IP Library Granted Patent US 11,539,673
Granted Patent B2
US 11,539,673 · App. 17/308,238 · Granted Dec 27, 2022

Predictive secure access service edge

Inventors: Jean-Philippe Vasseur (Saint Martin d'Uriage, FR); Grégory Mermoud (Venthône, CH); Vinay Kumar Kolar (San Jose, CA); Pierre-André Savalle (Rueil-Malmaison, FR)
Assignee: Cisco Technology, Inc.
H04L63/0281G06N5/04G06N20/00H04L12/4633H04L41/147H04L43/12H04L63/029H04L63/166H04L67/10H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,539,673
App. No.
17/308,238
Granted
Dec 27, 2022
Kind
B2
Abstract

In one embodiment, a device obtains telemetry data that results from an edge router sending probes to a cloud-hosted application via a plurality of points of presence. The device makes, based on the telemetry data, predictions as to whether use of each of the plurality of points of presence by the edge router to access the cloud-hosted application will result in a violation of a service level agreement. The device selects, based on the predictions, a particular point of presence from among the plurality of points of presence that the edge router should use to access the cloud-hosted application during a time window. The device causes the edge router to access the cloud-hosted application via the particular point of presence during the time window.

Claims (47)

1. A method comprising:

obtaining, by a device, telemetry data that results from an edge router sending probes to a cloud-hosted application via a plurality of points of presence;

making, by the device and based on the telemetry data, predictions as to whether use of each of the plurality of points of presence by the edge router to access the cloud-hosted application will result in a violation of a service level agreement;

selecting, by the device and based on the predictions, a particular point of presence from among the plurality of points of presence that the edge router should use to access the cloud-hosted application during a time window;

causing, by the device, the edge router to access the cloud-hosted application via the particular point of presence during the time window;

making, by the device, a determination that a violation of the service level agreement occurred while the edge router was accessing the cloud-hosted application via the particular point of presence; and

causing, by the device and based in part on the determination, the particular point of presence to be ineligible to be used by the edge router to access the cloud-hosted application.

2. The method as in claim 1 , wherein the plurality of points of presence are selected based on at least one of: their geographic distances to the edge router, data regarding their capacities, or their historical data.

3. The method as in claim 1 , wherein the device makes the predictions based further in part on telemetry data obtained from one or more other edge routers that also send probes to the cloud-hosted application via one or more of the plurality of points of presence.

4. The method as in claim 1 , further comprising:

causing, by the device, tunnels to be established between the edge router and the plurality of points of presence, prior to the edge router sending the probes to the cloud-hosted application.

5. The method as in claim 1 , further comprising:

causing, by the device, the edge router to connect to the plurality of points of presence via a Hypertext Transfer Protocol Secure (HTTPS) proxy.

6. The method as in claim 1 , further comprising:

causing, by the device, the particular point of presence to send traffic from the cloud-hosted application to the edge router via a particular tunnel.

7. The method as in claim 1 , further comprising:

adjusting the plurality of points of presence, based in part on the predictions.

8. The method as in claim 1 , wherein the probes comprise Session Initiation Protocol (SIP) probes.

9. The method as in claim 1 , wherein the probes comprise Hypertext Transfer Protocol Secure (HTTPS) probes.

10. An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

obtain telemetry data that results from an edge router sending probes to a cloud-hosted application via a plurality of points of presence;

make, based on the telemetry data, predictions as to whether use of each of the plurality of points of presence by the edge router to access the cloud-hosted application will result in a violation of a service level agreement;

select, based on the predictions, a particular point of presence from among the plurality of points of presence that the edge router should use to access the cloud-hosted application during a time window; and

cause the edge router to access the cloud-hosted application via the particular point of presence during the time window;

make a determination that a violation of the service level agreement occurred while the edge router was accessing the cloud-hosted application via the particular point of presence; and

cause, based in part on the determination, the particular point of presence to be ineligible to be used by the edge router to access the cloud-hosted application.

11. The apparatus as in claim 10 , wherein the plurality of points of presence are selected based on at least one of: their geographic distances to the edge router, data regarding their capacities, or their historical data.

12. The apparatus as in claim 10 , wherein the apparatus makes the predictions based further in part on telemetry data obtained from one or more other edge routers that also send probes to the cloud-hosted application via one or more of the plurality of points of presence.

13. The apparatus as in claim 10 , wherein the process when executed is further configured to:

cause tunnels to be established between the edge router and the plurality of points of presence, prior to the edge router sending the probes to the cloud-hosted application.

14. The apparatus as in claim 10 , wherein the process when executed is further configured to:

cause the edge router to connect to the plurality of points of presence via a Hypertext Transfer Protocol Secure (HTTPS) proxy.

15. The apparatus as in claim 10 , wherein the process when executed is further configured to:

cause the particular point of presence to send traffic from the cloud-hosted application to the edge router via a particular tunnel.

16. The apparatus as in claim 10 , wherein the process when executed is further configured to:

adjust the plurality of points of presence, based in part on the predictions.

17. The apparatus as in claim 10 , wherein the probes comprise Session Initiation Protocol (SIP) or Hypertext Transfer Protocol Secure (HTTPS) probes.

18. A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:

obtaining, by the device, telemetry data that results from an edge router sending probes to a cloud-hosted application via a plurality of points of presence;

making, by the device and based on the telemetry data, predictions as to whether use of each of the plurality of points of presence by the edge router to access the cloud-hosted application will result in a violation of a service level agreement;

selecting, by the device and based on the predictions, a particular point of presence from among the plurality of points of presence that the edge router should use to access the cloud-hosted application during a time window;

causing, by the device, the edge router to access the cloud-hosted application via the particular point of presence during the time window;

making, by the device, a determination that a violation of the service level agreement occurred while the edge router was accessing the cloud-hosted application via the particular point of presence; and

causing, by the device and based in part on the determination, the particular point of presence to be ineligible to be used by the edge router to access the cloud-hosted application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2021
From: VASSEUR, JEAN-PHILIPPE; MERMOUD, GRÉGORY; KOLAR, VINAY KUMAR; SAVALLE, PIERRE-ANDRÉ
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056140/0628 →
Continuity (1)
Related Publication 20220360567A1 · Nov 10, 2022