Virtual-Edge Docker Policy Enforcement for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional zero-trust security mechanisms fail to provide secure communication with a scalable approach and minimal latency, inefficiently utilizing hardware resources in software-defined perimeter (SDP) systems.

Innovation Solution

A virtual-edge (VE) docker system that performs policy lookups and pushes transformed network access control (NAC) constructs to enforcement points (EPs) in proximity to devices, enabling Just in Time policy (JITP) enforcement, minimizing latency, and improving policy scale by using a policy enforcement cache and netflow analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional zero-trust security mechanisms are implemented with network-based segmentation and SDP controllers, then security policy enforcement is achieved, but policy enforcement latency increases and hardware resource utilization becomes inefficient

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidpolicy enforcement latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-provisions network access control (NAC) constructs at enforcement points before traffic actually needs to be enforced. Flow tuples are captured and stored in advance, and NAC policies are pre-configured at EPs based on these flow tuples, so that when traffic arrives, enforcement can occur immediately without real-time computation delays at the SDP controller.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces flow tuple intermediaries that act as a buffer between the SDP controller and enforcement points. These flow tuples contain pre-processed traffic information that mediates the communication between the controller and EPs, eliminating the need for real-time traffic analysis at the controller and reducing enforcement latency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If conventional SDP systems use centralized SDP controllers for policy management, then security policies can be centrally controlled, but scalability is limited and hardware resources at enforcement points are underutilized

Engineering Contradiction:
Improvecentralized policy controlVSAvoidsystem scalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system segments the centralized policy management function into distributed components at enforcement points. Each EP maintains its own flow tuple cache and NAC construct database, allowing local policy enforcement decisions without constant controller intervention. This segmentation enables parallel processing at multiple EPs simultaneously, improving scalability while maintaining centralized policy definitions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Enforcement points are empowered to autonomously enforce NAC policies using locally cached flow tuples and pre-configured NAC constructs. The EPs self-serve by making local enforcement decisions without requiring real-time controller communication, thus utilizing their hardware resources efficiently and enabling the system to scale to numerous enforcement points.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250106258A1Secure network communication system and method
Publication Date: 2025.03.27 ELISITY INC
  • US20250106258A1 patent drawing
  • US20250106258A1 patent drawing
  • US20250106258A1 patent drawing

AI summary

A method for securing a network is described. The method includes receiving, by a virtual-edge (VE) docker of the network, a flow-tuple including data associated with at least a source device of the network, from an Internet Protocol (IP) flow cache. The method further includes performing, by the VE docker, a policy lookup for the flow-tuple in policy for the source device. The method furthermore includes pushing, by the VE docker, a transformed network access control (NAC) including NAC constructs based on the policy lookup, to an enforcement point (EP) in proximity to the source device.