IP Library Granted Patent US 11,374,979
Granted Patent B2
US 11,374,979 · App. 16/452,152 · Granted Jun 28, 2022

Graph-based policy representation system for managing network devices

Inventors: Anu Mercian (Santa Clara, CA); Puneet Sharma (Palo Alto, CA); Charles F. Clark (Roseville, CA)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/20H04L41/0803H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,374,979
App. No.
16/452,152
Granted
Jun 28, 2022
Kind
B2
Abstract

Systems and methods are provided for managing network devices using policy graph representations. In some embodiments, the method includes receiving configurations for a plurality of network devices; extracting one or more policies from the configurations; extracting a label hierarchy from the configurations, the label hierarchy describing an organization of nodes in a network comprising the network devices; generating a connectivity of a network comprising the network devices based on the one or more policies and the label hierarchy; generating a policy graph representation of the connectivity of the network; and displaying the policy graph representation of the connectivity to a user.

Claims (71)

1. A system, comprising:

a hardware processor; and

a non-transitory machine-readable storage medium encoded with instructions executable by the hardware processor to perform a method comprising:

receiving configurations for a plurality of network devices;

detecting a model type for each configuration;

responsive to the model type being a denylist model, converting the configuration to an allowlist model prior to extracting one or more policies from the configuration and extracting a label hierarchy from the configuration;

extracting the one or more policies from the configurations, comprising identifying names of the policies;

extracting the label hierarchy from the configurations according to the names of the policies, the label hierarchy describing an organization of nodes in a network comprising the network devices;

generating a connectivity of a network comprising the network devices based on the one or more policies and the label hierarchy;

generating a policy graph representation of the connectivity of the network; and

displaying the policy graph representation of the connectivity to a user.

2. The system of claim 1 , the method further comprising:

generating a composed graph representation of the one or more policies; and

displaying the composed graph representation of the one or more policies to the user.

3. The system of claim 2 , the method further comprising:

receiving input from the user to modify the policies; and

modifying the composed graph representation, and the policy graph representation, according to the input from the user.

4. The system of claim 3 , the method further comprising:

modifying the configurations for the network devices based on at least one of the user input and the modified composed graph representation.

5. The system of claim 4 , the method further comprising:

installing the modified configurations in the network devices.

6. The system of claim 1 , the method further comprising:

extracting an intent from one of the policies;

generating one or more input graphs according to the intent; and

displaying the one or more input graphs to the user.

7. A non-transitory machine-readable storage medium encoded with instructions executable by a hardware processor of a computing component, the machine-readable storage medium comprising instructions to cause the hardware processor to perform a method comprising:

receiving configurations for a plurality of network devices;

detecting a model type for each configuration;

responsive to the model type being a denylist model, converting the configuration to an allowlist model prior to extracting one or more policies from the configuration and extracting a label hierarchy from the configuration;

extracting the one or more policies from the configurations, comprising identifying names of the policies;

extracting the label hierarchy from the configurations according to the names of the policies, the label hierarchy describing an organization of nodes in a network comprising the network devices;

generating a connectivity of a network comprising the network devices based on the one or more policies and the label hierarchy;

generating a policy graph representation of the connectivity of the network; and

displaying the policy graph representation of the connectivity to a user.

8. The medium of claim 7 , the method further comprising:

generating a composed graph representation of the one or more policies; and

displaying the composed graph representation of the one or more policies to the user.

9. The medium of claim 8 , the method further comprising:

receiving input from the user to modify the policies; and

modifying the composed graph representation, and the policy graph representation, according to the input from the user.

10. The medium of claim 9 , the method further comprising:

modifying the configurations for the network devices based on at least one of the user input and the modified composed graph representation.

11. The medium of claim 10 , the method further comprising:

installing the modified configurations in the network devices.

12. The medium of claim 7 , the method further comprising:

extracting an intent from one of the policies;

generating one or more input graphs according to the intent; and

displaying the one or more input graphs to the user.

13. A method comprising:

receiving configurations for a plurality of network devices;

detecting a model type for each configuration;

responsive to the model type being a denylist model, converting the configuration to an allowlist model prior to extracting one or more policies from the configuration and extracting a label hierarchy from the configuration;

extracting one or more policies from the configuration, comprising identifying names of the policies;

extracting a label hierarchy from the configurations according to the names of the policies, the label hierarchy describing an organization of nodes in a network comprising the network devices;

generating a connectivity of a network comprising the network devices based on the one or more policies and the label hierarchy;

generating a policy graph representation of the connectivity of the network; and

displaying the policy graph representation of the connectivity to a user.

14. The method of claim 13 , further comprising:

generating a composed graph representation of the one or more policies; and

displaying the composed graph representation of the one or more policies to the user.

15. The method of claim 14 , further comprising:

receiving input from the user to modify the policies; and

modifying the composed graph representation, and the policy graph representation, according to the input from the user.

16. The method of claim 15 , further comprising:

modifying the configurations for the network devices based on at least one of the user input and the modified composed graph representation.

17. The method of claim 16 , further comprising:

installing the modified configurations in the network devices.

18. The method of claim 13 , further comprising:

extracting an intent from one of the policies;

generating one or more input graphs according to the intent; and

displaying the one or more input graphs to the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2019
From: MERCIAN, ANU; SHARMA, PUNEET; CLARK, CHARLES F.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 049583/0848 →
Continuity (1)
Related Publication 20200412763A1 · Dec 31, 2020
Cited By (1)
US 12,255,964