IP Library Granted Patent US 12,301,418
Granted Patent B2
US 12,301,418 · App. 18/422,708 · Granted May 13, 2025

Automatic SAAS optimization

Inventors: Darren Russell Dukes (Ottawa, CA); Jeevan Sharma (Pleasanton, CA); Fabio R. Maino (Palo Alto, CA); Alberto Rodriguez-Natal (Leon, ES)
Assignee: Cisco Technology, Inc.
H04L41/0823H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,418
App. No.
18/422,708
Granted
May 13, 2025
Kind
B2
Abstract

Techniques for enabling a network access provider to make automatic Software as a Service (SaaS) optimization decisions. Among other things, the techniques may include determining a SaaS application that is being accessed by client endpoints via flows through a network access provider. The techniques may also include determining, based at least in part on a policy associated with the network access provider, whether to enable network optimizations for traffic through the network access provider to the SaaS application. Based at least in part on a determination that the network optimizations are to be enabled for the traffic to the SaaS application, the techniques may include installing a service definition associated with the SaaS application in a service policy database of the network access provider.

Claims (46)

1. A method comprising:

determining an application that is being accessed by a client endpoint via a network access provider;

determining, based at least in part on a policy associated with the network access provider, whether to enable a service for traffic that is flowing through the network access provider between the client endpoint and the application; and

based at least in part on a determination that the service is to be enabled for the traffic, providing a service definition to the network access provider for applying the service to the traffic.

2. The method of claim 1 , wherein determining the application that is being accessed comprises receiving an indication that the client endpoint is accessing the application.

3. The method of claim 1 , wherein determining the application that is being accessed comprises:

receiving, from the network access provider, flow data associated with the traffic through the network access provider; and

accessing a global repository to identify, based at least in part on the flow data, the application that is being accessed,

wherein the global repository is configured to store applications of multiple providers, the applications defined in the global repository by at least one of a domain name, an internet protocol (IP) address, a port, or a protocol.

4. The method of claim 3 , wherein the flow data includes information associated with the client endpoints and access points of the client endpoints, the information including at least one of flows associated with the client endpoints or the access points, DNS queries of the client endpoints, or application usage of the client endpoints.

5. The method of claim 1 , further comprising installing the service definition associated with the application based at least in part on utilizing, by a service handler associated with the network access provider, an application programming interface (API) exposed by the network access provider to install the service definition in a service policy database of the network access provider such that the network access provider steers traffic to the application via preferred paths or interfaces.

6. The method of claim 1 , wherein the policy indicates a threshold volume of traffic to a given application to enable the service, and wherein determining whether to enable the service for the traffic comprises determining whether a volume of the traffic through the network access provider to the application is greater than the threshold volume.

7. The method of claim 1 , wherein a service handler is associated with multiple different network access providers including the network access provider, the method further comprising:

determining, based at least in part on another policy associated with another network access provider, whether to enable the service for other traffic through the other network access provider to the application; and

based at least in part on a determination that the service is to be enabled for the other traffic to the application, providing the service definition associated with the application to the other network access provider for applying the service to the other traffic.

8. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions that, when executed, cause the one or more processors to perform operations comprising:

determining an application that is being accessed by a client endpoint via a network access provider;

determining, based at least in part on a policy associated with the network access provider, whether to enable a service for traffic through the network access provider between the client endpoint and the application; and

based at least in part on a determination that the service is to be enabled for the traffic, providing a service definition to the network access provider for applying the service to the traffic.

9. The system of claim 8 , wherein determining the application that is being accessed comprises receiving an indication that the client endpoint is accessing the application.

10. The system of claim 8 , wherein determining the application that is being accessed comprises:

receiving, from the network access provider, flow data associated with the traffic through the network access provider; and

accessing a global SaaS repository to identify, based at least in part on the flow data, the SaaS application being accessed,

wherein the global repository is configured to store applications of multiple providers, the applications defined in the global repository by at least one of a domain name, an internet protocol (IP) address, a port, or a protocol.

11. The system of claim 10 , wherein the flow data includes information associated with the client endpoints and access points of the client endpoints, the information including at least one of flows associated with the client endpoints or the access points, DNS queries of the client endpoints, or application usage of the client endpoints.

12. The system of claim 8 , further comprising installing the service definition associated with the application based at least in part on utilizing, by the one or more processors, an application programming interface (API) exposed by the network access provider to install the service definition in a service policy database associated with the network access provider such that the network access provider steers traffic to the application via preferred paths or interfaces.

13. The system of claim 8 , wherein the policy indicates a threshold volume of traffic to a given application to enable the service, and wherein determining whether to enable the service for the traffic comprises determining whether a volume of the traffic through the network access provider to the application is greater than the threshold volume.

14. The system of claim 8 , wherein a service handler is associated with multiple different network access providers including the network access provider, the operations further comprising:

determining, based at least in part on another policy associated with another network access provider, whether to enable the service for other traffic through the other network access provider to the application; and

based at least in part on a determination that the service is to be enabled for the other traffic to the application, providing the service definition associated with the application to the other network access provider for applying the service to the other traffic.

15. One or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform operations comprising:

determining an application that is being accessed by a client endpoint via a network access provider;

determining, based at least in part on a policy associated with the network access provider, whether to enable a service for traffic that is flowing through the network access provider between the client endpoint and the application; and

based at least in part on a determination that the service is to be enabled for the traffic, providing a service definition to the network access provider for applying the service to the traffic.

16. The one or more non-transitory computer-readable media of claim 15 , wherein determining the application that is being accessed comprises receiving an indication that the client endpoint is accessing the application.

17. The one or more non-transitory computer-readable media of claim 15 , wherein determining the application that is being accessed comprises:

receiving, from the network access provider, flow data associated with the traffic through the network access provider; and

accessing a global repository to identify, based at least in part on the flow data, the application being accessed,

wherein the global repository is configured to store applications of multiple providers, the applications defined in the global repository by at least one of a domain name, an internet protocol (IP) address, a port, or a protocol.

18. The one or more non-transitory computer-readable media of claim 17 , wherein the flow data includes information associated with the client endpoints and access points of the client endpoints, the information including at least one of flows associated with the client endpoints or the access points, DNS queries of the client endpoints, or application usage of the client endpoints.

19. The one or more non-transitory computer-readable media of claim 15 , further comprising installing the service definition associated with the application based at least in part on utilizing, by the one or more processors, an application programming interface (API) exposed by the network access provider to install the service definition in a service policy database of the network access provider such that the network access provider steers traffic to the application via preferred paths or interfaces.

20. The one or more non-transitory computer-readable media of claim 15 , the operations further comprising:

determining, based at least in part on another policy associated with another network access provider, whether to enable the service for other traffic through the other network access provider to the application; and

based at least in part on a determination that the service is to be enabled for the other traffic to the application, providing the service definition to the other network access provider for applying the service to the other traffic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2024
From: DUKES, DARREN RUSSELL; SHARMA, JEEVAN; MAINO, FABIO R.; RODRIGUEZ-NATAL, ALBERTO
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066250/0424 →
Continuity (2)
Continuation 18132830 · Apr 10, 2023
Related Publication 20240340220A1 · Oct 10, 2024
References Cited (16)
US 10250699B2 · Rao · 2019 [cited by examiner]
US 11218424B1 · Hanahan · 2022 [cited by examiner]
US 11483290B2 · Radhakrishnan · 2022 [cited by applicant]
US 11546301B2 · Mutnuru · 2023 [cited by applicant]
US 11765244B1 · Barclay · 2023 [cited by examiner]
US 20130151386A1 · Malaviya · 2013 [cited by examiner]
US 20130254335A1 · Inoue · 2013 [cited by examiner]
US 20160164924A1 · Rosenberg · 2016 [cited by applicant]
US 20160337474A1 · Rao · 2016 [cited by examiner]
US 20200389417A1 · Wetterwald · 2020 [cited by applicant]
US 20210117306A1 · Somashekar · 2021 [cited by applicant]
US 20230164029A1 · Mermoud · 2023 [cited by applicant]
US 20230259415A1 · Kairali · 2023 [cited by applicant]
US 20230300059A1 · Rodriguez Natal · 2023 [cited by applicant]
CN 102135883 · 2011 [cited by applicant]
KR 20130047070 · 2013 [cited by applicant]