IP Library › Granted Patent US 12,107,937
Granted Patent B2
US 12,107,937 · App. 17/679,499 · Granted Oct 1, 2024

Dynamic proxy placement for policy-based routing

Inventors: Kyle Andrew Donald Mestery (Woodbury, MN); Vincent E. Parla (North Hampton, NH)
Assignee: Cisco Technology, Inc.
H04L67/56H04L12/56H04L41/0895H04L49/45H04L49/60H04L67/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,107,937
App. No.
17/679,499
Granted
Oct 1, 2024
Kind
B2
Abstract

Techniques for operationalizing workloads at edge network nodes, while maintaining centralized intent and policy controls. The techniques may include storing, in a cloud-computing network, a workload image that includes a function capability. The techniques may also include receiving, at the cloud-computing network, a networking policy associated with an enterprise network. Based at least in part on the networking policy, a determination may be made at the cloud-computing network that the function capability is to be operationalized on an edge device of the enterprise network. The techniques may also include sending the workload image to the edge device to be installed on the edge device to operationalize the function capability. In some examples, the function capability may be a security function capability (e.g., proxy, firewall, etc.), a routing function capability (e.g., network address translation, load balancing, etc.), or any other function capability.

Claims (54)

1. A method performed by an edge device of an enterprise network, the method comprising:

receiving a packet associated with a data flow between the edge device and a destination, the edge device being in a constituent network associated with the enterprise network;

determining that a proxy is to be installed on the edge device and used by the edge device to send the packet to the destination;

sending, to a controller hosted on a cloud-computing network that is remote from the enterprise network, a request for the controller to select a proxy image associated with the proxy based at least in part on the at least one of a networking policy or a networking optimization associated with the enterprise network;

obtaining, from the controller, the proxy image associated with the proxy;

installing the proxy image on the edge device to operationalize the proxy; and

causing the packet to be sent to the destination via the proxy, the proxy applying a policy to the packet without breaking encryption of the packet.

2. The method of claim 1 , wherein obtaining the proxy image comprises:

sending, to the controller hosted on the cloud-computing network, a request for the controller to (1) select the proxy image based at least in part on the at least one of the networking policy or the networking optimization and (2) send the proxy image to the edge device; and

receiving the proxy image from the controller.

3. The method of claim 1 , wherein obtaining the proxy image comprises:

receiving, from the controller, an indication of the proxy image to be used; and

obtaining, by the edge device and based at least in part on the indication, the proxy image from a memory that is accessible to the edge device.

4. The method of claim 1 , wherein the proxy image runs on the edge device as at least one of a virtual machine, a container, or a serverless function.

5. The method of claim 1 , wherein a protocol associated with the packet of the data flow comprises at least one of:

Hypertext Transfer Protocol (HTTP);

Quick user datagram protocol (UDP) Internet Connections (QUIC); or

Multiplexed Application Substrate over QUIC Encryption (MASQUE).

6. The method of claim 1 , wherein the edge device is a router device of the constituent network of the enterprise network.

7. The method of claim 1 , wherein a policy associated with the proxy comprises at least one of:

load balancing traffic;

caching;

allowing traffic to flow to the destination; or

denying traffic from flowing to the destination.

8. The method of claim 1 , further comprising:

determining that the data flow is inactive; and

based at least in part on the data flow being inactive, uninstalling the proxy image from running on the edge device.

9. The method of claim 1 , wherein the packet is a first packet of multiple packets of the data flow that are to be sent between the edge device and the destination, and wherein determining that the proxy is to be used is based at least in part on an inspection of the first packet.

10. The method of claim 1 , wherein the packet includes an encrypted portion and the proxy is configured to route the packet toward the destination based on information that is outside of the encrypted portion of the packet.

11. The method of claim 1 , wherein the proxy is configured to downgrade a protocol associated with the packet to enhance policy application between the edge device and the destination.

12. An edge device associated with an enterprise network, the edge device comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions that, when executed by the one or more processors, cause the edge device to perform operations comprising:

receiving a packet associated with a data flow between the edge device and a destination, the edge device being in a constituent network associated with the enterprise network;

determining that a proxy is to be installed on the edge device and used by the edge device to send the packet to the destination;

based at least in part on determining that the proxy is to be used to send the packet, sending, to a controller hosted on a cloud-computing network that is remote from the enterprise network, a request associated with identifying a proxy image that is to be installed on the edge device;

receiving, from the controller, an indication of the proxy image that is to be installed on the edge device, the proxy image selected by the controller based at least in part on the request and at least one of a networking policy or a networking optimization associated with the enterprise network;

installing the proxy image on the edge device to operationalize the proxy; and

causing the packet to be sent to the destination via the proxy, the proxy capable of applying a policy to the packet without breaking encryption of the packet.

13. The edge device of claim 12 , wherein the proxy image runs on the edge device as at least one of a virtual machine, a container, or a serverless function.

14. The edge device of claim 12 , the operations further comprising obtaining, based at least in part on the indication, the proxy image associated with the proxy, the proxy image obtained from a memory that is accessible to the edge device.

15. The edge device of claim 12 , wherein a protocol associated with the packet of the data flow comprises at least one of:

Hypertext Transfer Protocol (HTTP);

Quick user datagram protocol (UDP) Internet Connections (QUIC); or

Multiplexed Application Substrate over QUIC Encryption (MASQUE).

16. The edge device of claim 12 , wherein the edge device is a router device of the constituent network of the enterprise network.

17. The edge device of claim 12 , wherein the policy applied by the proxy comprises at least one of:

load balancing traffic;

caching;

allowing traffic to flow to the destination; or

denying traffic from flowing to the destination.

18. The edge device of claim 12 , wherein the packet is a first packet of multiple packets of the data flow that are to be sent between the edge device and the destination, and wherein determining that the proxy is to be used is based at least in part on an inspection of the first packet.

19. The edge device of claim 12 , wherein the packet includes an encrypted portion and the proxy is configured to route the packet toward the destination based on information that is outside of the encrypted portion of the packet.

20. The edge device of claim 12 , wherein the proxy is configured to downgrade a protocol associated with the packet to enhance policy application between the edge device and the destination.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2022
From: MESTERY, KYLE ANDREW DONALD; PARLA, VINCENT E.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059241/0075 →
Continuity (1)
Related Publication 20230269305A1 · Aug 24, 2023