IP Library › Granted Patent US 12,634,260
Granted Patent B2
US 12,634,260 · App. 18/113,248 · Granted May 19, 2026

Optimal data plane security and connectivity for secured connections

Inventors: Vincent E. Parla (North Hampton, NH); Cullen Frishman Jennings (Calgary, CA)
Assignee: Cisco Technology, Inc.
H04L63/0236H04L63/0281H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,260
App. No.
18/113,248
Granted
May 19, 2026
Kind
B2
Abstract

Techniques for creating an optimal and secure data plane based on network constraints. The techniques may include establishing an initial networking connection for a data flow between a client device and a resource such that data plane traffic of the data flow is routed through a relay node disposed between the client device and the resource. In some examples, the techniques may include determining, using a Session Traversal Utilities for Network Address Translators (STUN) server, an alternate networking connection for the data flow that bypasses the relay node. Based at least in part on a determination that the alternate networking connection is a more optimal path for the data plane traffic than the initial networking connection, the techniques may include causing the data plane traffic of the data flow to be routed over the alternate networking connection.

Claims (60)

1 . A method comprising:

establishing an initial networking connection for a data flow between a client device and a resource such that data plane traffic of the data flow is routed through a relay node disposed between the client device and the resource;

determining, using a Session Traversal Utilities for Network Address Translators (STUN) server, an alternate networking connection for the data flow that bypasses the relay node;

determining that the alternate networking connection is a direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection;

determining a comparison between performance characteristics of the alternate networking connection and performance characteristics of the initial networking connection;

determining, based at least in part on the comparison and the alternate networking connection being the direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection, that the alternate networking connection is a more optimal path for the data plane traffic than the initial networking connection; and

based at least in part on the determination that the alternate networking connection is the more optimal path for the data plane traffic than the initial networking connection, causing the data plane traffic of the data flow to be routed over the alternate networking connection.

2 . The method of claim 1 , wherein the alternate networking connection is determined using the STUN server while, simultaneously, the data plane traffic of the data flow is being sent between the client device and the resource via the initial networking connection.

3 . The method of claim 1 , wherein determining the alternate networking connection using the STUN server comprises determining an internet protocol (IP) address and a port associated with a pin-holed flow through one or more networking components or security components disposed between the client device and the resource.

4 . The method of claim 1 , further comprising determining whether a security policy allows for the alternate networking connection to be made between the client device and the resource, and wherein determining the alternate networking connection using the STUN server is based at least in part on a determination that the security policy allows for the alternate networking connection to be made.

5 . The method of claim 1 , further comprising causing the client device to store an indication that the alternate networking connection is the more optimal path for future connections to the resource.

6 . The method of claim 1 , further comprising determining whether an encryption protocol associated with the resource satisfies a security policy, and wherein determining the alternate networking connection using the STUN server is based at least in part on a determination that the encryption protocol satisfies the security policy.

7 . The method of claim 1 , further comprising:

determining that the alternate networking connection between the client device and the resource fails to meet a security policy requirement; and

causing the data plane traffic to flow through a security function associated with the resource when the data plane traffic is routed over the alternate networking connection.

8 . The method of claim 1 , further comprising refraining from causing the data plane traffic of the data flow to be routed over the alternate networking connection based at least in part on determining that the alternate networking connection is a less optimal path than the initial networking connection.

9 . The method of claim 1 , wherein the alternate networking connection is the more optimal path for the data plane traffic that is being sent from the resource to the client device and the initial networking connection is the more optimal path for the data plane traffic that is being sent to the resource from the client device, the method further comprising:

causing the data plane traffic that is being sent from the resource to the client device to be routed over the alternate networking connection; and

causing the data plane traffic that is being sent to the resource from the client device to be routed over the initial networking connection.

10 . The method of claim 1 , wherein determining, based at least in part on the comparison and one or more network conditions, that the alternate networking connection is the more optimal path for the data plane traffic than the initial networking connection is based on at least one of:

an increase in an amount of available bandwidth for the data flow;

a decrease in a cost associated with the data flow;

a decrease in a latency associated with the data flow;

a decrease in an amount of compute associated with sending the data plane traffic; or

achieving a more uniform distribution of resources or resource utilization.

11 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions that, when executed, cause the one or more processors to perform operations comprising:

establishing an initial networking connection for a data flow between a client device and a resource such that data plane traffic of the data flow is routed through a relay node disposed between the client device and the resource;

determining, using a Session Traversal Utilities for Network Address Translators (STUN) server, an alternate networking connection for the data flow between the client device and the resource that bypasses the relay node;

determining that the alternate networking connection is a direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection;

determining a comparison between performance characteristics of the alternate networking connection and performance characteristics of the initial networking connection;

determining, based at least in part on the comparison and the alternate networking connection being the direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection, whether the alternate networking connection is a more optimal path for the data plane traffic than the initial networking connection; and

based at least in part on determining that the alternate networking connection is the more optimal path, causing the data plane traffic of the data flow to be routed over the alternate networking connection.

12 . The system of claim 11 , wherein the alternate networking connection is determined using the STUN server while, simultaneously, the data plane traffic of the data flow is being sent between the client device and the resource via the initial networking connection.

13 . The system of claim 11 , wherein determining the alternate networking connection using the STUN server comprises determining an internet protocol (IP) address and a port associated with a pin-holed flow through one or more network security components disposed between the client device and the resource.

14 . The system of claim 11 , the operations further comprising determining whether a security policy allows for the alternate networking connection to be made between the client device and the resource, and wherein determining the alternate networking connection using the STUN server is based at least in part on a determination that the security policy allows for the alternate networking connection to be made.

15 . The system of claim 11 , the operations further comprising determining whether an encryption protocol associated with the resource satisfies a security policy, and wherein determining the alternate networking connection using the STUN server is based at least in part on a determination that the encryption protocol satisfies the security policy.

16 . The system of claim 11 , the operations further comprising:

determining that the alternate networking connection between the client device and the resource fails to meet a security policy requirement; and

causing the data plane traffic to flow through a security function associated with the resource when the data plane traffic is routed over the alternate networking connection.

17 . One or more non-transitory computer-readable media storing instructions that, when executed, cause one or more computing devices to perform operations comprising:

establishing an initial networking connection for a data flow between a client device and a resource such that data plane traffic of the data flow is routed through a relay node disposed between the client device and the resource;

determining, using a Session Traversal Utilities for Network Address Translators (STUN) server, an alternate networking connection for the data flow between the client device and the resource that bypasses the relay node;

determining that the alternate networking connection is a direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection;

determining a comparison between performance characteristics of the alternate networking connection and performance characteristics of the initial networking connection;

determining, based at least in part on the comparison and the alternate networking connection being the direct networking connection between the client device and the resource instead of the initial networking connection being the direct network connection, whether the alternate networking connection is a more optimal path for the data plane traffic than the initial networking connection; and

based at least in part on determining that the alternate networking connection is the more optimal path, causing the data plane traffic of the data flow to be routed over the alternate networking connection.

18 . The method of claim 1 , wherein the initial networking connection is a Zero Trust Network Access (ZTNA) networking connection, and the alternate networking connection is a first alternate networking connection, the method further comprising:

determining, using the STUN server, a second alternate networking connection for the data flow that bypasses the relay node;

determining that the second alternate networking connection is the more optimal path for the data plane traffic than the ZTNA networking connection, the second alternate networking connection being at least one of a proxied networking connection or a proxy and relay networking connection that passes through a different relay node; and

based at least in part on the determination that the second alternate networking connection is the more optimal path, causing the data plane traffic to be routed over the second alternate networking connection.

19 . The system of claim 11 , wherein the initial networking connection is a Zero Trust Network Access (ZTNA) networking connection, and the alternate networking connection is a first alternate networking connection, the operations further comprising:

determining, using the STUN server, a second alternate networking connection for the data flow that bypasses the relay node;

determining that the second alternate networking connection is the more optimal path for the data plane traffic than the ZTNA networking connection, the second alternate networking connection being at least one of a proxied networking connection or a proxy and relay networking connection that passes through a different relay node; and

based at least in part on the determination that the second alternate networking connection is the more optimal path, causing the data plane traffic to be routed over the second alternate networking connection.

20 . The one or more non-transitory computer-readable media of claim 17 , wherein the initial networking connection is a Zero Trust Network Access (ZTNA) networking connection, and the alternate networking connection is a first alternate networking connection, the operations further comprising:

determining, using the STUN server, a second alternate networking connection for the data flow that bypasses the relay node;

determining that the second alternate networking connection is the more optimal path for the data plane traffic than the ZTNA networking connection, the second alternate networking connection being at least one of a proxied networking connection or a proxy and relay networking connection that passes through a different relay node; and

based at least in part on the determination that the second alternate networking connection is the more optimal path, causing the data plane traffic to be routed over the second alternate networking connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2023
From: PARLA, VINCENT E.; JENNINGS, CULLEN FRISHMAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062841/0354 →
Continuity (2)
Provisional Application 63341557 · May 13, 2022
Related Publication 20230370424A1 · Nov 16, 2023
References Cited (41)
US 6778502B2 · Ricciulli · 2004 [cited by examiner]
US 9853885B1 · Tillotson · 2017 [cited by examiner]
US 9871720B1 · Tillotson · 2018 [cited by examiner]
US 9986411B1 · Stamatakis · 2018 [cited by examiner]
US 10313197B1 · Stamatakis · 2019 [cited by examiner]
US 10630579B1 · Plenderleith · 2020 [cited by examiner]
US 11570514B2 · Lee · 2023 [cited by examiner]
US 11750568B1 · Rasekh · 2023 [cited by examiner]
US 20050254430A1 · Clark · 2005 [cited by examiner]
US 20070094273A1 · Fritsch · 2007 [cited by applicant]
US 20070259653A1 · Tang · 2007 [cited by examiner]
US 20080080532A1 · O'Sullivan et al. · 2008 [cited by applicant]
US 20100138649A1 · Rossi · 2010 [cited by applicant]
US 20110063976A1 · Birk · 2011 [cited by examiner]
US 20110314250A1 · Innan · 2011 [cited by examiner]
US 20170093625A1 · Pera · 2017 [cited by examiner]
US 20170195132A1 · Burgio · 2017 [cited by examiner]
US 20170317933A1 · Oran · 2017 [cited by examiner]
US 20180124123A1 · Moore et al. · 2018 [cited by applicant]
US 20190342362A1 · Vysotsky · 2019 [cited by examiner]
US 20200116441A1 · Rasmussen · 2020 [cited by examiner]
US 20200389426A1 · Enguehard · 2020 [cited by applicant]
US 20210014285A1 · Maino · 2021 [cited by applicant]
US 20210314297A1 · Peterson · 2021 [cited by examiner]
US 20220015793A1 · Li · 2022 [cited by examiner]
US 20220038440A1 · Boynton · 2022 [cited by applicant]
US 20220201041A1 · Keiser, Jr · 2022 [cited by examiner]
US 20220294828A1 · Keiser, Jr. · 2022 [cited by examiner]
US 20230018210A1 · Keiser, Jr. · 2023 [cited by examiner]
US 20230093942A1 · Koikara · 2023 [cited by examiner]
US 20230231768A1 · Vysotsky · 2023 [cited by examiner]
US 20250080501A1 · Katyal · 2025 [cited by examiner]
US 20250080504A1 · Obulareddy · 2025 [cited by examiner]
CA 2567897C · 2012 [cited by examiner]
EP 3284287B1 · 2019 [cited by examiner]
EP 4521688A1 · 2025 [cited by examiner]
Wang, L., Ma, H., Li, Z., Pei, J., Hu, T., & Zhang, J. (2022). ZbSR: A Data Plane Security Model of SR-BE/TE based on Zero-Trust Architecture. [cited by applicant]
The PCT Search Report and Written Opinion mailed Sep. 25, 2023 for PCT application No. PCT/US23/21929, 14 pages. [cited by applicant]
Shore, et all, “Zero Trust: The What, How, Why, and When”, Cybersecurity and Trust, Oct. 22, 2021, Published by IEEE Computer Society, 10 pages. [cited by applicant]
Keranen A., et al., “Interactive Connectivity Establishment (ICE): A Protocol for Network Address Translator (NAT) Traversal”, Internet Engineering Task Force (IETF), RFC: 8445, Jul. 2018, pp. 1-100. [cited by applicant]
Office Action for Indian Application No. 202427086603, dated Feb. 9, 2026, 9 Pages. [cited by applicant]