Zero Trust Packet Routing for Misconfiguration-Resistant Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security techniques in cloud computing environments are prone to misconfigurations, leading to exposure of sensitive data, and maintaining security policies across multiple layers and components is complex and resource-intensive.

Innovation Solution

The implementation of a Zero Trust Packet Routing (ZPR) policy language (ZPL) that enables data-centric, intent-based policies to be enforced at various enforcement points within networks, ensuring secure data flow by defining who can access data and how, with guardrails that prevent violations due to misconfigurations or changes in network equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security rules and policies are created to protect data, then data protection coverage is improved, but system complexity and maintenance burden increase significantly

Engineering Contradiction:
Improvedata protectionVSAvoidpolicy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network security policies into hierarchical layers (tenancy-level, compartment-level, namespace-level) with the ZPL policy language providing a unified high-level abstraction. This segmentation allows complex security requirements to be broken down into manageable, enforceable rules at different levels, reducing overall policy complexity while maintaining comprehensive protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces Zero Trust Packet Routing (ZPR) enforcement points as intermediaries between network traffic and protected resources. These enforcement points automatically evaluate and enforce ZPL policies, acting as a mediator that translates high-level security intent into low-level packet routing decisions, thereby reducing the burden on administrators to manually configure complex network security rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network security rules are created to prevent misconfigurations, then security reliability is improved, but time and resources for creating and updating rules increase

Engineering Contradiction:
Improvesecurity configurationVSAvoidpolicy maintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by providing guardrails that are pre-configured into the ZPL policy language. These guardrails automatically prevent common misconfigurations before they can occur, eliminating the need for administrators to continuously update and maintain complex security rules. The guardrails encode security best practices directly into the policy enforcement mechanism.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The ZPR system performs self-service by automatically evaluating network traffic against ZPL policies at enforcement points without requiring manual intervention. The system self-updates and adapts to network changes while maintaining security posture, reducing the time and resources needed for manual policy creation and updates.

Inventive Principle:
Principle #25Self-service

3Reliability

If data access policies are enforced at multiple network layers, then security coverage is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy enforcement ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal ZPL policy language that can be enforced across multiple network layers and enforcement points with a single policy definition. This universal approach allows the same high-level security intent to be applied consistently throughout the network stack, eliminating the need to create and maintain separate policies for each layer while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If existing IAM and NSG policies are integrated with ZPL, then system compatibility is improved, but policy evaluation complexity increases

Engineering Contradiction:
Improvepolicy integrationVSAvoidpolicy evaluation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges existing IAM (Identity and Access Management) and NSG (Network Security Group) policies with ZPL into a unified policy evaluation framework. This integration allows ZPL to leverage existing identity and network security concepts while adding zero trust packet routing capabilities, creating a comprehensive security model that combines multiple policy types without requiring separate evaluation systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250211578A1Zero trust packet routing policy language
Publication Date: 2025.06.26 ORACLE INT CORP
  • US20250211578A1 patent drawing
  • US20250211578A1 patent drawing
  • US20250211578A1 patent drawing

AI summary

Techniques are described for creating and enforcing network policies using a zero trust packet routing (ZPR) policy language (ZPL). Generally, ZPL allows users to create data-centric, intent-based policies that are evaluated and enforced at different enforcement points within one or more networks to control data flow. According to some configurations, ZPL is used to define ZPR policy statements that specifies who/what (e.g., users, computing resources) can access data and how traffic flows throughout one or more networks. Generally, when packets are transmitted/received, the enforcement points evaluate the ingress or egress rules associated with the policy. In this way, packets are not transmitted from an enforcement point to a next hop until the rules are evaluated by the enforcement point and the enforcement point determines that the transmission is authorized by the policy.