IP Library › Granted Patent US 12,255,910
Granted Patent B2
US 12,255,910 · App. 18/462,025 · Granted Mar 18, 2025

Service plane optimizations with learning-enabled flow identification

Inventors: Ramanathan Subramanian (Milpitas, CA); Jeslin Antony Puthenparambil (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L63/1425H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,910
App. No.
18/462,025
Granted
Mar 18, 2025
Kind
B2
Abstract

The disclosed technology relates to a process for optimizing data flow within a computer network. The technology utilizes shared memory and machine learning logic to improve the efficiency of how computing resources are used during a transmission of data packets in the computer network. The shared memory is implemented during the transmission of data packets between the data plane and the service plane so that the copying of data packets after the data packets have been received and processed by an application is not necessary. The machine learning logic is implemented during the processing of the data packets in order to adjust a frequency or extent that the data packets (and corresponding source of the data packets) need to be evaluated to ensure that malicious content is not being transmitted across the computer network.

Claims (38)

1. A method for optimizing data flow in a computer network, the method comprising:

storing data plane identifying information about a data packet into shared memory to yield stored identifying information, wherein the shared memory is accessible only between a data plane of the computer network where the data packet originates and a service plane of the computer network associated with an application hosted on the computer network; and

matching the stored identifying information in the shared memory with the data plane identifying information to identify the data packet.

2. The method of claim 1 , wherein the data plane identifying information is stored in a ring buffer associated with the shared memory.

3. The method of claim 1 , further comprising:

calculating a confidence level using machine learning logic, wherein the confidence level is calculated based on the data packet; and

assigning a source of the data packet with the confidence level, wherein the confidence level identifies a level of trustworthiness of the source and its corresponding data packets.

4. The method of claim 3 , wherein the confidence level defines a frequency of performing subsequent evaluations on other data packets associated with the source, wherein the frequency identifies a period of time until a next evaluation.

5. The method of claim 4 , wherein the frequency also identifies a number of data packets that are transmitted without evaluations until the next evaluation.

6. The method of claim 3 , wherein the confidence level defines an extent of evaluating other data packets associated with the source, wherein the extent identifies a number of data packets that are evaluated during a next evaluation.

7. A non-transitory computer-readable medium comprising instructions that optimize data flow in a computer network, the instructions, when executed by a computing system, cause the computing system to perform operations comprising:

storing data plane identifying information about a data packet into shared memory to yield stored identifying information, wherein the shared memory is accessible only between a data plane of the computer network where the data packet originates and a service plane of the computer network associated with an application hosted on the computer network; and

matching the stored identifying information in the shared memory with data plane identifying information to identify the data packet.

8. The non-transitory computer-readable medium of claim 7 , wherein the non-transitory computer-readable medium stores additional instructions which, when executed by the computing system, cause the computing system to perform operations comprising:

storing the data plane identifying information in a ring buffer associated with the shared memory.

9. The non-transitory computer-readable medium of claim 7 , wherein the non-transitory computer-readable medium stores additional instructions which, when executed by the computing system, cause the computing system to perform operations comprising:

calculating a confidence level using machine learning logic, wherein the confidence level is calculated based on the data packet; and

assigning a source of the data packet with the confidence level, wherein the confidence level identifies a level of trustworthiness of the source and its corresponding data packets.

10. The non-transitory computer-readable medium of claim 9 , wherein the confidence level defines a frequency of performing subsequent evaluations on other data packets associated with the source, wherein the frequency identifies a period of time until a next evaluation.

11. The non-transitory computer-readable medium of claim 10 , wherein the frequency also identifies a number of data packets that are transmitted without evaluations until the next evaluation.

12. The non-transitory computer-readable medium of claim 9 , wherein the confidence level defines an extent of evaluating other data packets associated with the source, wherein the extent identifies a number of data packets that are evaluated during a next evaluation.

13. A system optimizing data flow in a computer network, the system comprising:

a processor; and

a memory storing instructions that, when executed by the system, cause the system to perform operations comprising:

storing data plane identifying information about a data packet being transmitted in a computer network into shared memory to yield stored identifying information, wherein the shared memory is accessible only between a data plane of the computer network where the data packet originates and a service plane of the computer network associated with an application hosted on the computer network; and

matching the stored identifying information in the shared memory with the data plane identifying information to identify the data packet.

14. The system of claim 13 , wherein the memory stores additional instructions that, when executed by the system, cause the system to perform operations comprising:

storing the data plane identifying information in a ring buffer associated with the shared memory.

15. The system of claim 13 , wherein the memory stores further instructions that, when executed by the system, cause the system to perform operations comprising:

calculating a confidence level using machine learning logic, wherein the confidence level is calculated based on the data packet; and

assigning a source of the data packet with the confidence level, wherein the confidence level identifies a level of trustworthiness of the source and its corresponding data packets.

16. The system of claim 15 , wherein the confidence level defines a frequency of performing subsequent evaluations on other data packets associated with the source, wherein the frequency identifies a period of time until a next evaluation.

17. The system of claim 16 , wherein the frequency also identifies a number of data packets that are transmitted without evaluations until the next evaluation.

18. The system of claim 15 , wherein the confidence level defines an extent of evaluating other data packets associated with the source, wherein the extent identifies a number of data packets that are evaluated during a next evaluation.

19. The system of claim 15 , wherein the memory stores additional instructions that, when executed by the system, cause the system to perform operations comprising:

evaluating the data packet at the application by determining whether the data packet includes malicious content.

20. The system of claim 15 , wherein the memory stores further instructions that, when executed by the system, cause the system to perform operations comprising:

generating a verdict based on an evaluation of the data packet, wherein the verdict instructs the computer network whether the data packet is to be forwarded or dropped.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2023
From: SUBRAMANIAN, RAMANATHAN; PUTHENPARAMBIL, JESLIN ANTONY
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064816/0478 →
Continuity (3)
Continuation 17592160 · Feb 3, 2022
Continuation 16534987 · Aug 7, 2019
Related Publication 20230421594A1 · Dec 28, 2023
References Cited (21)
US 8339959B1 · Moisand et al. · 2012 [cited by applicant]
US 8819115B2 · Rajan · 2014 [cited by examiner]
US 9229847B1 · McKown · 2016 [cited by examiner]
US 9240976B1 · Murchison · 2016 [cited by applicant]
US 9246825B2 · Jilani et al. · 2016 [cited by applicant]
US 9652612B2 · Brech et al. · 2017 [cited by applicant]
US 10581902B1 · Krishtal · 2020 [cited by examiner]
US 10764249B1 · Kommula et al. · 2020 [cited by applicant]
US 20040172557A1 · Nakae · 2004 [cited by examiner]
US 20100202466A1 · Eswaran · 2010 [cited by applicant]
US 20110209215A1 · Kabbara · 2011 [cited by examiner]
US 20120227109A1 · Dimuro · 2012 [cited by applicant]
US 20150156122A1 · Singh et al. · 2015 [cited by applicant]
US 20160044054A1 · Stiansen et al. · 2016 [cited by applicant]
US 20160173371A1 · Bays · 2016 [cited by applicant]
US 20170168985A1 · Hwang · 2017 [cited by examiner]
US 20180198827A1 · Eifler · 2018 [cited by examiner]
US 20180278647A1 · Gabaev · 2018 [cited by examiner]
US 20190141536A1 · Bachmutsky et al. · 2019 [cited by applicant]
US 20200296011A1 · Jain et al. · 2020 [cited by applicant]
US 20200366578A1 · Punj et al. · 2020 [cited by applicant]