IP Library Granted Patent US 10,917,438
Granted Patent B2
US 10,917,438 · App. 16/032,765 · Granted Feb 9, 2021

Secure publishing for policy updates

Inventors: Shashi Gandham (Fremont, CA); Navindra Yadav (Cupertino, CA); Janardhanan Radhakrishnan (Dublin, CA); Hoang-Nam Nguyen (San Jose, CA); Umesh Paul Mahindra (Cupertino, CA); Sunil Gupta (Milpitas, CA); Praneeth Vallem (San Jose, CA); Supreeth Rao (Cupertino, CA); Darshan Shrinath Purandare (Fremont, CA); Xuan Zou (Sunnyvale, CA); Girish Anant Kalele (Monte Sereno, CA); Jothi Prakash Prabakaran (Fremont, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/20H04L41/082H04L41/0806H04L41/0893H04L63/0823H04L43/10H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,917,438
App. No.
16/032,765
Granted
Feb 9, 2021
Kind
B2
Abstract

Aspects of the disclosed technology relate to ways to authenticate customer/subscriber access to a policy update stream. A process of the technology can include steps for instantiating a network monitoring device in response to a request, the request comprising one or more configuration parameters for the network monitoring device, and receiving a first certificate from the network monitoring device, wherein the first certificate is based on the one or more configuration parameters. In some aspects, the steps can further include sending the first certificate to a processing pipeline for authentication, wherein the processing pipeline is configured to authenticate the first certificate based on a second certificate received by the processing pipeline from the network monitoring device. Systems and machine readable media are also provided.

Claims (43)

1. A computer-implemented method for authenticating a subscriber to a policy stream, comprising:

creating a virtual instance of a network monitoring device that includes one or more computing clusters in response to a request from the subscriber, the request comprising one or more configuration parameters for the network monitoring device;

receiving a first certificate from the network monitoring device, wherein the first certificate is based on the one or more configuration parameters and identifies the subscriber;

sending the first certificate to a processing pipeline for authentication, wherein the processing pipeline is configured to authenticate the first certificate based on a second certificate, wherein the second certificate is received by the processing pipeline from the network monitoring device and the second certificate is generated by the network monitoring device; and

in response to the authentication being successful, subscribing the subscriber to the policy stream, the policy stream including one or more policy updates.

2. The computer-implemented method of claim 1 , further comprising:

receiving the one or more policy updates from the policy stream provided by the processing pipeline if the processing pipeline successfully authenticates the first certificate.

3. The computer-implemented method of claim 2 , further comprising:

decrypting the one or more policy updates received from the policy stream; and

implementing at least one change indicated by the one or more policy updates to an associated customer network.

4. The computer-implemented method of claim 1 , wherein the processing pipeline comprises a plurality of buffers arranged in a Directed Acyclic Graph (DAG) configuration.

5. The computer-implemented method of claim 1 , wherein the processing pipeline comprises a distributed messaging system.

6. The computer-implemented method of claim 1 , wherein the processing pipeline is further configured to authenticate the first certificate based on a third certificate provided by a third-party vendor.

7. The computer-implemented method of claim 6 , wherein the third certificate is integrated into product code in a software package provided by the third-party vendor.

8. A non-transitory computer-readable medium having computer readable instructions that, upon being executed by a processor, cause the processor to:

creating a virtual instance of a network monitoring device that includes one or more computing clusters in response to a request from a subscriber, the request comprising one or more configuration parameters for the network monitoring device;

receive a first certificate from the network monitoring device, wherein the first certificate is based on the one or more configuration parameters and identifies the subscriber;

send the first certificate to a processing pipeline for authentication, wherein the processing pipeline is configured to authenticate the first certificate based on a second certificate wherein the second certificate is received by the processing pipeline from the network monitoring device and the second certificate is generated by the network monitoring device; and

in response to the authentication being successful, subscribing the subscriber to the policy stream, the policy stream including one or more policy updates.

9. The non-transitory computer-readable medium of claim 8 , wherein the instructions are further configured to cause to processor to:

receive the one or more policy updates from the policy stream provided by the processing pipeline if the processing pipeline successfully authenticates the first certificate.

10. The non-transitory computer-readable medium of claim 9 , wherein the instructions are further configured to cause to processor to:

decrypting the one or more policy updates received from the policy stream; and

implementing at least one change indicated by the one or more policy updates to an associated customer network.

11. The non-transitory computer-readable medium of claim 8 , wherein the processing pipeline comprises a plurality of buffers arranged in a Directed Acyclic Graph (DAG) configuration.

12. The non-transitory computer-readable medium of claim 8 , wherein the processing pipeline comprises a distributed messaging system.

13. The non-transitory computer-readable medium of claim 8 , wherein the processing pipeline is further configured to authenticate the first certificate based on a third certificate provided by a third-party vendor.

14. The non-transitory computer-readable medium of claim 13 , wherein the third certificate is integrated into product code in a software package provided by the third-party vendor.

15. A system comprising:

a processor; and

memory including instructions that, upon being executed by the processor, cause the system to:

creating a virtual instance of a network monitoring device in response to a request from a subscriber, the request comprising one or more configuration parameters for the network monitoring device, wherein the network monitoring device includes one or more computing clusters;

receive a first certificate from the network monitoring device, wherein the first certificate is based on the one or more configuration parameters and identifies the subscriber;

send the first certificate to a processing pipeline for authentication, wherein the processing pipeline is configured to authenticate the first certificate based on a second certificate, wherein the second certificate is received by the processing pipeline from the network monitoring decice and the second certificate is generated by the network monitoring device; and

in response to the authentication being successful, subscribing the subscriber to the policy stream, the policy stream including one or more policy updates.

16. The system of claim 15 , wherein the instructions are further configured to cause to processor to:

receive the one or more policy updates from the policy stream provided by the processing pipeline if the processing pipeline successfully authenticates the first certificate.

17. The system of claim 16 , wherein the instructions are further configured to cause to processor to:

decrypting the one or more policy updates received from the policy stream; and

implementing at least one change indicated by the one or more policy updates to an associated customer network.

18. The system of claim 15 , wherein the processing pipeline comprises a plurality of buffers arranged in a Directed Acyclic Graph (DAG) configuration.

19. The system of claim 15 , wherein the processing pipeline comprises a messaging system.

20. The system of claim 15 , wherein the processing pipeline is further configured to authenticate the first certificate based on a third certificate provided by a third-party vendor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2018
From: GANDHAM, SHASHI; YADAV, NAVINDRA; RADHAKRISHNAN, JANARDHANAN; NGUYEN, HOANG-NAM; MAHINDRA, UMESH PAUL; GUPTA, SUNIL; VALLEM, PRANEETH; RAO, SUPREETH; PURANDARE, DARSHAN SHRINATH; ZOU, XUAN; KALELE, GIRISH ANANT; PRABAKARAN, JOTHI PRAKASH
To: CISCO TECHNOLOGY, INC.
Reel/Frame 046322/0626 →
Continuity (2)
Provisional Application 62621900 · Jan 25, 2018
Related Publication 20190230127A1 · Jul 25, 2019
Cited By (7)
US 12,348,519 US 12,355,770 US 12,423,418 US 12,432,242 US 12,603,921 US 12,670,246 US 12,695,793