IP Library Granted Patent US 12,289,243
Granted Patent B2
US 12,289,243 · App. 17/454,071 · Granted Apr 29, 2025

Network policy application based on session state

Inventor: Patrick Timmons (Newton, MA)
Assignee: Juniper Networks, Inc.
H04L47/2475H04L67/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,243
App. No.
17/454,071
Granted
Apr 29, 2025
Kind
B2
Abstract

Techniques are disclosed for the detection of different states of a session comprising a bidirectional flow of network traffic between client devices so as to enable a network device to apply different network policies to different states of the session. In one example, a computing device identifies multiple states of a session and defines a plurality of network policies. Each network policy defines performance requirements for network traffic during each state of the session. A network device receives the plurality of network policies and determines a state of the session. The network device selects a path based on the performance requirements of the network policy associated with the determined state of the session. The network device forwards traffic associated with the session along the selected path while the session is in the determined state.

Claims (60)

1. A method comprising:

receiving, by a network device of a plurality of network devices forming a network, a first network policy defining one or more first performance requirements for network traffic during a session establishment state of a session and a second network policy defining one or more second performance requirements for network traffic during a data communication state of the session, wherein the session comprises a bidirectional flow of network traffic between a first client device and a second client device;

based at least in part on determining that the session is in the session establishment state, selecting, by the network device and based on the one or more first performance requirements defined by the first network policy corresponding to the session establishment state of the session, a first path of a plurality of different paths through the network;

forwarding, by the network device, network traffic associated with the session establishment state of the session along the first path;

based at least in part on determining a change in the session from the session establishment state to the data communication state, selecting, by the network device and based on the one or more second performance requirements defined by the second network policy corresponding to the data communication state of the session, a second path of the plurality of different paths, the second path different from the first path; and

forwarding, by the network device, network traffic associated with the data communication state of the session along the second path.

2. The method of claim 1 , further comprising:

based at least in part on determining a change in the session from the data communication state to a teardown state, selecting, by the network device and based on one or more third performance requirements defined by a third network policy corresponding to the teardown state, a third path of the plurality of different paths, the third path different from the second path; and

forwarding, by the network device, network traffic associated with the teardown state of the session along the third path.

3. The method of claim 1 , wherein the one or more first performance requirements comprise one or more of jitter, latency, packet loss, bandwidth, or cost.

4. The method of claim 1 , wherein determining the change in the session from the session establishment state to the data communication state is based on at least one of:

a number of packets associated with the session received by the network device;

an elapsed time of the session; or

a type of packet received by the network device.

5. The method of claim 1 , wherein a plurality of different states of the session includes the session establishment state, the data communication state, and a teardown state.

6. The method of claim 1 ,

wherein determining the session is in the session establishment state is based at least in part on receiving a packet comprising a Transmission Control Protocol (TCP) “SYN” message from the first client device; and

wherein determining the change in the session from the session establishment state to the data communication state based at least in part on receiving a packet comprising a TCP “ACK” message from the first client device.

7. The method of claim 1 ,

wherein determining the session is in the session establishment state is based at least in part on receiving a packet comprising a Transport Layer Security (TLS) “ClientHello” message from the first client device; and

wherein determining the change in the session from the session establishment state to the data communication state is based at least in part on receiving a packet comprising a TLS “Finished” message from the first client device.

8. The method of claim 1 , wherein a plurality of different states of the session includes:

the session establishment state;

the data communication state, and

at least one of a real-time state, a time-sensitive state, or a time-insensitive state.

9. A network device of a plurality of network devices forming a network, the network device comprising:

storage media; and

processing circuitry configured to:

receive a first network policy defining one or more first performance requirements for network traffic during a session establishment state of a session and a second network policy defining one or more second performance requirements for network traffic during a data communication state of the session, wherein the session comprises a bidirectional flow of network traffic between a first client device and a second client device;

based at least in part on determining that the session is in the session establishment state, select, based on the one or more first performance requirements defined by the first network policy corresponding to the session establishment state of the session, a first path of a plurality of different paths through the network;

forward network traffic associated with the session establishment state of the session along the first path;

based at least in part on determining a change in the session from the session establishment state to the data communication state, select, based on the one or more second performance requirements defined by the second network policy corresponding to the data communication state of the session, a second path of the plurality of different paths, the second path different from the first path; and

forward network traffic associated with the data communication state of the session along the second path.

10. The network device of claim 9 , wherein the processing circuitry is further configured to:

based at least in part on determining a change in the session from the data communication state to a teardown state, select, based on one or more third performance requirements defined by a third network policy corresponding to the teardown state, a third path of the plurality of different paths, the third path different from the second path; and

forward network traffic associated with the teardown state of the session along the third path.

11. The network device of claim 9 , wherein the one or more first performance requirements comprise one or more of jitter, latency, packet loss, bandwidth, or cost.

12. The network device of claim 9 , wherein the processing circuitry is configured to determine the change in the session from the session establishment state to the data communication state based on a number of packets associated with the session received by the network device.

13. The network device of claim 9 , wherein the processing circuitry is configured to determine the change in the session from the session establishment state to the data communication state based on an elapsed time of the session.

14. The network device of claim 9 , wherein the processing circuitry is configured to determine the change in the session from the session establishment state to the data communication state based on a type of packet received by the network device.

15. The network device of claim 9 , wherein a plurality of different states of the session includes the session establishment state, the data communication state, and a teardown state.

16. The network device of claim 9 ,

wherein the processing circuitry is configured to determine the session is in the session establishment state based at least in part on receiving a packet comprising a Transport Layer Security (TLS) “ClientHello” message from the first client device; and

wherein the processing circuitry is configured to determine the change in the session from the session establishment state to the data communication state to based at least in part on receiving a packet comprising a TLS “Finished” message from the first client device.

17. The network device of claim 9 , wherein a plurality of different states of the session includes:

the session establishment state;

the data communication state, and

at least one of a real-time state, a time-sensitive state, or a time-insensitive state.

18. The network device of claim 10 , wherein the processing circuitry is configured to determine the change in the session from the data communication state to the teardown state based on receiving at least one of:

a packet comprising a TLS “Close Notify” message from the first client device or the second client device; or

a packet comprising a TCP “FIN” message from the first client device or the second client device.

19. The network device of claim 9 ,

wherein, to determine the change in the session from the session establishment state to the data communication state, the processing circuitry is configured to determine an impending change in the session from the session establishment state to the data communication state; and

wherein the processing circuitry is configured to proactively forward network traffic associated with session along the second path prior to the change in the session from the session establishment state to the data communication state.

20. Non-transitory, computer-readable media comprising instructions that, when executed, are configured to cause processing circuitry to:

receive a first network policy defining one or more first performance requirements for network traffic during a session establishment state of a session and a second network policy defining one or more second performance requirements for network traffic during a data communication state of the session, wherein the session comprises a bidirectional flow of network traffic between a first client device and a second client device;

based at least in part on determining that the session is in the session establishment state, select, based on the one or more first performance requirements defined by the first network policy corresponding to the session establishment state of the session, a first path of a plurality of different paths through a network formed by a plurality of network devices;

forward network traffic associated with the session establishment state of the session along the first path;

based at least in part on determining a change in the session from the session establishment state to the data communication state, select, based on the one or more second performance requirements defined by the second network policy corresponding to the data communication state of the session, a second path of the plurality of different paths, the second path different from the first path; and

forward network traffic associated with the data communication state of the session along the second path.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2025
From: TIMMONS, PATRICK
To: JUNIPER NETWORKS, INC.
Reel/Frame 070757/0602 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2021
From: TIMMONS, PATRICK
To: JUNIPER NETWORKS, INC.
Reel/Frame 058056/0533 →
Continuity (2)
Provisional Application 63128672 · Dec 21, 2020
Related Publication 20220200915A1 · Jun 23, 2022
References Cited (89)
US 8499095B1 · Sullenberger et al. · 2013 [cited by applicant]
US 8706883B2 · Aggarwal et al. · 2014 [cited by applicant]
US 8737198B1 · Holness et al. · 2014 [cited by applicant]
US 9252972B1 · Dukes · 2016 [cited by examiner]
US 9729439B2 · MeLampy et al. · 2017 [cited by applicant]
US 9729682B2 · Kumar et al. · 2017 [cited by applicant]
US 9762485B2 · Kaplan et al. · 2017 [cited by applicant]
US 9871748B2 · Gosselin et al. · 2018 [cited by applicant]
US 9985883B2 · MeLampy et al. · 2018 [cited by applicant]
US 10027768B2 · Rao · 2018 [cited by applicant]
US 10142126B2 · Venugopal et al. · 2018 [cited by applicant]
US 10200264B2 · Menon et al. · 2019 [cited by applicant]
US 10257061B2 · Menon et al. · 2019 [cited by applicant]
US 10277506B2 · Timmons et al. · 2019 [cited by applicant]
US 10341140B2 · Shen et al. · 2019 [cited by applicant]
US 10355989B1 · Panchal et al. · 2019 [cited by applicant]
US 10425511B2 · McCulley et al. · 2019 [cited by applicant]
US 10432519B2 · Baj et al. · 2019 [cited by applicant]
US 10432522B2 · Kaplan et al. · 2019 [cited by applicant]
US 10602422B1 · Jagannatha · 2020 [cited by examiner]
US 10841206B2 · Menon et al. · 2020 [cited by applicant]
US 11165863B1 · Timmons et al. · 2021 [cited by applicant]
US 11223538B1 · Arumugam · 2022 [cited by examiner]
US 11252126B1 · Thunga et al. · 2022 [cited by applicant]
US 11429463B2 · Graham · 2022 [cited by applicant]
US 11438255B2 · Tillotson et al. · 2022 [cited by applicant]
US 11582144B2 · Ramaswamy et al. · 2023 [cited by applicant]
US 11972134B2 · Irwin et al. · 2024 [cited by applicant]
US 11973686B1 · Panchal et al. · 2024 [cited by applicant]
US 20050025069A1 · Aysan · 2005 [cited by applicant]
US 20060236370A1 · John · 2006 [cited by examiner]
US 20090097417A1 · Asati et al. · 2009 [cited by applicant]
US 20090154341A1 · Bhupalam · 2009 [cited by examiner]
US 20100246602A1 · Barreto et al. · 2010 [cited by applicant]
US 20110069685A1 · Tofighbakhsh · 2011 [cited by examiner]
US 20130114482A1 · Oh · 2013 [cited by examiner]
US 20150092551A1 · Moisand · 2015 [cited by examiner]
US 20160080195A1 · Ramachandran · 2016 [cited by examiner]
US 20160337193A1 · Rao · 2016 [cited by applicant]
US 20160373341A1 · Venugopal et al. · 2016 [cited by applicant]
US 20170026417A1 · Ermagan et al. · 2017 [cited by applicant]
US 20170078410A1 · Rao · 2017 [cited by applicant]
US 20170346722A1 · Smith et al. · 2017 [cited by applicant]
US 20170366618A1 · Vrzic · 2017 [cited by examiner]
US 20180367445A1 · Bajaj · 2018 [cited by examiner]
US 20190260657A1 · Filsfils et al. · 2019 [cited by applicant]
US 20190312914A1 · Cohn · 2019 [cited by applicant]
US 20200252234A1 · Ramamoorthi et al. · 2020 [cited by applicant]
US 20200366589A1 · Kaplan et al. · 2020 [cited by applicant]
US 20200366590A1 · Kaplan et al. · 2020 [cited by applicant]
US 20200366598A1 · Kaplan et al. · 2020 [cited by applicant]
US 20200366599A1 · Kaplan et al. · 2020 [cited by applicant]
US 20200382471A1 · Janakiraman et al. · 2020 [cited by applicant]
US 20200403890A1 · McCulley et al. · 2020 [cited by applicant]
US 20210036953A1 · Menon et al. · 2021 [cited by applicant]
US 20210328889A1 · McCulley et al. · 2021 [cited by applicant]
US 20220006756A1 · Ramaswamy et al. · 2022 [cited by applicant]
US 20220070092A1 · MeLampy · 2022 [cited by examiner]
US 20220078046A1 · Wang et al. · 2022 [cited by applicant]
US 20220086062A1 · Gutierrez Estevez · 2022 [cited by applicant]
US 20220103471A1 · Kulkarni et al. · 2022 [cited by applicant]
US 20220138081A1 · Varma · 2022 [cited by examiner]
US 20220294725A1 · Vasseur et al. · 2022 [cited by applicant]
US 20220311695A1 · Kaciulis et al. · 2022 [cited by applicant]
US 20220329563A1 · Yeh et al. · 2022 [cited by applicant]
US 20230034314A1 · Brissette et al. · 2023 [cited by applicant]
US 20230059537A1 · Gavand et al. · 2023 [cited by applicant]
US 20230246930A1 · McCulley et al. · 2023 [cited by applicant]
US 20240064099A1 · Pang et al. · 2024 [cited by applicant]
EP 3690649A1 · 2020 [cited by applicant]
JP 2020167469A · 2020 [cited by examiner]
U.S. Appl. No. 17/446,601, entitled “Identifying Root Cause of Failures Through Detection of Network Scope Failures,” Juniper Networks, Inc. (inventor: Cheng et al.) filed Aug. 31, 2021. [cited by applicant]
“Transmission Control Protocol,” Darpa Internet Program Protocol Specification, Information Sciences Institute, RFC 793, Sep. 1981, 91 pp. [cited by applicant]
Dierks et al., “The Transport Layer Security (TLS) Protocol Version 1.2,” Network Working Group, RFC 5246, Aug. 2008, 105 pp. [cited by applicant]
Rescorla, “The Transport Layer Security (TLS) Protocol Version 1.3,” Internet Engineering Task Force (IETF), RFC 8446, Aug. 2018, 160 pp. [cited by applicant]
Postel, “ User Datagram Protocol,” RFC 768, Aug. 28, 1980, 3 pp. [cited by applicant]
Menon et al. “Secure Vector Reouting (SVR),” draft-menon-svr-00, Network Working Group, Internet-Draft, Oct. 1, 2021, 38 pp. [cited by applicant]
Katz et al., “Bidirectional Forwarding Detection (BFD),” RFC 5880, Internet Engineering Task Force, Jun. 2010, 49 pp. [cited by applicant]
U.S. Appl. No. 17/449,618, entitled “Metric-Based Multi-Hop Path Selection,” Juniper Networks, Inc. (inventor: Menon et al.) and filed Sep. 30, 2021. [cited by applicant]
Response to Extended Search Report dated May 30, 2022, from counterpart European Application No. 21215581.6 filed Dec. 22, 2022, 22 pp. [cited by applicant]
“Cisco Dynamic Multipoint VPN: Simple and Secure Branch-to-Branch Communications Data Sheet,” Cisco Systems, Inc., Retrieved from: https://www.cisco.com/c/en/us/products/collateral/security/dynamic-multipoint-vpn-dmvpn/… [cited by applicant]
Anonymous, “Cisco SD-WAN Dynamic on-demand Tunnel Feature—The Network DNA”, Aug. 31, 2021, 4 pp., Retrieved from the Internet: URL:https://www.thenetworkdna.com/2021/08/cisco-sd-wan-dynamic-on-demand-tunnel.html. [cited by applicant]
Cisco, “Dynamic On-Demand Tunnels”, Aug. 20, 2020, 10 pp., Retrieved from the Internet: URL:https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/system-interface/ios-xe-17/systems-interfaces-book-xe-sdwan/m… [cited by applicant]
Extended Search Report from counterpart European Application No. 21215581.6 dated May 30, 2022, 9 pp. [cited by applicant]
Guha et al., “NAT Behavioral Requirements for TCP,” Network Working Group, RFC 5382, Oct. 2008, 21 pp. [cited by applicant]
Keranen et al., “Interactive Connectivity Establishment (ICE): A Protocol for Network Address Translator (NAT) Traversal,” IETF, RFC 8445, Jul. 2018, 100 pp. [cited by applicant]
U.S. Appl. No. 17/449,311, filed Sep. 9, 2021, naming inventors Scholz et al. [cited by applicant]
Communication pursuant to Article 94(3) EPC from counterpart European Application No. 21215581.6 dated Nov. 6, 2024, 6 pp. [cited by applicant]
Response to Communication pursuant to Article 94(3) EPC dated Nov. 6, 2024, from counterpart European Application No. 21215581.6 filed Mar. 3, 2025, p. 24. [cited by applicant]
Cited By (1)
US 12,501,316