Unified Policy Broker for Network Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of managing and configuring multiple policy enforcement engines in a network environment is exacerbated by their diverse APIs and terminologies, making it difficult for users to manually enforce network policies across different devices without conflicts.
Innovation Solution
A unified policy broker system that provides a single user experience and API to manage various policy enforcement engines by normalizing terminologies, workflows, and capabilities, allowing seamless migration and configuration across different engines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple different policy enforcement engines are deployed along the network path to enforce networking policies, then the network can provide flexible policy enforcement capabilities and performance characteristics, but the complexity of managing and configuring these engines increases significantly due to diverse APIs and terminologies
Solution Approach 1:
The patent introduces a policy broker as an intermediary component that sits between the network administrator and multiple policy enforcement engines. The broker translates diverse engine-specific APIs and terminologies into a unified policy language, mediating the interaction between administrators and heterogeneous enforcement engines. This resolves the contradiction by maintaining adaptability to multiple engines while reducing management complexity through the broker's translation layer.
Solution Approach 2:
The policy broker implements a universal interface that can interact with multiple different types of policy enforcement engines through a single unified API. This multi-functional approach allows the same broker to manage diverse engines (firewalls, routers, switches) with different native APIs, providing universality in management while preserving the specialized capabilities of each engine type.
2Reliability
If each policy enforcement engine has its own specific API and terminology, then each engine can be optimized for its specific function, but users must learn multiple different terminologies and configurations to manage policies across different devices
Solution Approach 1:
The policy broker acts as a mediator that translates between the unified policy language used by administrators and the engine-specific languages required by individual enforcement engines. This allows administrators to work with a single easy-to-learn terminology while the broker handles the translation to optimized engine-specific configurations, resolving the contradiction between operational ease and engine optimization.
Solution Approach 2:
The system changes the parameter of policy representation from multiple engine-specific formats to a single unified format at the broker level. The broker then transforms this unified representation into engine-specific parameters as needed, allowing administrators to work with consistent parameters while engines receive their optimized native formats.
3Manufacturing precision
If manual configuration of policy enforcement engines is performed, then precise control over each engine can be achieved, but the process becomes difficult and complex due to the need to understand and configure multiple different APIs
Solution Approach 1:
The policy broker serves as an intermediary that receives high-level policy intentions from administrators and automatically translates them into precise engine-specific configurations. This maintains precise control over each engine while eliminating the complexity of manual multi-API configuration, as the broker automates the translation process.
Solution Approach 2:
The policy broker performs preliminary translation and validation of policies before they are deployed to individual engines. By pre-processing policies in a unified format and generating engine-specific configurations in advance, the system achieves precise engine control while reducing the complexity of direct manual configuration.
Data Source
AI summary
One aspect described in this application provides a unified policy broker. During operation, the system receives configuration information from the set of network devices. At least two network devices in the network can be equipped with a first and a second policy enforcement engine, respectively, for enforcing one or more given policy rules. The system can determine, based on the configuration information, a first and a second representation of the similar policy function corresponding to the first and the second policy enforcement engine, respectively. The system can apply a unified policy model to perform a first mapping from a unified representation of the similar policy function to the first and the second representation. The system can create a unified API based on the unified representation. The system applies, via a user interface, the unified API to configure the similar policy function across the first and the second policy enforcement engines.


