Zero Trust Packet Routing Visualization for Multi-Layer Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Protecting data in cloud computing environments is challenging due to complex network configurations and the difficulty in maintaining up-to-date security policies, which can lead to misconfigurations exposing sensitive data, and existing network security techniques fail to enforce policies across different network layers effectively.

Innovation Solution

A Zero Trust Packet Routing (ZPR) architecture that includes a zero trust access (ZTA) service with an aggregation and visualization service, allowing users to create intent-based policies using ZPR Policy Language (ZPL) and enforce them at different enforcement points within the network, providing real-time visualization of policy impacts and enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security rules and policies are created and deployed at each network layer, then data protection coverage is improved, but system complexity and maintenance burden increase significantly

Engineering Contradiction:
Improvedata protection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network security enforcement into multiple distributed enforcement points (EPs) deployed at different network layers (L3, L4, L7). Each EP independently evaluates and enforces security policies for specific traffic types, replacing the traditional monolithic security architecture. This segmentation allows comprehensive multi-layer protection while distributing complexity across manageable components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security policy framework where a single set of security policies can be enforced across multiple network layers and different traffic types. The policy language and evaluation mechanism are designed to be layer-agnostic, allowing the same security rules to apply consistently from network layer to application layer, reducing the need for separate policy configurations at each layer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security policies are enforced at multiple network layers, then security effectiveness is improved, but processing overhead and performance degradation increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting security enforcement across distributed EPs at different network layers, the patent enables parallel processing of security evaluations. Different traffic flows are handled by appropriate EPs simultaneously, reducing the cumulative processing time compared to sequential multi-layer inspection. Critical traffic can be handled by faster L3/L4 EPs while application-layer traffic is handled by L7 EPs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different enforcement strategies at different network layers based on local requirements. L3/L4 EPs perform faster, simpler packet-level filtering for high-volume traffic, while L7 EPs perform more intensive application-layer inspection only when needed. This local optimization ensures that most traffic receives efficient processing while maintaining comprehensive security where required.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If security policies are customized for different network layers, then policy precision is improved, but policy management complexity and update time increase

Engineering Contradiction:
Improvepolicy precisionVSAvoidpolicy update time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements a universal policy language that can express security requirements applicable across multiple network layers. A single policy definition can be evaluated and enforced at L3, L4, and L7 layers simultaneously, eliminating the need to create and maintain separate policy sets for each layer. The policy evaluation mechanism adapts the universal policies to layer-specific contexts automatically.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system incorporates log collection and analysis capabilities that provide feedback on policy effectiveness at each enforcement point. This feedback mechanism enables automated policy optimization and rapid updates based on observed security events and traffic patterns, reducing the manual time required to adjust policies across different layers.

Inventive Principle:
Principle #23Feedback

4Reliability

If distributed enforcement points are deployed across the network, then policy enforcement coverage is improved, but system configuration complexity and deployment difficulty increase

Engineering Contradiction:
Improvepolicy enforcement coverageVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The enforcement points are designed with self-configuration capabilities, automatically receiving and applying security policies from a centralized management system. The EPs can autonomously evaluate policies against local traffic characteristics and enforce appropriate rules without manual configuration at each deployment location. This self-service approach simplifies deployment while maintaining comprehensive enforcement coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a centralized policy management system that acts as an intermediary between security administrators and distributed enforcement points. This intermediary handles policy creation, validation, and distribution to multiple EPs, abstracting away the complexity of configuring each enforcement point individually. The intermediary ensures consistent policy application across all deployment locations while simplifying the deployment process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260039630A1Zero trust packet routing aggregation and log ingestion
Publication Date: 2026.02.05 ORACLE INT CORP
  • US20260039630A1 patent drawing
  • US20260039630A1 patent drawing
  • US20260039630A1 patent drawing

AI summary

Techniques are described for visualizing enforcement of ZPR policy. A method includes aggregating log data associated with a flow of traffic within one or more networks; accessing rules associated with a policy that specifies how the flow of traffic is enforced between enforcement points within the one or more networks, wherein the policy includes one or more layer 4 rules and one or more layer 7 rules; determining, based on the rules associated with the policy, an enforcement of flow of traffic; generating a visualization of the enforcement of the flow of traffic between different enforcement points; and presenting the visualization for display within a user interface.