IP Library Granted Patent US 12677150
Granted Patent B2
US 12677150 · App. 18/489,611 · Granted Jul 7, 2026

Stateful multi-privileged SD-WAN control connections

Inventors: Venkatesh Nataraj (Union City, CA); Angelica Jirina Semenec (Fremont, CA)
Assignee: Cisco Technology, Inc.
H04W12/069H04L63/0823H04L63/10H04L63/20H04W12/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12677150
App. No.
18/489,611
Granted
Jul 7, 2026
Kind
B2
Abstract

This disclosure describes techniques to establish and manage stateful multi-privileged control connections between edge devices and a controller of a SD-WAN. The described techniques may receive request(s) and/or data from edge device(s) that include certificates. The described techniques may utilize criteria to determine validity and acceptability of the certificates during authentication. Where the controller determines a certificate in invalid and acceptable, the described techniques move the edge device to a new quarantine state. In the quarantine state, an edge device maintains the control connection with the controller in order to remediate the certificate, but restricts access to the data plane to reduce security risks. A notification may be generated and displayed to an administrator in response to determining a certificate is invalid and acceptable and/or in response to moving the edge device to the quarantine state. Accordingly, the described techniques improve SD-WAN infrastructure and reduce security risks.

Claims (69)

1 . A method implemented by a controller of a network that manages control connections within the network, the method comprising:

receiving a request from an edge device to form a control connection with the controller and access the network, the request including a certificate;

determining that the certificate is invalid by determining that the certificate has expired based on an expiration of the certificate;

determining that the certificate is acceptable by determining that the certificate is at least one of not corrupted, has a valid serial number, was issued by a trusted certificate authority, or does not include a security compromise indicator;

based at least in part on the certificate being invalid and acceptable, moving the edge device to a quarantine state, wherein moving the edge device to the quarantine state comprises:

removing, by the controller, access of the edge device to a data plane of the network; and

maintaining, by the controller, the control connection with the edge device to enable access to a control plane of the network; and

while the edge device is in the quarantine state:

enabling the edge device to utilize the control connection to access the control plane to remediate the certificate being invalid and acceptable;

communicating, via the control plane, an updated certificate to the edge device; and

receiving, at the control plane device, the updated certificate from the edge device; and

in response to determining that the updated certificate is valid, moving the edge device out of the quarantine state by providing the edge device with access to the data plane of the network.

2 . The method of claim 1 , wherein the network comprises a Software-Defined Wide Area Network (SD-WAN) and wherein the control connections comprise stateful multi-privileged control connections.

3 . The method of claim 1 , wherein moving the edge device to the quarantine state comprises:

updating, by the controller and based on accessing a list associated with a plurality of edge devices in the network, a state associated with the edge device from one of a valid state or a staging state to the quarantine state.

4 . The method of claim 1 , further comprising:

receiving input indicating a corrective action associated with the edge device;

performing, by the controller, the corrective action; and

based at least in part on performing the corrective action, moving the edge device from the quarantine state to a valid state, wherein the valid state enables access to the data plane of the network.

5 . The method of claim 1 , further comprising:

causing a notification to be displayed on a user interface, the notification indicating the edge device being moved to the quarantine state, wherein the user interface further displays data associated with a plurality of edge devices within the network, the data comprising health data associated with the network.

6 . The method of claim 1 , wherein prior to moving the edge device to the quarantine state, the method further comprises:

causing a notification to be displayed on a user interface, the notification indicating that the edge device is invalid and acceptable;

receiving, via the user interface, input requesting the edge device be moved to the quarantine state; and

based at least in part on the input, moving the edge device to the quarantine state.

7 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, by a controller of a network, a request from an edge device to form a control connection with the controller and access the network, the request including a certificate;

determining that the certificate is invalid by determining that the certificate has expired based on an expiration of the certificate;

determining that the certificate is acceptable by determining that the certificate is at least one of not corrupted, has a valid serial number, was issued by a trusted certificate authority, or does not include a security compromise indicator;

based at least in part on the certificate being invalid and acceptable, moving, by the controller, the edge device to a quarantine state, wherein moving the edge device to the quarantine state comprises:

removing, by the controller, access of the edge device to a data plane of the network; and

maintaining, by the controller, the control connection with the edge device to enable access to a control plane of the network; and

while the edge device is in the quarantine state:

enabling the edge device to utilize the control connection to access the control plane to remediate the certificate being invalid and acceptable;

communicating, via the control plane, an updated certificate to the edge device; and

receiving, at the control plane device, the updated certificate from the edge device; and

in response to determining that the updated certificate is valid, moving the edge device out of the quarantine state by providing the edge device with access to the data plane of the network.

8 . The system of claim 7 , wherein the network comprises a Software-Defined Wide Area Network (SD-WAN) and wherein the control connection comprises a stateful multi-privileged control connection.

9 . The system of claim 7 , wherein moving the edge device to the quarantine state comprises:

updating, by the controller and based on accessing a list associated with a plurality of edge devices in the network, a state associated with the edge device from one of a valid state or a staging state to the quarantine state.

10 . The system of claim 7 , the operations further comprising:

receiving, via a user interface, input indicating a corrective action associated with the edge device;

performing, by the controller, the corrective action; and

based at least in part on performing the corrective action, moving the edge device from the quarantine state to a valid state, wherein the valid state enables access to the data plane of the network.

11 . The system of claim 7 , wherein a user interface further displays data associated with a plurality of edge devices within the network, the data comprising health data associated with the network.

12 . The system of claim 7 , wherein prior to moving the edge device to the quarantine state, the operations further comprise:

causing a notification to be displayed on a user interface, the notification indicating that the edge device is invalid and acceptable;

receiving, via the user interface, input requesting the edge device be moved to the quarantine state; and

based at least in part on the input, moving the edge device to the quarantine state.

13 . A method implemented by a controller of a network that manages control connections of a plurality of edge devices within the network, the method comprising:

maintaining, for the plurality of edge devices, the control connections between the plurality of edge devices and the controller;

receiving, from an edge device of the plurality of edge devices, data associated with a certificate of the edge device;

determining that the certificate is invalid by determining that the certificate has expired based on an expiration of the certificate;

determining that the certificate is acceptable by determining that the certificate is at least one of not corrupted, has a valid serial number, was issued by a trusted certificate authority, or does not include a security compromise indicator;

based at least in part on the certificate being invalid and acceptable, moving the edge device from a valid state to a quarantine state, wherein moving the edge device to the quarantine state comprises:

removing, by the controller, access of the edge device to a data plane of the network; and

maintaining, by the controller, the control connection with the edge device to enable access to a control plane of the network; and

while the edge device is in the quarantine state:

enabling the edge device to utilize the control connection to access the control plane to remediate the certificate being invalid and acceptable;

communicating, via the control plane, an updated certificate to the edge device; and

receiving, at the control plane device, the updated certificate from the edge device; and

in response to determining that the updated certificate is valid, moving the edge device out of the quarantine state by providing the edge device with access to the data plane of the network.

14 . The method of claim 13 , wherein the network comprises a Software-Defined Wide Area Network (SD-WAN), and wherein the control connections comprise stateful multi-privileged control connections.

15 . The method of claim 13 , further comprising:

receiving, via a user interface, input indicating a corrective action associated with the edge device;

performing, by the controller, the corrective action; and

based at least in part on performing the corrective action, moving the edge device from the quarantine state to the valid state, wherein the valid state enables access to the data plane of the network.