IP Library Granted Patent US 12,238,099
Granted Patent B2
US 12,238,099 · App. 18/323,183 · Granted Feb 25, 2025

Systems and methods for generating contextual labels

Inventors: Stefan Olofsson (Dubai, AE); Ijsbrand Wijnands (Leuven, BE); Hendrikus G. P. Bosch (Aalsmeer, NL)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/0892H04L12/4641H04L63/0272H04L63/0823H04L63/083H04L63/168H04L61/2571
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,099
App. No.
18/323,183
Granted
Feb 25, 2025
Kind
B2
Abstract

In one embodiment, an apparatus includes one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors. The one or more computer-readable non-transitory storage media include instructions that, when executed by the one or more processors, cause the apparatus to perform operations including receiving a user credential from a remote access client within a network and communicating the user credential to an authentication, authorization and accounting (AAA) server within the network. The operations also include receiving a user attribute from the AAA server and generating a contextual label based on the user attribute. The contextual label includes routing instructions associated with traffic behavior within the network. The operations further include advertising a control message, which includes the contextual label, to the remote access client.

Claims (70)

1. An apparatus, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause the apparatus to perform operations comprising:

receiving a user credential from a remote access client over a network;

communicating the user credential to an authentication server;

receiving a user attribute from the authentication server;

generating one or more contextual instructions based on the user attribute and one or more application traffic policies, wherein:

the one or more contextual instructions comprises routing instructions; and

the routing instructions map one or more applications to a Virtual Private Network (VPN) routing/forwarding (VRF) instance; and

transmitting a message to the remote access client, wherein:

the message includes the one or more contextual instructions;

the one or more contextual instructions comprise a contextual label;

the remote access client uses the one or more contextual instructions to forward data packets associated with the one or more applications to the VPN VRF instance; and

the remote access client adds the contextual label to the data packets.

2. The apparatus of claim 1 , wherein the user attribute corresponds to a user group.

3. The apparatus of claim 1 , wherein the user attribute corresponds to a security group.

4. The apparatus of claim 1 , wherein the user attribute is associated with one or more of the following:

a security group;

a quality of service (QOS) profile; or

a Network Address Translation (NAT) profile.

5. The apparatus of claim 1 , wherein the user credential comprises a username and a password.

6. The apparatus of claim 1 , wherein the user credential identifies a user associated with the remote access client.

7. The apparatus of claim 1 , wherein the operations further comprise establishing a secure session with the remote access client.

8. The apparatus of claim 7 , wherein the secure session is a Secure Sockets Layer (SSL) connection.

9. The apparatus of claim 1 , wherein the operations further comprise:

determining that the user attribute has changed; and

withdrawing the one or more contextual instructions in response to determining that the user attribute has changed.

10. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving a user credential from a remote access client over a network;

communicating the user credential to an authentication server;

receiving a user attribute from the authentication server;

generating one or more contextual instructions based on the user attribute and one or more application traffic policies, wherein:

the one or more contextual instructions comprises routing instructions; and

the routing instructions map one or more applications to a Virtual Private Network (VPN) routing/forwarding (VRF) instance; and

transmitting a message to the remote access client, wherein:

the message includes the one or more contextual instructions;

the one or more contextual instructions comprise a contextual label;

the remote access client uses the one or more contextual instructions to forward data packets associated with the one or more applications to the VPN VRF instance; and

the remote access client adds the contextual label to the data packets.

11. The one or more computer-readable non-transitory storage media of claim 10 , wherein the user attribute corresponds to a user group.

12. The one or more computer-readable non-transitory storage media of claim 10 , wherein the user attribute corresponds to a security group.

13. The one or more computer-readable non-transitory storage media of claim 10 , wherein the user attribute is associated with one or more of the following:

a security group;

a quality of service (QOS) profile; or

a Network Address Translation (NAT) profile.

14. The one or more computer-readable non-transitory storage media of claim 10 , wherein the user credential comprises a username and a password.

15. The one or more computer-readable non-transitory storage media of claim 10 , wherein the user credential identifies a user associated with the remote access client.

16. The one or more computer-readable non-transitory storage media of claim 10 , wherein the operations further comprise establishing a secure session with the remote access client.

17. The one or more computer-readable non-transitory storage media of claim 16 , wherein the secure session is a Secure Sockets Layer (SSL) connection.

18. The one or more computer-readable non-transitory storage media of claim 10 , wherein the operations further comprise:

determining that the user attribute has changed; and

withdrawing the one or more contextual instructions in response to determining that the user attribute has changed.

19. A method, comprising:

receiving, at an apparatus, a user credential from a remote access client over a network;

communicating the user credential to an authentication server;

receiving a user attribute from the authentication server;

generating one or more contextual instructions based on the user attribute and one or more application traffic policies, wherein:

the one or more contextual instructions comprises routing instructions; and

the routing instructions map one or more applications to a Virtual Private Network (VPN) routing/forwarding (VRF) instance; and

transmitting a message to the remote access client, wherein:

the message includes the one or more contextual instructions;

the one or more contextual instructions comprise a contextual label;

the remote access client uses the one or more contextual instructions to forward data packets associated with the one or more applications to the VPN VRF instance; and

the remote access client adds the contextual label to the data packets.

20. The method of claim 19 , wherein the user attribute corresponds to a user group.

21. The method of claim 19 , wherein the user attribute corresponds to a security group.

22. The method of claim 19 , wherein the user credential comprises a username and a password.

23. The method of claim 19 , wherein the user credential identifies a user associated with the remote access client.

24. The method of claim 19 , wherein the method further comprises establishing a secure session with the remote access client.

25. The method of claim 24 , wherein the secure session is a Secure Sockets Layer (SSL) connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2023
From: OLOFSSON, STEFAN; WIJNANDS, IJSBRAND; BOSCH, HENDRIKUS G. P.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063754/0074 →
Continuity (3)
Continuation 16562867 · Sep 6, 2019
Provisional Application 62858191 · Jun 6, 2019
Related Publication 20230300134A1 · Sep 21, 2023
References Cited (61)
US 6339595B1 · Rekhter · 2002 [cited by applicant]
US 6680943B1 · Gibson · 2004 [cited by applicant]
US 7319699B1 · Provine · 2008 [cited by applicant]
US 7899918B1 · Potter et al. · 2011 [cited by applicant]
US 8095786B1 · Kshirsagar · 2012 [cited by applicant]
US 8339973B1 · Pichumani · 2012 [cited by examiner]
US 8572219B1 · Shigapov · 2013 [cited by applicant]
US 9038151B1 · Chua · 2015 [cited by applicant]
US 10042722B1 · Chigurupati · 2018 [cited by examiner]
US 10742548B1 · Sitaraman · 2020 [cited by examiner]
US 11296908B2 · Lin · 2022 [cited by applicant]
US 11374906B2 · Martz · 2022 [cited by applicant]
US 11418560B1 · Hinds · 2022 [cited by applicant]
US 11444872B2 · Mayya · 2022 [cited by applicant]
US 11977712B2 · Fleck · 2024 [cited by examiner]
US 11991051B2 · Frost · 2024 [cited by examiner]
US 12020089B2 · Malhotra · 2024 [cited by examiner]
US 12028740B2 · Mehta · 2024 [cited by examiner]
US 20040087304A1 · Buddhikot · 2004 [cited by applicant]
US 20040098622A1 · O'Neill · 2004 [cited by applicant]
US 20040221051A1 · Liong · 2004 [cited by examiner]
US 20050063411A1 · Wang · 2005 [cited by applicant]
US 20050091396A1 · Nilakantan · 2005 [cited by applicant]
US 20050102529A1 · Buddhikot · 2005 [cited by applicant]
US 20060059265A1 · Keronen · 2006 [cited by examiner]
US 20060104233A1 · Zhang · 2006 [cited by examiner]
US 20070150946A1 · Hanberger · 2007 [cited by examiner]
US 20080225708A1 · Lange · 2008 [cited by applicant]
US 20100063988A1 · Khalid · 2010 [cited by applicant]
US 20100309926A1 · Sun · 2010 [cited by examiner]
US 20140032758A1 · Barton · 2014 [cited by examiner]
US 20140033271A1 · Barton · 2014 [cited by examiner]
US 20140040979A1 · Barton · 2014 [cited by applicant]
US 20150043590A1 · Pan · 2015 [cited by applicant]
US 20150049631A1 · Heron · 2015 [cited by applicant]
US 20150085664A1 · Sachdev et al. · 2015 [cited by applicant]
US 20150121476A1 · Zheng · 2015 [cited by examiner]
US 20150271102A1 · Antich · 2015 [cited by examiner]
US 20150319092A1 · Ghai · 2015 [cited by applicant]
US 20150350912A1 · Head · 2015 [cited by applicant]
US 20160164728A1 · Chakrabarti · 2016 [cited by applicant]
US 20170064749A1 · Jain · 2017 [cited by applicant]
US 20170155724A1 · Haddad · 2017 [cited by applicant]
US 20170180374A1 · Gandhewar · 2017 [cited by applicant]
US 20170245310A1 · Chandramouli · 2017 [cited by applicant]
US 20170310686A1 · Ray · 2017 [cited by applicant]
US 20190052558A1 · Mehta · 2019 [cited by applicant]
US 20190349268A1 · Pai · 2019 [cited by examiner]
US 20210385736A1 · Zaks · 2021 [cited by applicant]
US 20220078122A1 · Hua · 2022 [cited by examiner]
CN 103580980A · 2014 [cited by applicant]
CN 108173981A · 2018 [cited by applicant]
CN 109495503A · 2019 [cited by applicant]
EP 2866389A1 · 2015 [cited by applicant]
WO 0124476A1 · 2001 [cited by applicant]
Patent Cooperation Treaty, International Search Report and Written Opinion, International Application No. PCT/US2020/034610, date of mailing Aug. 25, 2020, 9 pages. [cited by applicant]
Chinese Office Action corresponding to Chinese Patent Application No. CN202080048757.1, dated Nov. 14, 2022, 9 pages. [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2020/034610, mailed Dec. 16, 2021, 7 Pages. [cited by applicant]
Office Action—Notice of Intention to Grant for European Application No. 20744196.5, dated Aug. 14, 2023, 39 Pages. [cited by applicant]
Office Action for Indian Application No. 202147060829, dated Nov. 1, 2023, 8 Pages. [cited by applicant]
Office Action for Indian Application No. 202147060829, dated Jun. 20, 2024, 3 Pages. [cited by applicant]