IP Library Granted Patent US 10,728,097
Granted Patent B1
US 10,728,097 · App. 16/204,144 · Granted Jul 28, 2020

Hierarchical policies in a network

Inventors: Bill Y. Chin (Sunnyvale, CA); Elanchezhiyan Elango (Cupertino, CA); Venkatram Ramanathan (San Jose, CA)
Assignee: Riverbed Technology, Inc.
H04L41/0893H04L67/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,728,097
App. No.
16/204,144
Granted
Jul 28, 2020
Kind
B1
Abstract

Systems and techniques are described for applying a set of policy rules to network traffic. During operation, conditions specified in the set of policy rules can be evaluated, wherein each condition is a logical expression defined over a set of variables, and is evaluated by substituting values of the set of variables associated with the network traffic into the logical expression. Next, a subset of policy rules can be selected whose conditions evaluated as true. A highest precedence policy rule from the subset of policy rules can then be identified by applying a set of precedence rules to the subset of policy rules, wherein the set of precedence rules imposes a precedence order on the set of policy rules based on condition categories and condition specificities. Finally, an action that is specified in the highest precedence policy rule can be performed.

Claims (32)

1. A method for applying a set of policy rules to network traffic, the method comprising:

evaluating, by using a processor, conditions specified in the set of policy rules, wherein each condition is a logical expression defined over a set of variables, and is evaluated by substituting values of the set of variables associated with the network traffic into the logical expression;

selecting a subset of policy rules whose conditions evaluated as true;

selecting a highest precedence policy rule from the subset of policy rules by applying a set of precedence rules to the subset of policy rules, wherein the set of precedence rules imposes a precedence order on the set of policy rules based on condition categories and condition specificities; and

performing an action specified in the highest precedence policy rule.

2. The method of claim 1 , wherein the set of variables includes one or more of: a user variable that corresponds to a user, an application variable that corresponds to an application, a network segment variable that corresponds to a network segment, or a timeframe variable that corresponds to a timeframe.

3. The method of claim 1 , wherein the action includes one or more of: path selection, encryption, Quality of Service (QoS), and drop.

4. The method of claim 1 , wherein each condition belongs to a condition category that is one of: an application category, a user category, a segment category, or a timeframe category.

5. The method of claim 4 , wherein the precedence order in decreasing precedence is as follows: conditions in the application category, conditions in the user category, conditions in the segment category, and conditions in the timeframe category.

6. The method of claim 5 , wherein within a given category, conditions with more specificity have higher precedence than conditions with lower specificity.

7. A non-transitory storage medium storing instructions that, when executed by a processor, cause the processor to perform a method for applying a set of policy rules to network traffic, the method comprising:

evaluating conditions specified in the set of policy rules, wherein each condition is a logical expression defined over a set of variables, and is evaluated by substituting values of the set of variables associated with the network traffic into the logical expression;

selecting a subset of policy rules whose conditions evaluated as true;

selecting a highest precedence policy rule from the subset of policy rules by applying a set of precedence rules to the subset of policy rules, wherein the set of precedence rules imposes a precedence order on the set of policy rules based on condition categories and condition specificities; and

performing an action specified in the highest precedence policy rule.

8. The non-transitory storage medium of claim 7 , wherein the set of variables includes one or more of: a user variable that corresponds to a user, an application variable that corresponds to an application, a network segment variable that corresponds to a network segment, or a timeframe variable that corresponds to a timeframe.

9. The non-transitory storage medium of claim 7 , wherein the action includes one or more of: path selection, encryption, Quality of Service (QoS), and drop.

10. The non-transitory storage medium of claim 7 , wherein each condition belongs to a condition category that is one of: an application category, a user category, a segment category, or a timeframe category.

11. The non-transitory storage medium of claim 10 , wherein the precedence order in decreasing precedence is as follows: conditions in the application category, conditions in the user category, conditions in the segment category, and conditions in the timeframe category.

12. The non-transitory storage medium of claim 11 , wherein within a given category, conditions with more specificity have higher precedence than conditions with lower specificity.

13. An apparatus, comprising:

a processor; and

a non-transitory storage medium storing instructions that, when executed by the processor, cause the processor to perform a method for applying a set of policy rules to network traffic, the method comprising:

evaluating conditions specified in the set of policy rules, wherein each condition is a logical expression defined over a set of variables, and is evaluated by substituting values of the set of variables associated with the network traffic into the logical expression;

selecting a subset of policy rules whose conditions evaluated as true;

selecting a highest precedence policy rule from the subset of policy rules by applying a set of precedence rules to the subset of policy rules, wherein the set of precedence rules imposes a precedence order on the set of policy rules based on condition categories and condition specificities; and

performing an action specified in the highest precedence policy rule.

14. The apparatus of claim 13 , wherein the set of variables includes one or more of: a user variable that corresponds to a user, an application variable that corresponds to an application, a network segment variable that corresponds to a network segment, or a timeframe variable that corresponds to a timeframe.

15. The apparatus of claim 13 , wherein the action includes one or more of: path selection, encryption, Quality of Service (QoS), and drop.

16. The apparatus of claim 13 , wherein each condition belongs to a condition category that is one of: an application category, a user category, a segment category, or a timeframe category.

17. The apparatus of claim 16 , wherein the precedence order in decreasing precedence is as follows: conditions in the application category, conditions in the user category, conditions in the segment category, and conditions in the timeframe category.

18. The apparatus of claim 17 , wherein within a given category, conditions with more specificity have higher precedence than conditions with lower specificity.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
PATENT SECURITY AGREEMENT Recorded Jul 10, 2019
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 049720/0808 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2018
From: CHIN, BILL Y.; ELANGO, ELANCHEZHIYAN; RAMANATHAN, VENKATRAM
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 047830/0265 →
Cited By (1)
US 12,647,321