IP Library Granted Patent US 12,413,650
Granted Patent B2
US 12,413,650 · App. 18/670,513 · Granted Sep 9, 2025

Routing application control and data-plane traffic in support of cloud-native applications

Inventors: Vincent Parla (North Hampton, NH); Kyle Andrew Donald Mestery (Woodbury, MN)
Assignee: Cisco Technology, Inc.
H04L67/63H04L45/74H04L47/2475H04L67/1001
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,650
App. No.
18/670,513
Granted
Sep 9, 2025
Kind
B2
Abstract

Techniques for using computer networking protocol extensions to route control-plane traffic and data-plane traffic associated with a common application are described herein. For instance, a traffic flow associated with an application may be established such that control-plane traffic is sent to a control-plane node associated with the application and data-plane traffic is sent to a data-plane node associated with the application. When a client device sends an authentication request to connect to the application, the control-plane node may send an indication of a hostname to be used by the client device to send data-plane traffic to the data-node. As such, when a packet including the hostname corresponding with the data-plane node is received, the packet may be forwarded to the data-plane node.

Claims (37)

1. A method comprising:

receiving traffic from a client device, the traffic including an identifier associated with a service hosted on a cloud-computing system, the identifier being associated with an encryption protocol;

determining, based at least in part on the identifier, whether the traffic is control plane traffic associated with the service or data plane traffic associated with the service; and

at least one of:

sending the traffic to a control plane node associated with the service based at least in part on determining that the traffic is the control plane traffic, or

sending the traffic to a data plane node associated with the service based at least in part on determining that the traffic is the data plane traffic.

2. The method of claim 1 , wherein the traffic is received via a secure communication flow between the client device and the cloud-computing system.

3. The method of claim 2 , wherein the secure communication flow is at least one of a Zero Trust Network Access (ZTNA) flow or a virtual private network (VPN) flow between the client device and the cloud-computing system.

4. The method of claim 1 , wherein the traffic is encrypted according to an encryption protocol, the identifier included in an extension of the encryption protocol.

5. The method of claim 4 , wherein the encryption protocol is at least one of Transport Layer Security (TLS) or Datagram Transport Layer Security (DTLS) and the extension is a Server Name Indication (SNI) extension.

6. The method of claim 4 , wherein the encryption protocol is at least one of Transport Layer Security (TLS) or Datagram Transport Layer Security (DTLS) and the extension is an Encrypted Client Hello (ECH) extension.

7. The method of claim 4 , wherein the extension of the encryption protocol is at least one of a Server Name Indication (SNI) extension or an Encrypted Client Hello (ECH) extension.

8. The method of claim 1 , wherein the identifier is a first identifier indicating that the traffic is the control plane traffic, the first identifier distinguishable from a second identifier associated with the data plane traffic, and the method includes sending the traffic to the control plane node based at least in part on the first identifier.

9. The method of claim 1 , wherein the identifier is a first identifier indicating that the traffic is the data plane traffic, the first identifier distinguishable from a second identifier associated with the control plane traffic, and the method includes sending the traffic to the data plane node based at least in part on the first identifier.

10. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions that, when executed, cause the one or more processors to perform operations comprising:

receiving traffic from a client device, the traffic including an identifier associated with a service hosted on a cloud-computing system;

determining, based at least in part on the identifier, whether the traffic is control plane traffic associated with the service or data plane traffic associated with the service; and

at least one of:

sending the traffic to a control plane node associated with the service based at least in part on determining that the traffic is the control plane traffic, or

sending the traffic to a data plane node associated with the service based at least in part on determining that the traffic is the data plane traffic.

11. The system of claim 10 , wherein the traffic is received via a secure communication flow between the client device and the cloud-computing system.

12. The system of claim 11 , wherein the secure communication flow is at least one of a Zero Trust Network Access (ZTNA) flow or a virtual private network (VPN) flow between the client device and the cloud-computing system.

13. The system of claim 10 , wherein the traffic is encrypted according to an encryption protocol, the identifier included in an extension of the encryption protocol.

14. The system of claim 13 , wherein the extension of the encryption protocol is at least one of a Server Name Indication (SNI) extension or an Encrypted Client Hello (ECH) extension.

15. The system of claim 10 , wherein the identifier is a first identifier indicating that the traffic is the control plane traffic, the first identifier distinguishable from a second identifier associated with the data plane traffic, and the operations include sending the traffic to the control plane node based at least in part on the first identifier.

16. The system of claim 10 , wherein the identifier is a first identifier indicating that the traffic is the data plane traffic, the first identifier distinguishable from a second identifier associated with the control plane traffic, and the operations include sending the traffic to the data plane node based at least in part on the first identifier.

17. One or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform operations comprising:

receiving traffic from a client device, the traffic including an identifier associated with a service hosted on a cloud-computing system, the identifier being associated with an encryption protocol;

determining, based at least in part on the identifier, whether the traffic is control plane traffic associated with the service or data plane traffic associated with the service; and

at least one of:

sending the traffic to a control plane node associated with the service based at least in part on determining that the traffic is the control plane traffic, or

sending the traffic to a data plane node associated with the service based at least in part on determining that the traffic is the data plane traffic.

18. The one or more non-transitory computer-readable media of claim 17 , wherein the traffic is received via a secure communication flow between the client device and the cloud-computing system.

19. The one or more non-transitory computer-readable media of claim 17 , wherein the traffic is encrypted according to an encryption protocol, the identifier included in an extension of the encryption protocol.

20. The one or more non-transitory computer-readable media of claim 19 , wherein the extension of the encryption protocol is at least one of a Server Name Indication (SNI) extension or an Encrypted Client Hello (ECH) extension.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2024
From: PARLA, VINCENT; MESTERY, KYLE ANDREW DONALD
To: CISCO TECHNOLOGY, INC.
Reel/Frame 067483/0961 →
Continuity (3)
Continuation 18198124 · May 16, 2023
Continuation 17376646 · Jul 15, 2021
Related Publication 20240314219A1 · Sep 19, 2024
References Cited (25)
US 8787250B2 · Beser · 2014 [cited by examiner]
US 9419942B1 · Buruganahalli · 2016 [cited by examiner]
US 10148430B1 · Roth · 2018 [cited by examiner]
US 10454823B1 · Thomas · 2019 [cited by examiner]
US 11362862B2 · Liebsch · 2022 [cited by examiner]
US 11689642B2 · Parla · 2023 [cited by examiner]
US 12052329B2 · Parla · 2024 [cited by examiner]
US 20160352867A1 · Subbarayan · 2016 [cited by examiner]
US 20200104275A1 · Sen · 2020 [cited by examiner]
US 20200162422A1 · Meng · 2020 [cited by examiner]
US 20200169394A1 · Khristi et al. · 2020 [cited by applicant]
US 20200245163A1 · Jaya et al. · 2020 [cited by applicant]
US 20200336467A1 · Subbarayan et al. · 2020 [cited by applicant]
US 20200409611A1 · Olson et al. · 2020 [cited by applicant]
US 20200412667A1 · Elder · 2020 [cited by examiner]
US 20210067561A1 · Ithal et al. · 2021 [cited by applicant]
US 20210168052A1 · Parulkar · 2021 [cited by examiner]
US 20230015687A1 · Parla · 2023 [cited by examiner]
US 20230291813A1 · Parla · 2023 [cited by examiner]
US 20240314219A1 · Parla · 2024 [cited by examiner]
Kong Gateway, “Hybrid Mode Deployment,” downloaded Jun. 7, 2021, 11 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/198,124, mailed on Dec. 6, 2023, Vincent E. Parla, “Routing Application Control and Data-Plane Traffic in Support of Cloud-Native Applications”, 6 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/376,646, mailed on Oct. 5, 2022, Parla, “Routing Application Control and Data-Plane Traffic in Support of Cloud-Native Applications”, 6 pages. [cited by applicant]
The PCT Search Report and Written Opinion mailed Sep. 27, 2022 for PCT application No. PCT/US2022/036255, 16 pages. [cited by applicant]
Rescoria: “TLS Encrypted Client Hello draft-ietf-tls-esni-09”', TLS Internet-Draft, Dec. 16, 2020 (Dec. 16, 2020), XP055808812, Retrieved from the Internet: URL:https://tools.ietf.org/pdf/draft-ietftls-esni-09.pdf [retr… [cited by applicant]