained policies in an abstract and natural way and policies do not adapt to changing configurations
Solution Approach 1:
The patent introduces a traffic midpoint device as an intermediary between the provider managed server and user devices. This mediator enables abstract policy expression by translating high-level service-based policies into concrete enforcement rules at the network layer, resolving the contradiction between policy adaptability and complexity
Solution Approach 2:
The patent shifts policy enforcement from the traditional network layer (IP addresses, physical devices) to the application layer (services, functions). This dimensional change allows policies to be expressed in terms of service logic rather than physical constructs, enabling fine-grained control without increasing complexity
2Ease of operation
If policies are tied to physical devices and low-level constructs, then enforcement is straightforward at the network layer, but it is difficult to express fine-grained policies in an abstract and natural way
Solution Approach 1:
The patent segments the network communication into distinct functional components: the provider managed server, the traffic midpoint device, and user devices. By assigning policy enforcement responsibilities to the traffic midpoint device, the system achieves both ease of operation (centralized policy management) and fine granularity (service-specific rules)
Solution Approach 2:
The patent creates a logical copy of the policy enforcement function at the traffic midpoint device, which mirrors the service logic from the provider managed server. This copying mechanism enables abstract policy expression to be translated into concrete enforcement actions without requiring direct modification of the original service code
3Reliability
If conventional policies reference IP addresses and network interfaces, then they can be enforced at the network layer, but they do not adapt to changing configurations of routers, switches, and load balancers
Solution Approach 1:
The patent implements dynamic policy enforcement by placing the policy engine at the traffic midpoint device, which can adapt to changing network configurations in real-time. The system dynamically updates enforcement rules based on current service topology, ensuring reliable policy application regardless of infrastructure changes
Solution Approach 2:
The traffic midpoint device serves multiple functions: it acts as a policy enforcement point, a service broker, and a configuration adapter. This multi-functionality enables the system to maintain reliable policy enforcement across diverse and changing network configurations without requiring separate mechanisms for each scenario
Data Source
AI summary
A global manager computer generates management instructions for a particular managed server within an administrative domain according to a set of rules. A global manager computer identifies a traffic midpoint device through which the provider managed server provides a service to a user device. The global manager determines a relevant rule from the set of rules that is applicable to communication between the provider managed server and the user device and generates a backend rule that is applicable to communication between the provider managed server and the traffic midpoint device. The global managed generates a backend function-level instruction including a reference to an actor-set authorized to communicate with the provider managed server to use the service. The global manager sends the backend function-level instruction to the provider managed server to configure the provider managed server to enforce the backend rule on communication with the actor-set including the traffic midpoint device.


