IP Library › Granted Patent US 12,627,716
Granted Patent B2
US 12,627,716 · App. 18/750,053 · Granted May 12, 2026

Enabling security policies on cloud security provider based on SD-WAN context

Inventors: Shailendra Vinod Pardeshi (Dublin, CA); Venkatesh Nataraj (Union City, CA); Saravanan Radhakrishnan (Bangalore, IN); Pritam Baruah (Fremont, CA); Kannan Kumar (Tracy, CA)
Assignee: Cisco Technology, Inc.
H04L63/20H04L63/0272H04L63/029
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,716
App. No.
18/750,053
Granted
May 12, 2026
Kind
B2
Abstract

The present technology provides solutions for enabling software-defined wide area network (SD-WAN) policies on a cloud security provider. An example method includes collecting, by a SD-WAN controller, contextual data associated with at least one user account of a SD-WAN, wherein the contextual data includes at least one of a virtual private network (VPN) identifier or a security group tag; and transmitting, by the SD-WAN controller, the contextual data over a secure application programming interface to a cloud security engine of a cloud network for enforcement of security policies on the cloud network based on the contextual data. Systems and computer-readable media are also provided.

Claims (38)

1 . A method for enabling software-defined wide area network (SD-WAN) policies on a cloud security provider, the method comprising:

collecting, by a SD-WAN controller, contextual data associated with at least one user account of a SD-WAN, wherein the contextual data includes at least one of a virtual private network (VPN) identifier or a security group tag; and

transmitting, by the SD-WAN controller, the contextual data over a secure application programming interface to a cloud security engine of a cloud network for enforcement of security policies on the cloud network based on the contextual data.

2 . The method of claim 1 , further comprising:

setting, by the SD-WAN controller, the security policies for the SD-WAN, wherein the security policies are associated with the at least one user account; and

transmitting, by the SD-WAN controller, the security policies over the secure application programming interface to the cloud security engine for enforcement of the security policies on the cloud network based on the contextual data.

3 . The method of claim 1 , wherein the security group tag is associated with a user profile.

4 . The method of claim 1 , further comprising:

updating, by the SD-WAN controller, a database storing the contextual data; and

transmitting, by the SD-WAN controller, an update of the database over the secure application programming interface to the cloud security engine of the cloud network for enforcement of the security policies on the cloud network based on the contextual data.

5 . The method of claim 1 , wherein the contextual data is inserted into a metadata header of an Internet Protocol Security (IPsec) payload of a packet associated with the at least one user account as the at least one user account accesses the SD-WAN.

6 . The method of claim 5 , wherein the packet is received by the cloud security engine from a SD-WAN device associated with the at least one user account through a secure Internet gateway (SIG) tunnel established between the SD-WAN device and the cloud security engine.

7 . The method of claim 5 , wherein enforcement of the security policies includes the cloud security engine decrypting the packet to determine the contextual data.

8 . The method of claim 1 , wherein the security policies are defined using the contextual data.

9 . The method of claim 1 , wherein the virtual private network (VPN) identifier is associated with a location or a sub-location.

10 . A non-transitory computer-readable storage medium including instructions that, when executed by a processor, cause the processor to:

collect, by a SD-WAN controller, contextual data associated with at least one user account of a SD-WAN, wherein the contextual data includes at least one of a virtual private network (VPN) identifier or a security group tag; and

transmit, by the SD-WAN controller, the contextual data over a secure application programming interface to a cloud security engine of a cloud network for enforcement of security policies on the cloud network based on the contextual data.

11 . The non-transitory computer-readable storage medium of claim 10 , wherein the instructions further configure the processor to:

set, by the SD-WAN controller, the security policies for the SD-WAN, wherein the security policies are associated with the at least one user account; and

transmit, by the SD-WAN controller, the security policies over the secure application programming interface to the cloud security engine for enforcement of the security policies on the cloud network based on the contextual data.

12 . The non-transitory computer-readable storage medium of claim 10 , wherein the security group tag is associated with a user profile.

13 . The non-transitory computer-readable storage medium of claim 10 , wherein the instructions further configure the processor to:

update, by the SD-WAN controller, a database storing the contextual data; and

transmit, by the SD-WAN controller, an update of the database over the secure application programming interface to the cloud security engine of the cloud network for enforcement of the security policies on the cloud network based on the contextual data.

14 . The non-transitory computer-readable storage medium of claim 10 , wherein the contextual data is inserted into a metadata header of an Internet Protocol Security (IPsec) payload of a packet associated with the at least one user account as the at least one user account accesses the SD-WAN.

15 . The non-transitory computer-readable storage medium of claim 14 , wherein the packet is received by the cloud security engine from a SD-WAN device associated with the at least one user account through a secure Internet gateway (SIG) tunnel established between the SD-WAN device and the cloud security engine.

16 . The non-transitory computer-readable storage medium of claim 14 , wherein enforcement of the security policies includes the cloud security engine decrypting the packet to determine the contextual data.

17 . The non-transitory computer-readable storage medium of claim 10 , wherein the security policies are defined using the contextual data.

18 . The non-transitory computer-readable storage medium of claim 10 , wherein the virtual private network (VPN) identifier is associated with a location or a sub-location.

19 . A system comprising:

a processor; and

a memory storing instructions that, when executed by the processor, cause the processor to:

collect, by a SD-WAN controller, contextual data associated with at least one user account of a SD-WAN, wherein the contextual data includes at least one of a virtual private network (VPN) identifier or a security group tag; and

transmit, by the SD-WAN controller, the contextual data over a secure application programming interface to a cloud security engine of a cloud network for enforcement of security policies on the cloud network based on the contextual data.

20 . The system of claim 19 , wherein the instructions, when executed by the processor, further cause the processor to:

set, by the SD-WAN controller, the security policies for the SD-WAN, wherein the security policies are associated with the at least one user account; and

transmit, by the SD-WAN controller, the security policies over the secure application programming interface to the cloud security engine for enforcement of the security policies on the cloud network based on the contextual data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2024
From: PARDESHI, SHAILENDRA VINOD; NATARAJ, VENKATESH; RADHAKRISHNAN, SARAVANAN; BARUAH, PRITAM; KUMAR, KANNAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 067840/0900 →
Continuity (1)
Related Publication 20250392625A1 · Dec 25, 2025
References Cited (24)
US 12143423B2 · Oswal · 2024 [cited by examiner]
US 20080127327A1 · Carrasco · 2008 [cited by examiner]
US 20170026417A1 · Ermagan · 2017 [cited by examiner]
US 20200177503A1 · Hooda · 2020 [cited by examiner]
US 20200177550A1 · Valluri · 2020 [cited by examiner]
US 20200213360A1 · Ojha · 2020 [cited by examiner]
US 20200389457A1 · Olofsson · 2020 [cited by examiner]
US 20200389796A1 · Olofsson · 2020 [cited by examiner]
US 20210136871A1 · Bull · 2021 [cited by examiner]
US 20210160251A1 · Keisam · 2021 [cited by examiner]
US 20210185011A1 · Zhang et al. · 2021 [cited by applicant]
US 20210273913A1 · Bosch · 2021 [cited by examiner]
US 20210288881A1 · Zhang · 2021 [cited by applicant]
US 20210369309A1 · Olofsson · 2021 [cited by examiner]
US 20220209990A1 · Dillon · 2022 [cited by examiner]
US 20220217015A1 · Vuggrala · 2022 [cited by examiner]
US 20230025586A1 · Rolando · 2023 [cited by examiner]
US 20230026865A1 · Rolando et al. · 2023 [cited by applicant]
US 20240163313A1 · Qian · 2024 [cited by examiner]
WO WO2020247224A1 · 2020 [cited by examiner]
WO 2022216950A1 · 2022 [cited by applicant]
Aldeeb F.H.A., et al., “Software Defined Wide Area Network SD-WAN: Principles and Architecture”, Researchgate, 4th International African Conference on Current Studies, published on Nov. 4, 2021, pp. 1-12. [cited by applicant]
CISCO: “Cisco SD-WAN Cloud Scale Architecture”, CTI, Published on 2019, Nov. 4, 2020, 216 Pages. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2025/033750, mailed Sep. 10, 2025, 13 Pages. [cited by applicant]