Unified Policy Manager for Network Security Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security policies in large networks are challenging to manage due to the need for individual management of multiple security services through different APIs, leading to tedious configuration and cumbersome policy collection and analysis.

Innovation Solution

A policy manager system that integrates data from various security services into a holistic API, allowing network administrators to view, modify, and assess the network's security framework through visual representations and summaries, and automatically updates and enforces security policies across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple security services are managed individually through separate APIs, then each security service can be configured independently, but the overall management complexity increases and configuration becomes tedious

Engineering Contradiction:
ImproveIndependent security service configurationVSAvoidManagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple individual security service APIs into a single unified management interface. The system aggregates security policies from different services (firewall, intrusion detection, antivirus, etc.) and presents them through one consolidated API, allowing administrators to manage all security services from a single point rather than switching between multiple separate interfaces.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified management interface is designed to be universal, supporting multiple types of security services through a single system. The interface can handle diverse security functions (network security, application security, device security) using common management protocols and data structures, making the system adaptable to various security service types without requiring service-specific management approaches.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If security policies are collected and analyzed from individual security services, then detailed policy information can be obtained, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
ImprovePolicy information completenessVSAvoidPolicy collection time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively collecting and normalizing security policy data from multiple services in advance, before administrative review is needed. The unified interface continuously aggregates policy information from all connected security services, maintaining an up-to-date consolidated view that is ready for immediate analysis and decision-making, eliminating the need for time-consuming manual data gathering.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The unified management interface acts as an intermediary between individual security services and administrators. It receives detailed policy information from various security services, normalizes the data into a common format, and presents it in a consolidated manner. This intermediary layer translates diverse service-specific data structures into a universal format that can be easily analyzed and compared across different security services.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a unified management interface is implemented for multiple security services, then management complexity is reduced, but integration of different security services becomes more challenging

Engineering Contradiction:
ImproveSecurity policy management easeVSAvoidIntegration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system applies segmentation by maintaining separate connection interfaces for each security service while presenting a unified management view. Each security service retains its own API and data structure, but the unified interface segments the integration task into manageable connections with individual services. This allows the system to integrate multiple services incrementally, connecting to each service independently while providing consolidated management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The unified management interface uses parameter changes to adapt to different security service types. It employs configurable parameters and metadata that describe each service's specific characteristics, allowing the same interface to work with diverse services by adjusting its behavior based on service-specific parameters. This enables the system to handle different security services with a single interface without requiring hard-coded integration logic for each service type.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250193243A1Zero trust policy manager
Publication Date: 2025.06.12 CISCO TECHNOLOGY INC
  • US20250193243A1 patent drawing
  • US20250193243A1 patent drawing
  • US20250193243A1 patent drawing

AI summary

In some aspects, a method for managing security policies on a network may include a policy manager receiving, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services. The policy manager may also compare the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status. Finally, the policy manager may present a visual representation of the security data that includes at least an indication of the one or more discrepancies.