IP Library › Granted Patent US 11,962,469
Granted Patent B2
US 11,962,469 · App. 17/172,820 · Granted Apr 16, 2024

Identifying devices and device intents in an IoT network

Inventors: Laurent Jean Charles Hausermann (Lyons, FR); Maik Guenter Seewald (Nuremberg, DE); André Guérard (Saint Etienne, FR); Ruben Gerald Lobo (Raleigh, NC); Daniel R. Behrens (Chardon, OH); Gulian Lorini (Lyons, FR); Laetitia Pot (Lyons, FR)
Assignee: Cisco Technology, Inc.
H04L41/12G06N20/00G16Y20/10G16Y20/20G16Y40/10H04L41/0853H04L61/2567
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,962,469
App. No.
17/172,820
Granted
Apr 16, 2024
Kind
B2
Abstract

According to one or more embodiments of the disclosure, an asset inventory service executed by one or more devices receives telemetry data collected passively by a sensor application regarding a node in a network. The asset inventory service requests, after receiving the telemetry data, that the sensor application perform active discovery of nodes in the network. The asset inventory service receives active discovery data collected by the sensor application via active discovery of nodes in the network. The asset inventory service generates, based on the telemetry data and the active discovery data, an identity profile for the node.

Claims (30)

1. A method comprising:

receiving, at an asset inventory service executed by one or more devices, telemetry data collected passively by a sensor application regarding a node in a network, wherein the sensor application passively collects the telemetry data by performing deep packet inspection (DPI) on traffic flowing through networking equipment located on a different side of a Network Address Translation (NAT) boundary defined by a NAT layer in the network than that of the asset inventory service;

requesting, by the asset inventory service and after receiving the telemetry data, that the sensor application perform active discovery of nodes in the network by broadcasting a hello request to the nodes using a communication protocol detected from the telemetry data passively collected by the sensor application;

receiving, at the asset inventory service, active discovery data collected by the sensor application via the active discovery of the nodes in the network; and

generating, by the asset inventory service and based on the telemetry data, the active discovery data, and engineering and configuration data associated with the node, an identity profile for the node that comprises two or more unique IP address-MAC address pairs associated with the node, wherein the telemetry data and the active discovery data indicate two or more different IP addresses or two or more different MAC addresses for the node, further wherein the engineering and configuration data comprises at least one of: a General Station Description (GSD) file, an Electronic Data Sheet (EDS) file, or a Substation Configuration Language (SCL) file.

2. The method as in claim 1 , wherein the sensor application and the nodes actively discovered by the sensor application are located on the different side of the NAT boundary than that of the asset inventory service.

3. The method as in claim 1 , wherein the networking equipment comprises at least one of: a switch, a router, or a gateway.

4. The method as in claim 1 , wherein, in response to the hello request, at least one of the nodes sends information about itself to the sensor application, wherein the active discovery data received by the asset inventory service comprises the information.

5. The method as in claim 1 , wherein at least one of the two or more different IP addresses or two or more different MAC addresses is reused elsewhere in the network.

6. The method as in claim 1 , wherein the node comprises a remote terminal unit, programmable logic controller, or a substation intelligent electronic device.

7. The method as in claim 1 , further comprising:

assigning a policy to the node, based on its identity profile.

8. An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

receive telemetry data collected passively by a sensor application regarding a node in a network, wherein the sensor application passively collects the telemetry data by performing deep packet inspection (DPI) on traffic flowing through networking equipment located on a different side of a Network Address Translation (NAT) boundary defined by a NAT layer in the network than that of the apparatus;

request, after receiving the telemetry data, that the sensor application perform active discovery of nodes in the network by broadcasting a hello request to the nodes using a communication protocol detected from the telemetry data passively collected by the sensor application;

receive active discovery data collected by the sensor application via the active discovery of the nodes in the network; and

generate, based on the telemetry data, the active discovery data, and engineering and configuration data associated with the node, an identity profile for the node that comprises two or more unique IP address-MAC address pairs associated with the node, wherein the telemetry data and the active discovery data indicate two or more different IP addresses or two or more different MAC addresses for the node, further wherein engineering and configuration data comprises at least one of: a General Station Description (GSD) file, an Electronic Data Sheet (EDS) file, or a Substation Configuration Language (SCL) file.

9. The apparatus as in claim 8 wherein the sensor application and the nodes actively discovered by the sensor application are located on the different side of the NAT boundary than that of the apparatus.

10. The apparatus as in claim 8 , wherein the networking equipment comprises at least one of: a switch, a router, or a gateway.

11. The apparatus as in claim 8 , wherein, in response to the hello request, at least one of the nodes sends information about itself to the sensor application, wherein the active discovery data received by the apparatus comprises the information.

12. The apparatus as in claim 8 , wherein at least one of the two or more different IP addresses or two or more different MAC addresses is reused elsewhere in the network.

13. The apparatus as in claim 8 , wherein the node comprises a remote terminal unit, programmable logic controller, or a substation intelligent electronic device.

14. A tangible, non-transitory, computer-readable medium storing program instructions that cause an asset inventory service executed by one or more devices to perform a process comprising:

receiving, at the asset inventory service, telemetry data collected passively by a sensor application regarding a node in a network, wherein the sensor application passively collects the telemetry data by performing deep packet inspection (DPI) on traffic flowing through networking equipment located on a different side of a Network Address Translation (NAT) boundary defined by a NAT layer in the network than that of the asset inventory service;

requesting, by the asset inventory service and after receiving the telemetry data, that the sensor application perform active discovery of nodes in the network by broadcasting a hello request to the nodes using a communication protocol detected from the telemetry data passively collected by the sensor application;

receiving, at the asset inventory service, active discovery data collected by the sensor application via the active discovery of the nodes in the network; and

generating, by the asset inventory service and based on the telemetry data, the active discovery data, and engineering and configuration data associated with the node, an identity profile for the node that comprises two or more unique IP address-MAC address pairs associated with the node, wherein the telemetry data and the active discovery data indicate two or more different IP addresses or two or more different MAC addresses for the node, further wherein the engineering and configuration data comprises at least one of: a General Station Description (GSD) file, an Electronic Data Sheet (EDS) file, or a Substation Configuration Language (SCL) file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2021
From: HAUSERMANN, LAURENT JEAN CHARLES; SEEWALD, MAIK GUENTER; GUÉRARD, ANDRÉ; LOBO, RUBEN GERALD; BEHRENS, DANIEL R.; LORINI, GULIAN; POT, LAETITIA
To: CISCO TECHNOLOGY, INC.
Reel/Frame 055218/0220 →
Continuity (1)
Related Publication 20220255805A1 · Aug 11, 2022