Network Safety Component for vWAN Policy Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtualized wide area networks (vWANs) lack effective mechanisms to ensure compliance with laws, regulations, and policies, as network operators may unintentionally violate them due to limited control over underlying network configurations.
Innovation Solution
An apparatus and method for managing policies in vWANs, which includes a processor configured to evaluate a set of safety rules based on changes to policies and configurations, ensuring compliance with higher-level laws and regulations by generating error messages or blocking non-compliant changes, and utilizing a network safety component to enforce safety rules across virtual network entities and connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a vWAN operator provides configuration flexibility to network operators, then adaptability and ease of operation are improved, but the risk of violating laws, regulations, or policies increases
Solution Approach 1:
The patent introduces an intermediary safety verification system that sits between the network operator's configuration changes and the actual vWAN implementation. This intermediary automatically evaluates proposed configurations against stored laws, regulations, and policies before allowing changes to take effect, thus maintaining configuration flexibility while ensuring compliance through an automated mediation layer.
Solution Approach 2:
The system performs preliminary safety verification by evaluating configuration changes against compliance rules before the changes are applied to the live network. This preliminary action prevents non-compliant configurations from being deployed, allowing operators to make flexible configuration changes with the assurance that compliance checks will be performed in advance.
2Reliability
If automated safety verification is implemented in vWAN, then reliability and compliance are improved, but device complexity increases
Solution Approach 1:
The safety verification system operates autonomously by automatically retrieving configuration changes, evaluating them against stored compliance rules, and determining whether to allow or block changes without human intervention. This self-service automation reduces the need for manual compliance checking and minimizes the operational complexity despite the enhanced verification capabilities.
Solution Approach 2:
The verification system is designed to handle multiple types of compliance rules (laws, regulations, policies) and various configuration parameters through a unified evaluation framework. This universal approach consolidates what could be multiple separate verification systems into a single multi-functional component, reducing overall system complexity.
3Ease of operation
If manual compliance checking is performed, then ease of operation is maintained, but productivity and response time are reduced
Solution Approach 1:
The system provides immediate automated feedback to network operators about whether their proposed configuration changes comply with applicable rules. This instant feedback mechanism eliminates the delay associated with manual compliance checking while maintaining operator control, as operators receive clear guidance on whether to proceed with or modify their proposed changes.
Solution Approach 2:
The patent replaces manual compliance checking (mechanical human operation) with automated computational evaluation. The system uses computer-based algorithms to retrieve configuration changes, evaluate them against stored compliance rules, and determine compliance status, substituting human manual processes with automated mechanical-computational processes that are both faster and equally controllable.
Data Source
AI summary
Described are examples for providing a system for managing configuration and policies for a virtualized wide area network (vWAN) support on a wide area network (WAN). The vWAN includes a plurality of virtual network entities associated with geographic locations including the physical computing resources of the WAN and virtual connections between the virtual network entities. The system includes a network safety component for managing configurations and policies of the vWAN on the WAN. The network safety component receives a change to a policy or configuration of the vWAN from an operator of a network connected to the vWAN. The network safety component evaluates a set of safety rules for the operator based on the change and a network state of a physical WAN underlying the vWAN. The network safety component generates an error message in response to at least one of the set of safety rules failing the evaluation.


