IP Library Granted Patent US 12,368,757
Granted Patent B2
US 12,368,757 · App. 18/584,531 · Granted Jul 22, 2025

Intent-based enterprise security using dynamic learning of network segment prefixes

Inventors: Kaushik Dutta Majumdar (Bangalore, IN); FNU Nadeem (Fremont, CA); Shanmukh Uppuluri (Hyderabad, IN)
Assignee: Juniper Networks, Inc.
H04L63/20H04L63/0227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,757
App. No.
18/584,531
Granted
Jul 22, 2025
Kind
B2
Abstract

In an example, systems and methods enable automatic implementation of intent-based security policies in a network system, such as a software-defined wide area network system, in which network segment prefixes for network segments at one or more sites are dynamically learned. A service orchestrator controller translates an intent-based security policy input by a user to a security policy for a first site. The security policy for the first site specifies a segment-specific queryable resource associated with a second site. To implement the security policy, a device associated with the first site queries the segment-specific queryable resource associated with the second site, and updates one or more forwarding tables of the device with the network segment prefixes associated with one or more network segments at the second site received in response to the query. The first site forwards network traffic to the second site based on the updated forwarding tables.

Claims (53)

1. Non-transitory computer-readable storage media comprising encoded instructions for causing one or more processors to, at least one of collectively or individually:

translate an intent-based policy to a policy for a first site of a network system, the policy for the first site specifying a segment-specific queryable resource associated with a second site of the network system;

store network segment prefixes associated with one or more network segments at the second site, the network segment prefixes learned at the second site via a routing protocol; and

configure, based on the policy for the first site, a first device associated with the first site to query the segment-specific queryable resource associated with the second site to obtain, in response to the query, the network segment prefixes.

2. The non-transitory computer-readable storage media of claim 1 , further comprising instructions for causing the one or more processors to:

manage a plurality of segment-specific queryable resources, each associated with a different one of a plurality of sites in the network system; and

transmit, in response to a query to one of the plurality of segment-specific queryable resources, network segment prefixes associated with one or more network segments at a site corresponding to a queried segment-specific queryable resource, to one of a plurality of devices that issued the query.

3. The non-transitory computer-readable storage media of claim 2 , wherein the plurality of segment-specific queryable resources includes a plurality of segment-specific Uniform Resource Locators, the non-transitory computer-readable storage media further comprising instructions for causing the one or more processors to:

implement a feed server that manages queries to the plurality of segment-specific Uniform Resource Locators and, in response to a query, returns one or more network segment prefixes corresponding to a queried segment-specific Uniform Resource Locator stored in a database.

4. The non-transitory computer-readable storage media of claim 1 , wherein the network system comprises a plurality of sites comprising the first site and the second site, the non-transitory computer-readable storage media further comprising instructions for causing the one or more processors to:

receive notifications from one or more virtual route reflectors indicative of changes to network segment prefixes at one or more sites of the plurality of sites in the network system; and

store data indicative of the changes to the network segment prefixes at the one or more sites.

5. The non-transitory computer-readable storage media of claim 1 , wherein the intent-based policy specifies a workgroup corresponding to at least one of the one or more network segments at the second site.

6. The non-transitory computer-readable storage media of claim 1 , wherein:

the network system comprises a software-defined wide area network (SD-WAN),

the first device comprises a customer premises equipment (CPE) device,

the one or more network segments comprise Local Area Network (LAN) segments at the second site, and

the network segment prefixes comprise LAN segment prefixes corresponding to the LAN segments at the second site.

7. Non-transitory computer-readable storage media comprising encoded instructions for causing one or more processors of a computing system associated with a first site in a network system to, at least one of collectively or individually:

store a policy that specifies a segment-specific queryable resource associated with a second site in the network system, wherein the policy is translated from an intent-based policy specifying the segment-specific queryable resource associated with the second site;

query, in implementing the policy, the segment-specific queryable resource associated with the second site;

receive, in response to the query, network segment prefixes associated with one or more network segments at the second site;

update a forwarding table with the network segment prefixes received in response to the query; and

control, based on the updated forwarding table, network traffic between the first site and the second site.

8. The non-transitory computer-readable storage media of claim 7 , wherein the policy comprises a security policy, and wherein the segment-specific queryable resource associated with the second site is queryable via a segment-specific Uniform Resource Locator specified by the security policy.

9. The non-transitory computer-readable storage media of claim 7 , wherein the computing system is a first computing system, and wherein the intent-based policy is received by the first computing system based on input by a user at one of the first computing system associated with the first site, a second computing system associated with the second site, or a management interface associated with a network service orchestrator.

10. The non-transitory computer-readable storage media of claim 7 , wherein the intent-based policy specifies a user group corresponding to at least one of the one or more network segments at the second site.

11. The non-transitory computer-readable storage media of claim 7 wherein querying the segment-specific queryable resource associated with the second site further comprises periodically querying the segment-specific queryable resource for the second site at a user-configurable frequency.

12. The non-transitory computer-readable storage media of claim 7 , wherein the network segment prefixes associated with the one or more network segments at the second site are associated with a workgroup at the second site.

13. A device associated with a first site in a network system, the device comprising processing circuitry, wherein the device is configured to:

store a policy that specifies a segment-specific queryable resource associated with a second site in the network system, wherein the policy is translated from an intent-based policy specifying the segment-specific queryable resource associated with the second site;

query, in implementing the policy, the segment-specific queryable resource associated with the second site;

receive, in response to the query, network segment prefixes associated with one or more network segments at the second site;

update a forwarding table with the network segment prefixes received in response to the query; and

control, based on the updated forwarding table, network traffic between the first site and the second site.

14. The device of claim 13 , wherein the segment-specific queryable resource associated with the second site is queryable via a segment-specific Uniform Resource Locator specified by the policy, and wherein querying the segment-specific queryable resource associated with the second site further comprises periodically querying the segment-specific queryable resource for the second site at a user-configurable frequency.

15. The device of claim 13 , wherein the device is a first device, wherein the intent-based policy is received by the first device based on input by a user at one of the first device associated with the first site, a second device associated with the second site, or a management interface associated with a network service orchestrator, wherein the intent-based policy specifies a user group corresponding to at least one of the one or more network segments at the second site.

16. A device comprising processing circuitry and memory, the processing circuitry configured to:

translate an intent-based policy to a policy for a first site of a network system, the policy for the first site specifying a segment-specific queryable resource associated with a second site of the network system;

store network segment prefixes associated with one or more network segments at the second site, the network segment prefixes learned at the second site via a routing protocol; and

configure, based on the policy for the first site, a first device associated with the first site to query the segment-specific queryable resource associated with the second site to obtain, in response to the query, the network segment prefixes.

17. The device of claim 16 , wherein the processing circuitry is further configured to:

manage a plurality of segment-specific queryable resources, each associated with a different one of a plurality of sites in the network system; and

transmit, in response to a query to one of the plurality of segment-specific queryable resources, network segment prefixes associated with one or more network segments at a site corresponding to the queried segment-specific queryable resource, to one of a plurality of devices that issued the query.

18. The device of claim 17 , wherein the processing circuitry is further configured to:

receive notifications from one or more virtual route reflectors indicative of changes to network segment prefixes at one or more sites in the network system; and

store data indicative of the changes to the network segment prefixes at the one or more sites.

19. The device of claim 16 , wherein:

the network system comprises a software-defined wide area network (SD-WAN),

the first device comprises a customer premises equipment (CPE) device,

the one or more network segments comprise Local Area Network (LAN) segments at the second site, and

the network segment prefixes comprise LAN segment prefixes corresponding to the LAN segments at the second site.

20. The device of claim 16 , wherein the policy comprises a security policy, wherein the processing circuitry is configured to translate the intent-based policy to the security policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: MAJUMDAR, KAUSHIK DUTTA; NADEEM, FNU; UPPULURI, SHANMUKH
To: JUNIPER NETWORKS, INC.
Reel/Frame 071793/0560 →
Continuity (2)
Continuation 17301278 · Mar 30, 2021
Related Publication 20240195844A1 · Jun 13, 2024
References Cited (44)
US 7095738B1 · Desanti · 2006 [cited by applicant]
US 8879394B2 · Allan et al. · 2014 [cited by applicant]
US 9906402B2 · Ramachandran et al. · 2018 [cited by applicant]
US 10135652B2 · Rong et al. · 2018 [cited by applicant]
US 10594560B2 · Prasad · 2020 [cited by examiner]
US 10630509B2 · Bickhart et al. · 2020 [cited by applicant]
US 20060092949A1 · Thubert et al. · 2006 [cited by applicant]
US 20060179480A1 · Jardin et al. · 2006 [cited by applicant]
US 20070250642A1 · Thubert et al. · 2007 [cited by applicant]
US 20120117617A1 · Krupp et al. · 2012 [cited by applicant]
US 20130132468A1 · Azeez et al. · 2013 [cited by applicant]
US 20150381493A1 · Bansal et al. · 2015 [cited by applicant]
US 20170005923A1 · Babakian · 2017 [cited by applicant]
US 20170134274A1 · Araújo · 2017 [cited by applicant]
US 20170279717A1 · Bethers et al. · 2017 [cited by applicant]
US 20180331945A1 · Attarwala · 2018 [cited by applicant]
US 20180375802A1 · Wackerly · 2018 [cited by applicant]
US 20190297114A1 · Panchalingam et al. · 2019 [cited by applicant]
US 20200177550A1 · Valluri et al. · 2020 [cited by applicant]
US 20200344171A1 · Sharma · 2020 [cited by examiner]
US 20210021511A1 · James et al. · 2021 [cited by applicant]
US 20210044565A1 · Moreno et al. · 2021 [cited by applicant]
US 20210135995A1 · Saklikar et al. · 2021 [cited by applicant]
US 20220321604A1 · Majumdar et al. · 2022 [cited by applicant]
CN 1754350A · 2006 [cited by applicant]
CN 101019381A · 2007 [cited by applicant]
CN 102474499A · 2012 [cited by applicant]
CN 104718733A · 2015 [cited by applicant]
CN 105306333A · 2016 [cited by applicant]
CN 105659683A · 2016 [cited by applicant]
CN 106375027A · 2017 [cited by applicant]
CN 107078921A · 2017 [cited by applicant]
CN 110324226A · 2019 [cited by applicant]
WO 2017015667A1 · 2017 [cited by applicant]
A. Campanella, “Intent Based Network Operations,” 2019 Optical Fiber Communications Conference and Exhibition (OFC), San Diego, CA, USA, 2019, pp. 1-3. (Year: 2019). [cited by applicant]
Chai et al., “Key Technology in SD-WAN”, ZTE Technology Journal, vol. 25, No. 2, China Academy of Information and Communications Technology, Mar. 26, 2019, pp. 15-19, URL: https://www.zte.com.cn/content/dam/zte-site/res… [cited by applicant]
Extended Search Report from counterpart European Application No. 21181788.7 dated Dec. 10, 2021, 6 pp. [cited by applicant]
First Office Action and Search Report, and translation thereof, from counterpart Chinese Application No. 202110873600.9 dated Jan. 26, 2024, 8 pp. [cited by applicant]
Response to Communication pursuant to Rule 69 EPC dated Oct. 10, 2022, from counterpart European Application No. 21181788.7 filed Apr. 3, 2023, 10 pp. [cited by applicant]
Zhou et al., “EBoD—Building up the Open SD-WAN Network Service Platform”, ZTE Technology Journal, vol. 25, No. 2, China Mobile Research Institute, Apr. 8, 2019, pp. 20-27, URL: https://www.zte.com.cn/content/dam/zte-sit… [cited by applicant]
Prosecution History from U.S. Appl. No. 17/301,278, dated May 18, 2023 through Feb. 22, 2024, 41 pp. [cited by applicant]
Notice of Allowance from U.S. Appl. No. 17/301,278 dated May 17, 2024, 11 pp. [cited by applicant]
Notice of Intent to Grant from counterpart Chinese Application No. 202110873600.9 dated Mar. 25, 2024, 3 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 24190065.3 dated Jan. 30, 2025, 7 pp. [cited by applicant]