IP Library Patent Application 18075263
Patent Application
App. No. 18/075,263

NETWORK SECURITY FOR MULTIPLE FUNCTIONAL DOMAINS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/075,263
Abstract

Methods, systems, and storage media are described for providing network security across multiple functional domains. In particular, some implementations are directed to encapsulating data packets sent from one functional domain to another with fully qualified security group (FQSG) information to allow the destination domain to process the data packet based on the FQSG information from the source domain. Other implementations may be disclosed or claimed.

Claims (37)

1 . A computer system comprising:

a processor; and

memory coupled to the processor and storing instructions that, when executed by the processor, are configurable to cause the computer system to:

generate a data packet within a first functional domain;

determine that the data packet is destined for a second functional domain; and

in response to determining that the data packet is destined for the second functional domain:

encapsulate the data packet within a header comprising a fully qualified security group (FQSG) field associated with one or more cloud native security groups; and

send the encapsulated data packet to the second functional domain.

2 . The computer system of claim 1 , wherein the first functional domain and the second functional domain are within a common functional instance.

3 . The computer system of claim 1 , wherein the FQSG field comprises a unique identifier.

4 . The computer system of claim 1 , wherein the encapsulated data packet is sent to the second functional domain via an overlay tunnel.

5 . The computer system of claim 4 , wherein the overlay tunnel comprises user datagram protocol (UDP) or transmission control protocol (TCP).

6 . The computer system of claim 1 , wherein the one or more cloud native security groups is defined based on a risk profile.

7 . The computer system of claim 1 , wherein the first functional domain is a source domain having a first Internet protocol (IP) subnet, and wherein the second functional domain is a destination domain having a second IP subnet.

8 . The computer system of claim 7 , wherein the first IP subnet and second IP subnet do not overlap.

9 . The computer system of claim 7 , wherein the first IP subnet and the second IP subnet at least partially overlap.

10 . The computer system of claim 1 , wherein the FQSG field is associated with an FQSG policy comprising a plurality of parameters.

11 . The computer system of claim 10 , wherein a parameter from the plurality of parameters in the FQSG policy is a destination parameter associated with the second functional domain.

12 . The computer system of claim 11 , wherein the destination parameter identifies a service associated with the second functional domain.

13 . The computer system of claim 11 , wherein the destination parameter identifies a functional instance associated with the second functional domain.

14 . The computer system of claim 10 , wherein a parameter from the plurality of parameters in the FQSG policy is a source parameter associated with the first functional domain.

15 . The computer system of claim 14 , wherein the source parameter identifies a service associated with the first functional domain.

16 . The computer system of claim 14 , wherein the source parameter identifies a functional instance associated with the first functional domain.

17 . The computer system of claim 14 , wherein the source parameter identifies foundation and control telemetry features associated with the first functional domain.

18 . The computer system of claim 10 , wherein the the FQSG field is associated with a second FQSG policy comprising a plurality of parameters, and wherein the second FQSG policy is to override a pre-existing first FQSG policy.

19 . A tangible, non-transitory computer-readable medium storing instructions that, when executed by a computer system, are configurable to cause the computer system to:

generate a data packet within a first functional domain;

determine that the data packet is destined for a second functional domain; and

in response to determining that the data packet is destined for the second functional domain:

encapsulate the data packet within a header comprising a fully qualified security group (FQSG) field associated with one or more cloud native security groups; and

send the encapsulated data packet to the second functional domain.

20 . A method, comprising:

generating a data packet within a first functional domain;

determining that the data packet is destined for a second functional domain; and

in response to determining that the data packet is destined for the second functional domain:

encapsulating the data packet within a header comprising a fully qualified security group (FQSG) field associated with one or more cloud native security groups; and

sending the encapsulated data packet to the second functional domain.

Assignments (2)
CHANGE OF NAME Recorded Nov 20, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069406/0699 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2022
From: PEMMARAJU, CHAITANYA
To: SALESFORCE.COM, INC.
Reel/Frame 061982/0034 →