Traffic Midpoint Device for End-to-End Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security policies for managing computer servers in administrative domains are cumbersome due to their reliance on low-level constructs like IP addresses, making it difficult to enforce fine-grained policies and adapt to changing network configurations.

Innovation Solution

A method and system that generate management instructions based on an administrative domain-wide policy, using a traffic midpoint device to enforce rules between a provider managed server and user devices, allowing for abstract and natural policy expression independent of physical devices and network topologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional security policies reference physical devices and low-level constructs like IP addresses, then policy enforcement is tied to specific network configurations, but it becomes difficult to write fine-grained policies in an abstract and natural way and policies do not adapt to changing configurations

Engineering Contradiction:
Improvepolicy adaptabilityVSAvoidpolicy complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a traffic midpoint device as an intermediary between the provider managed server and user devices. This mediator enables abstract policy expression by translating high-level service-based policies into concrete enforcement rules at the network layer, resolving the contradiction between policy adaptability and complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent shifts policy enforcement from the traditional network layer (IP addresses, physical devices) to the application layer (services, functions). This dimensional change allows policies to be expressed in terms of service logic rather than physical constructs, enabling fine-grained control without increasing complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If policies are tied to physical devices and low-level constructs, then enforcement is straightforward at the network layer, but it is difficult to express fine-grained policies in an abstract and natural way

Engineering Contradiction:
Improvepolicy expression easeVSAvoidpolicy granularity
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the network communication into distinct functional components: the provider managed server, the traffic midpoint device, and user devices. By assigning policy enforcement responsibilities to the traffic midpoint device, the system achieves both ease of operation (centralized policy management) and fine granularity (service-specific rules)

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a logical copy of the policy enforcement function at the traffic midpoint device, which mirrors the service logic from the provider managed server. This copying mechanism enables abstract policy expression to be translated into concrete enforcement actions without requiring direct modification of the original service code

Inventive Principle:
Principle #26Copying

3Reliability

If conventional policies reference IP addresses and network interfaces, then they can be enforced at the network layer, but they do not adapt to changing configurations of routers, switches, and load balancers

Engineering Contradiction:
Improvepolicy enforcement reliabilityVSAvoidnetwork configuration adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policy enforcement by placing the policy engine at the traffic midpoint device, which can adapt to changing network configurations in real-time. The system dynamically updates enforcement rules based on current service topology, ensuring reliable policy application regardless of infrastructure changes

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The traffic midpoint device serves multiple functions: it acts as a policy enforcement point, a service broker, and a configuration adapter. This multi-functionality enables the system to maintain reliable policy enforcement across diverse and changing network configurations without requiring separate mechanisms for each scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10819590B2End-to-end policy enforcement in the presence of a traffic midpoint device
Publication Date: 2020.10.27 ILLUMIO INC
  • US10819590B2 patent drawing
  • US10819590B2 patent drawing
  • US10819590B2 patent drawing

AI summary

A global manager computer generates management instructions for a particular managed server within an administrative domain according to a set of rules. A global manager computer identifies a traffic midpoint device through which the provider managed server provides a service to a user device. The global manager determines a relevant rule from the set of rules that is applicable to communication between the provider managed server and the user device and generates a backend rule that is applicable to communication between the provider managed server and the traffic midpoint device. The global managed generates a backend function-level instruction including a reference to an actor-set authorized to communicate with the provider managed server to use the service. The global manager sends the backend function-level instruction to the provider managed server to configure the provider managed server to enforce the backend rule on communication with the actor-set including the traffic midpoint device.