Network Workload Labeling with Segmentation Server Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing segmentation policies in network environments are vulnerable to manipulation by malicious actors who can exploit label assignment schemes, leading to security risks by altering workload attributes to gain unauthorized access.

Innovation Solution

A system that securely assigns labels to workloads based on pairing profiles and attributes, using a segmentation server to enforce label-based rules, where labels associated with pairing profiles are fixed and secure, while labels based on workload attributes are adaptable, allowing for flexible management of security and adaptability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If labels are automatically assigned to workloads based on workload attributes, then label assignment efficiency is improved, but security is worsened because malicious actors can manipulate attributes to gain unauthorized access

Engineering Contradiction:
Improvelabel assignment efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the label assignment process into two distinct components: (1) automatic label assignment based on workload attributes for efficiency, and (2) administrator approval requirement for security. This segmentation allows the system to benefit from both automated efficiency and human oversight for security-critical decisions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an administrator as an intermediary between the automatic label assignment process and the final label application. The administrator reviews and approves label assignments, acting as a mediator who can prevent malicious assignments while allowing legitimate automated assignments to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrator approval is required for label assignment, then security is improved, but label assignment efficiency is worsened due to manual review requirements

Engineering Contradiction:
ImprovesecurityVSAvoidlabel assignment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by requiring administrator approval only for certain label assignments while allowing other assignments to proceed automatically. This selective approach ensures security for critical assignments while maintaining efficiency for routine assignments.

Inventive Principle:
Principle #3Local quality

3Reliability

If fixed labels are assigned based on pairing profiles, then security boundaries are strengthened, but adaptability to changing workload conditions is reduced

Engineering Contradiction:
Improvesecurity boundariesVSAvoidadaptability to workload changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by allowing labels to transition from fixed (when assigned via pairing profile) to adaptable (when administrator-approved changes are made). This enables the system to adjust security boundaries dynamically based on changing workload conditions while maintaining strong security foundations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11171991B2Automatically assigning labels to workloads while maintaining security boundaries
Publication Date: 2021.11.09 ILLUMIO INC
  • US11171991B2 patent drawing
  • US11171991B2 patent drawing
  • US11171991B2 patent drawing

AI summary

In a segmented network environment, a segmentation server assigns labels to workloads to enable the segmentation server to implement a segmentation policy based on label-based rules. A first set of labels associated with one or more label dimensions may be assigned in a secure manner by automatically assigning the labels based on a pairing profile. A second set of labels associated with different label dimensions may be assigned automatically based on workload attributes. An administrator can manage which label dimensions are assigned in a secure way based on the pairing profile and which labels are assigned in an adaptable way based on workload attributes, thereby enabling the administrator to flexibly manage the tradeoff between adaptability and security.