IP Library › Granted Patent US 11,411,765
Granted Patent B2
US 11,411,765 · App. 16/739,442 · Granted Aug 9, 2022

Automating a software-defined wide area network policy for internet of things end points

Inventors: Balaji Sundararajan (Fremont, CA); Vivek Agarwal (Campbell, CA); Anand Oswal (Pleasanton, CA); Chethan Channappa (San Jose, CA); Subhash Kodnad (Dublin, CA); Jeevan Sharma (Fremont, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L12/2856G06F9/45558G16Y30/10H04L12/66H04L41/145H04L41/5032H04L49/70H04L63/20H04W92/02G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,765
App. No.
16/739,442
Granted
Aug 9, 2022
Kind
B2
Abstract

The present disclosure is directed to managing industrial internet of things end points and includes one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause one or more switches to perform operations comprising: identifying a first end point using a protocol associated with the first end point, determining a classification for the identified first end point based on one or more attributes of the first end point, identifying one or more related end points having the classification in common with the first end point, segmenting the first end point with the identified one or more related end points, and applying one or more policies to the segmented first end point and the one or more related end points.

Claims (63)

1. A system, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause one or more switches to perform operations comprising:

detecting a first connection of a first end point to a network;

in response to detecting the first connection, determining a protocol associated with the first end point;

identifying the first end point as an end point requiring classification, the identifying based on the protocol associated with the first end point;

in response to identifying the first end point as the end point requiring classification, determining one or more attributes of the first end point;

determining the classification for the identified first end point based on the one or more attributes of the first end point;

identifying one or more related end points having the classification in common with the first end point;

segmenting the first end point with the identified one or more related end points; and

applying one or more policies to the segmented first end point and the one or more related end points.

2. The system of claim 1 , the operations further comprising:

applying a policy to communicatively connect the first end point with the identified one or more related end points.

3. The system of claim 1 , wherein the one or more switches comprise a virtual machine, and wherein the virtual machine is operable to perform the operations comprising identifying the first end point using the protocol associated with the first end point and identifying the one or more related end points having the classification in common with the first end point.

4. The system of claim 1 , the operations further comprising:

creating a secure network overlay for the first end point and the identified one or more related end points.

5. The system of claim 4 , the operations further comprising:

enforcing network policies on the first end point and across the secure network overlay.

6. The system of claim 1 , the operations further comprising:

integrating the first end point and the identified one or more related end points in a software-defined wide area network (SD-WAN).

7. The system of claim 1 , the operations further comprising:

extending the one or more policies applied to the first end point and the one or more related end points across one or more clouds.

8. A method, comprising:

detecting a first connection of a first end point to a network;

in response to detecting the first connection, determining a protocol associated with the first end point;

identifying, via one or more switches, the first end point as an end point requiring classification, the identifying based on the protocol associated with the first end point;

in response to identifying the first end point as the end point requiring classification, determining one or more attributes of the first end point;

determining the classification for the identified first end point based on the one or more attributes of the first end point;

identifying, via the one or more switches, one or more related end points having the classification in common with the first end point;

segmenting the first end point with the identified one or more related end points; and

applying one or more policies to the segmented first end point and the one or more related end points.

9. The method of claim 8 , further comprising:

applying a policy to communicatively connect the first end point with the identified one or more related end points.

10. The method of claim 8 , further comprising:

collecting telemetry data from a plurality of end points, wherein the plurality of end points comprises the first end point, the one or more related end points, and one or more unrelated end points that do not have the classification in common with the first end point; and

grouping a subset of the telemetry data indicating performance of a segment, wherein the subset of the telemetry data comprises telemetry data associated with the first end point and telemetry data associated with the one or more related end points, and excludes telemetry data associated with the unrelated end points.

11. The method of claim 8 , further comprising:

creating a secure network overlay for the first end point and the identified one or more related end points.

12. The method of claim 11 , further comprising:

enforcing network policies on the first end point and across the secure network overlay.

13. The method of claim 8 , further comprising:

integrating the first end point and the identified one or more related end points in a software-defined wide area network (SD-WAN).

14. The method of claim 8 , further comprising:

extending the one or more policies applied to the first end point and the one or more related end points across one or more clouds.

15. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause one or more switches to perform operations comprising:

detecting a first connection of a first end point to a network;

in response to detecting the first connection, determining a protocol associated with the first end point;

identifying the first end point as an end point requiring classification, the identifying based on the protocol associated with the first end point;

in response to identifying the first end point as the end point requiring classification, determining one or more attributes of the first end point;

determining the classification for the identified first end point based on the one or more attributes of the first end point;

identifying one or more related end points having the classification in common with the first end point;

segmenting the first end point with the identified one or more related end points; and

applying one or more policies to the segmented first end point and the one or more related end points.

16. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising:

applying a policy to communicatively connect the first end point with the identified one or more related end points.

17. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising:

creating a secure network overlay for the first end point and the identified one or more related end points.

18. The one or more computer-readable non-transitory storage media of claim 17 , the operations further comprising:

enforcing network policies on the first end point and across the secure network overlay.

19. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising:

integrating the first end point and the identified one or more related end points in a software-defined wide area network (SD-WAN).

20. The one or more computer-readable non-transitory storage media of claim 15 , the operations further comprising:

extending the one or more policies applied to the first end point across one or more clouds.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2020
From: SUNDARARAJAN, BALAJI; AGARWAL, VIVEK; OSWAL, ANAND; CHANNAPPA, CHETHAN; KODNAD, SUBHASH; SHARMA, JEEVAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 051476/0844 →
Continuity (1)
Related Publication 20210218594A1 · Jul 15, 2021