IP Library Granted Patent US 12689659
Granted Patent B2
US 12689659 · App. 18/532,497 · Granted Jul 21, 2026

Zero trust policy manager

Inventors: György Ács (Paty, HU); Patrick Cardot (Montlignon, FR); Pascal Delprat (Collobrières, FR); Hatem Aljehani (Jeddah, SA)
Assignee: Cisco Technology, Inc.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12689659
App. No.
18/532,497
Granted
Jul 21, 2026
Kind
B2
Abstract

In some aspects, a method for managing security policies on a network may include a policy manager receiving, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services. The policy manager may also compare the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status. Finally, the policy manager may present a visual representation of the security data that includes at least an indication of the one or more discrepancies.

Claims (41)

1 . A computer-implemented method for managing security policies on a network, comprising:

receiving, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services;

comparing the information descriptive of the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status by identifying portions of the information descriptive of the security policy data that are not reflected in the security status of at least one network connection; and

presenting an interactive visual representation, the interactive visual representation includes the security data that includes at least an indication of the one or more discrepancies, an overall threat level, and at least a portion of the network.

2 . The computer-implemented method of claim 1 , further comprising:

receiving a request to update the security policy data, wherein the request includes a modification to the security policy data associated with the one or more security services; and

transmitting the request to a policy modification program, wherein when received by the policy modification program, the policy modification program distributes the modification to the security policy data to at least one of the one or more security services.

3 . The computer-implemented method of claim 2 , wherein the at least one of the one or more security services implements the modification to the security policy data on the network.

4 . The computer-implemented method of claim 1 , further comprising: generating a database comprised of at least the one or more security services and the security data.

5 . The computer-implemented method of claim 4 , wherein the database has a hierarchical tree structure comprised of objects and arrays, and wherein the hierarchical tree structure includes at least a user, user group, a device, and a network access method based on the security data.

6 . The computer-implemented method of claim 1 , wherein the visual representation is configured as a matrix, indicating at least a device and one or more network connections associated with the device.

7 . The computer-implemented method of claim 1 , wherein the visual representation is configured to display security data according to workforce, workplace, or workload.

8 . The computer-implemented method of claim 1 , further comprising:

updating the visual representation according to periodic updates to the security data as indicated by a security policy associated with the network.

9 . A system comprising:

one or more processors; and

a memory storing instructions that, when executed by the one or more processors, configure the system to:

receive, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services;

compare the information descriptive of the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status by identifying portions of the information descriptive of the security policy data that are not reflected in the security status of at least one network connection; and

present an interactive visual representation, the interactive visual representation includes the security data that includes at least an indication of the one or more discrepancies, an overall threat level, and at least a portion of the network.

10 . The system of claim 9 , wherein the instructions further configure the system to:

receive a request to update the security policy data, wherein the request includes a modification to the security policy data associated with the one or more security services; and

transmit the request to a policy modification program, wherein when received by the policy modification program, the policy modification program distributes the modification to the security policy data to at least one of the one or more security services.

11 . The system of claim 10 , wherein the at least one of the one or more security services implements the modification to the security policy data on the network.

12 . The system of claim 9 , wherein the instructions further configure the system to:

generate a database comprised of at least the one or more security services and the security data.

13 . The system of claim 12 , wherein the database has a hierarchical tree structure comprised of objects and arrays, and wherein the hierarchical tree structure includes at least a user, user group, a device, and a network access method based on the security data.

14 . The system of claim 9 , wherein the visual representation is configured as a matrix, indicate at least a device and one or more network connections associated with the device.

15 . The system of claim 9 , wherein the visual representation is configured to display security data according to workforce, workplace, or workload.

16 . The system of claim 9 , wherein the instructions further configure the system to:

update the visual representation according to periodic updates to the security data as indicated by a security policy associated with the network.

17 . A non-transitory computer-readable storage medium, the non-transitory computer-readable storage medium including instructions that when executed by a computer, cause the computer to:

receive, from one or more security services implemented on a network, information descriptive of a security policy data and a security status of at least one network connection between a user and a service protected by the one or more security services;

compare the information descriptive of the security policy data and the security status of at least one network connection to determine one or more discrepancies between an intent of the security policy data and the security status by identifying portions of the information descriptive of the security policy data that are not reflected in the security status of at least one network connection; and

present an interactive visual representation, the interactive visual representation includes a the security data that includes at least an indication of the one or more discrepancies, an overall threat level, and at least a portion of the network.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions further configure the computer to:

receive a request to update the security policy data, wherein the request includes a modification to the security policy data associated with the one or more security services; and

transmit the request to a policy modification program, wherein when received by the policy modification program, the policy modification program distributes the modification to the security policy data to at least one of the one or more security services.

19 . The non-transitory computer-readable storage medium of claim 17 , wherein the instructions further configure the computer to:

generate a database comprised of at least the one or more security services and the security data.

20 . The non-transitory computer-readable storage medium of claim 19 , wherein the database has a hierarchical tree structure comprised of objects and arrays, and wherein the hierarchical tree structure includes at least a user, user group, a device, and a network access method based on the security data.