Virtual-Edge Docker Policy Enforcement for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional zero-trust security mechanisms fail to provide secure communication with a scalable approach and minimal latency, inefficiently utilizing hardware resources in software-defined perimeter (SDP) systems.
Innovation Solution
A virtual-edge (VE) docker system that performs policy lookups and pushes transformed network access control (NAC) constructs to enforcement points (EPs) in proximity to devices, enabling Just in Time policy (JITP) enforcement, minimizing latency, and improving policy scale by using a policy enforcement cache and netflow analytics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional zero-trust security mechanisms are implemented with network-based segmentation and SDP controllers, then security policy enforcement is achieved, but policy enforcement latency increases and hardware resource utilization becomes inefficient
Solution Approach 1:
The system pre-provisions network access control (NAC) constructs at enforcement points before traffic actually needs to be enforced. Flow tuples are captured and stored in advance, and NAC policies are pre-configured at EPs based on these flow tuples, so that when traffic arrives, enforcement can occur immediately without real-time computation delays at the SDP controller.
Solution Approach 2:
The patent introduces flow tuple intermediaries that act as a buffer between the SDP controller and enforcement points. These flow tuples contain pre-processed traffic information that mediates the communication between the controller and EPs, eliminating the need for real-time traffic analysis at the controller and reducing enforcement latency.
2Adaptability or versatility
If conventional SDP systems use centralized SDP controllers for policy management, then security policies can be centrally controlled, but scalability is limited and hardware resources at enforcement points are underutilized
Solution Approach 1:
The system segments the centralized policy management function into distributed components at enforcement points. Each EP maintains its own flow tuple cache and NAC construct database, allowing local policy enforcement decisions without constant controller intervention. This segmentation enables parallel processing at multiple EPs simultaneously, improving scalability while maintaining centralized policy definitions.
Solution Approach 2:
Enforcement points are empowered to autonomously enforce NAC policies using locally cached flow tuples and pre-configured NAC constructs. The EPs self-serve by making local enforcement decisions without requiring real-time controller communication, thus utilizing their hardware resources efficiently and enabling the system to scale to numerous enforcement points.
Data Source
AI summary
A method for securing a network is described. The method includes receiving, by a virtual-edge (VE) docker of the network, a flow-tuple including data associated with at least a source device of the network, from an Internet Protocol (IP) flow cache. The method further includes performing, by the VE docker, a policy lookup for the flow-tuple in policy for the source device. The method furthermore includes pushing, by the VE docker, a transformed network access control (NAC) including NAC constructs based on the policy lookup, to an enforcement point (EP) in proximity to the source device.


