IP Library › Granted Patent US 12,225,057
Granted Patent B2
US 12,225,057 · App. 18/244,048 · Granted Feb 11, 2025

Resolving access policies between intent-based network architectures and cloud native architectures

Inventors: Thomas Szigeti (Vancouver, CA); David John Zacks (Vancouver, CA); Walter Hulick (Pearland, TX); Shannon McFarland (Parker, CO)
Assignee: Cisco Technology, Inc.
H04L63/20H04L63/0876H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,057
App. No.
18/244,048
Granted
Feb 11, 2025
Kind
B2
Abstract

Techniques for expressing, communicating, de-conflicting, and enforcing consistent access policies between an IBN architecture and a Cloud-Native architecture. Generally, network administrators and/or users of a Cloud-Native architecture and an IBN architecture express access policies independently for the two different domains or architectures. According to the techniques described herein, a Network Service Endpoint (NSE) of the Cloud-Native architecture may exchange access policies with a network device of the IBN architecture. After exchanging access policies, conflicts between the sets of access policies may be identified, such as differences between allowing or denying communications between microservices and/or applications. The conflicts may be de-conflicted using various types of heuristics or rules, such as always selecting an access policy of the IBN architecture when conflicts arise. After the access policies have been de-conflicted, the IBN architecture and Cloud-Native architecture may then apply consistent access policies for traffic and communications in their respective network architectures.

Claims (73)

1. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, at a containerized-application network, a first set of access policies that define whether first applications are allowed or restricted from communicating in the containerized-application network with second applications;

receiving, at the containerized-application network and from a network architecture, a second set of access policies that define whether the first applications are allowed or restricted from communicating in the network architecture with the second applications;

identifying a conflict between the first set of access policies and the second set of access policies;

obtaining data indicating a resolution for the conflict between the first set of access policies and the second set of access policies;

determining, based at least in part on the resolution, a third set of access policies that defines whether the first applications are allowed or restricted from communicating with the second applications in the containerized-application network and the network architecture; and

applying the third set of access policies to communications in the containerized-application network.

2. The system of claim 1 , further comprising:

a network service endpoint (NSE) associated with the containerized-application network; and

a network device associated with the network architecture,

the operations further comprising:

establishing an encrypted tunnel between the NSE and a network device associated with the network architecture,

wherein obtaining the second set of access policies includes receiving, at the NSE, the second set of access policies from the network device and over the encrypted tunnel.

3. The system of claim 1 , wherein:

obtaining the first set of access policies and obtaining the second set of access policies are performed at the containerized-application network; and

determining the resolution for the conflict includes receiving input from a network administrator associated with the containerized-application network, the input indicating the resolution.

4. The system of claim 1 , wherein:

obtaining the first set of access policies and obtaining the second set of access policies are performed at the network architecture; and

determining the resolution for the conflict includes receiving input from a network administrator associated with the network architecture, the input indicating the resolution.

5. The system of claim 1 , further comprising:

identifying a conflict rule indicating that conflicts between the second set of access policies of the containerized-application network and the first set of access policies of the network architecture are resolved by adopting the second set of access policies of the containerized-application network,

wherein the determining the resolution for the conflict includes selecting a first access policy of the first set of access policies over a second access policy of the second set of access policies that conflicts with the first access policy.

6. The system of claim 1 , further comprising:

identifying a conflict rule indicating that conflicts between access policies of the containerized-application network and access policies of the network architecture are resolved by adopting the access policies of the network architecture,

wherein the determining the resolution for the conflict includes selecting a second access policy of the second set of access policies over a first access policy of the first set of access policies that conflicts with the second access policy.

7. The system of claim 1 , further comprising:

detecting a change in at least one of the first set of access policies or the second set of access policies; and

determining whether the change resulted in a subsequent conflict between the first set of access policies and the second set of access policies.

8. A computer-implemented method comprising:

receiving, at a containerized-application network, a first set of access policies that define whether first applications are allowed or restricted from communicating in the containerized-application network with second applications;

receiving, at the containerized-application network and from a network architecture, a second set of access policies that define whether the first applications are allowed or restricted from communicating in the network architecture with the second applications;

identifying a conflict between the first set of access policies and the second set of access policies;

obtaining data indicating a resolution for the conflict between the first set of access policies and the second set of access policies;

determining, based at least in part on the resolution, a third set of access policies that defines whether the first applications are allowed or restricted from communicating with the second applications in the containerized-application network and the network architecture; and

applying the third set of access policies to communications in the containerized-application network.

9. The computer-implemented method of claim 8 , further comprising:

establishing, by a network service endpoint (NSE) of the containerized-application network, an encrypted tunnel with a network device associated with the network architecture; and

sending the first set of access policies to the network device using the encrypted tunnel.

10. The computer-implemented method of claim 8 , further comprising:

detecting a change in the first set of access policies; and

determining whether the change in the first set of access policies caused another conflict between the first set of access policies and the second set of access policies.

11. The computer-implemented method of claim 8 , further comprising:

converting at least one of the first set of access policies or the second set of access policies such the first set of access policies and the second set of access policies are in a common format,

wherein identifying the conflict is performed by comparing the first set of access policies and the second set of access policies once in the common format.

12. The computer-implemented method of claim 8 , wherein obtaining the data indicating the resolution includes receiving input that indicates the resolution from a network administrator associated with the containerized-application network.

13. The computer-implemented method of claim 8 , further comprising:

identifying a conflict rule indicating that conflicts between the second set of access policies of the containerized-application network and the first set of access policies of the network architecture are resolved by adopting the second set of access policies of the containerized-application network,

wherein the obtaining the data indicating the resolution for the conflict includes selecting a first access policy of the first set of access policies over a second access policy of the second set of access policies that conflicts with the first access policy.

14. The computer-implemented method of claim 8 , further comprising:

identifying a conflict rule indicating that conflicts between access policies of the containerized-application network and access policies of the network architecture are resolved by adopting the access policies of the network architecture,

wherein the obtaining the data indicating the resolution for the conflict selecting a second access policy of the second set of access policies.

15. A computer-implemented method comprising:

receiving, at a network architecture, a first set of access policies that define whether first applications are allowed or restricted from communicating in the network architecture with second applications;

receiving, at the network architecture and from a containerized-application network, a second set of access policies that define whether the first applications are allowed or restricted from communicating in the containerized-application network with the second applications;

identifying a conflict between the first set of access policies and the second set of access policies;

obtaining data indicating a resolution for the conflict between the first set of access policies and the second set of access policies;

determining, based at least in part on the resolution, a third set of access policies that defines whether the first applications are allowed or restricted from communicating with the second applications in the containerized-application network and the network architecture; and

applying the third set of access policies to communications in the network architecture.

16. The computer-implemented method of claim 15 , further comprising:

establishing an encrypted tunnel between a network device of the network architecture and a network service endpoint (NSE) of the containerized-application network; and

sending the first set of access policies to the NSE using the encrypted tunnel.

17. The computer-implemented method of claim 15 , further comprising:

detecting a change in the first set of access policies; and

determining whether the change in the first set of access policies caused another conflict between the first set of access policies and the second set of access policies.

18. The computer-implemented method of claim 15 , further comprising:

converting at least one of the first set of access policies or the second set of access policies such the first set of access policies and the second set of access policies are in a common format,

wherein identifying the conflict is performed by comparing the first set of access policies and the second set of access policies once in the common format.

19. The computer-implemented method of claim 15 , wherein obtaining the data indicating the resolution includes receiving input that indicates the resolution from a network administrator associated with the containerized-application network.

20. The computer-implemented method of claim 15 , further comprising:

identifying a conflict rule indicating that conflicts between the second set of access policies of the containerized-application network and the first set of access policies of the network architecture are resolved by adopting the second set of access policies of the containerized-application network,

wherein the obtaining the data indicating the resolution for the conflict includes selecting a first access policy of the first set of access policies over a second access policy of the second set of access policies that conflicts with the first access policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2023
From: SZIGETI, THOMAS; ZACKS, DAVID J.; HULICK, WALTER; MCFARLAND, SHANN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064849/0145 →
Continuity (2)
Continuation 17473306 · Sep 13, 2021
Related Publication 20230421610A1 · Dec 28, 2023
References Cited (14)
US 10944691B1 · Raut et al. · 2021 [cited by applicant]
US 10944793B2 · Nimmagadda et al. · 2021 [cited by applicant]
US 20180375802A1 · Wackerly et al. · 2018 [cited by applicant]
US 20200059370A1 · Abraham · 2020 [cited by applicant]
US 20200322273A1 · Natal et al. · 2020 [cited by applicant]
US 20220200863A1 · Kotalwar · 2022 [cited by applicant]
US 20230081708A1 · Szigeti · 2023 [cited by applicant]
Intent-Based End-to-End Network Service Orchestration System for Multi-Platforms. Rafiq. MDPI. (Year: 2020). [cited by examiner]
Software defined wireless sensor networks application opportunities for efficient network management: A survey. Modieginyane. Elsevier. (Year: 2018). [cited by examiner]
Energy-efficient auto-scaling of virtualized network function instances based on resource execution pattern> Mehmood. Elsevier. (Year: 2020). [cited by examiner]
Abhashkumar, et al., “Supporting Diverse Dynamic Intent-based Policies using Janus”, ACM, Dec. 2017, pp. 296-309. [cited by applicant]
“Driving Intent-Based Networking with AppFormix”, Juniper Networks, Jun. 1, 2021, 4 pages. [cited by applicant]
Rafiq, et al, “Intent-Based Slicing between Containers in SDN Overlay Network”, ResearchGate, Journal of Communications vol. 15, No. 3, Mar. 2020, 9 pages. [cited by applicant]
Zhang, et al., “Demo Abstract: An Intent Solver for Enabling Intent-based SDN”, IEEE, 2017, pp. 968-969. [cited by applicant]