IP Library › Granted Patent US 12,568,176
Granted Patent B2
US 12,568,176 · App. 18/409,729 · Granted Mar 3, 2026

Managing a segmentation policy for workloads in a secure enclave

Inventors: George Jeffrey Francis (Snohomish, WA); Matthew Kirby Glenn (Mountain View, CA); Jalandip Lepcha (San Jose, CA); Paul James Kirner (Palo Alto, CA)
Assignee: Illumio, Inc.
H04M15/66H04L47/20H04L63/0263H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,176
App. No.
18/409,729
Granted
Mar 3, 2026
Kind
B2
Abstract

A policy management server manages a segmentation policy and automatically configures an enclave protection device consistently with the segmentation policy so that that the segmentation policy can be enforced with respect to workloads within a secure enclave protected by the enclave protection device. The policy management server identifies protected workloads that are members of a secure enclave and external workloads that are external to the secure enclave. The policy management server identifies cross-boundary rules of the segmentation policy affecting traffic between the protected workloads and external workloads. The policy management server generates and distributes a configuration of the enclave protection device to enable enforcement of the cross-boundary rules pertaining to traffic passing through the enclave protection device.

Claims (46)

1 . A method comprising:

generating an enclave protection rule that permits traffic between a first workload group identified by a first group identifier and a second workload group identified by a second group identifier that meets specified traffic criteria;

generating membership information specifying first workload identifiers for first workloads in the first workload group and second workload identifiers for second workloads in the second workload group;

generating, based on the enclave protection rule and membership information, a configuration for an enclave protection device;

detecting a change in the first workloads in the first workload group; and

transmitting updated membership information to the enclave protection device reflecting the change.

2 . The method of claim 1 , wherein the updated membership information is transmitted to the enclave protection device without transmitting the enclave protection rule.

3 . The method of claim 1 , wherein the specified traffic criteria comprises at least one of: a service, a port, or a protocol.

4 . The method of claim 1 , wherein the first workload identifiers and second workload identifiers are internet protocol (IP) addresses.

5 . The method of claim 1 , wherein generating the configuration for the enclave protection device comprises:

identifying that the enclave protection rule is a duplicate of a different enclave protection rule;

combining the duplicate rules into a combined rule; and

replacing the enclave protection rule and the different enclave protection rule with the combined rule, the configuration for the enclave protection device being based on the combined rule.

6 . The method of claim 5 , wherein the enclave protection rule and different enclave protection rule share a common set of services, ports, and protocols.

7 . The method of claim 1 , wherein detecting the change in the first workloads in the first workload group comprises detecting that at least one workload in the first workload group is re-assigned to a different workload group.

8 . The method of claim 1 , wherein detecting the change in the first workloads in the first workload group comprises detecting that at least one workload in the first workload group comes online or goes offline.

9 . A non-transitory computer-readable storage medium storing instructions for managing a segmentation policy, the instructions, when executed by a computing system, causing the computing system to perform operations comprising:

generating an enclave protection rule that permits traffic between a first workload group identified by a first group identifier and a second workload group identified by a second group identifier that meets specified traffic criteria;

generating membership information specifying first workload identifiers for first workloads in the first workload group and second workload identifiers for second workloads in the second workload group;

generating, based on the enclave protection rule and membership information, a configuration for an enclave protection device;

detecting a change in the first workloads in the first workload group; and

transmitting updated membership information to the enclave protection device reflecting the change.

10 . The non-transitory computer-readable storage medium of claim 9 , wherein the updated membership information is transmitted to the enclave protection device without transmitting the enclave protection rule.

11 . The non-transitory computer-readable storage medium of claim 9 , wherein the specified traffic criteria comprises at least one of: a service, a port, or a protocol.

12 . The non-transitory computer-readable storage medium of claim 9 , wherein the first workload identifiers and second workload identifiers are internet protocol (IP) addresses.

13 . The non-transitory computer-readable storage medium of claim 9 , wherein generating the configuration for the enclave protection device comprises:

identifying that the enclave protection rule is a duplicate of a different enclave protection rule;

combining the duplicate rules into a combined rule; and

replacing the enclave protection rule and the different enclave protection rule with the combined rule, the configuration for the enclave protection device being based on the combined rule.

14 . The non-transitory computer-readable storage medium of claim 13 , wherein the enclave protection rule and different enclave protection rule share a common set of services, ports, and protocols.

15 . The non-transitory computer-readable storage medium of claim 9 , wherein detecting the change in the first workloads in the first workload group comprises detecting that at least one workload in the first workload group is re-assigned to a different workload group.

16 . The non-transitory computer-readable storage medium of claim 9 , wherein detecting the change in the first workloads in the first workload group comprises detecting that at least one workload in the first workload group goes offline or comes online.

17 . A computer system comprising:

one or more processors; and

a non-transitory computer-readable storage medium storing instructions for managing a segmentation policy, the instructions when executed by the one or more processors causing the computer system to perform steps including:

generating an enclave protection rule that permits traffic between a first workload group identified by a first group identifier and a second workload group identified by a second group identifier that meets specified traffic criteria;

generating membership information specifying first workload identifiers for first workloads in the first workload group and second workload identifiers for second workloads in the second workload group;

generating, based on the enclave protection rule and membership information, a configuration for an enclave protection device;

detecting a change in the first workloads in the first workload group; and

transmitting updated membership information to the enclave protection device reflecting the change.

18 . The computer system of claim 17 , wherein the updated membership information is transmitted to the enclave protection device without transmitting the enclave protection rule.

19 . The computer system of claim 17 , wherein generating the configuration for the enclave protection device comprises:

identifying that the enclave protection rule is a duplicate of a different enclave protection rule;

combining the duplicate rules into a combined rule; and

replacing the enclave protection rule and the different enclave protection rule with the combined rule, the configuration for the enclave protection device being based on the combined rule.

20 . The computer system of claim 17 , wherein detecting the change in the first workloads in the first workload group comprises detecting that at least one workload in the first workload group comes online, goes offline, or is re-assigned to a different workload group.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2024
From: FRANCIS, GEORGE JEFFREY; GLENN, MATTHEW KIRBY; LEPCHA, JALANDIP; KIRNER, PAUL JAMES
To: ILLUMIO, INC.
Reel/Frame 066901/0872 →
Continuity (2)
Continuation 16775248 · Jan 28, 2020
Related Publication 20240146773A1 · May 2, 2024
References Cited (14)
US 11218485B1 · Delaney · 2022 [cited by examiner]
US 20080276206A1 · Mariani · 2008 [cited by examiner]
US 20180234459A1 · Kung · 2018 [cited by examiner]
US 20190173736A1 · Ponnuswamy et al. · 2019 [cited by applicant]
US 20190238508A1 · Hira et al. · 2019 [cited by applicant]
US 20200236086A1 · Patil et al. · 2020 [cited by applicant]
US 20200272741A1 · Bhatia et al. · 2020 [cited by applicant]
US 20210182169A1 · Mardente et al. · 2021 [cited by applicant]
US 20220294828A1 · Kieser · 2022 [cited by applicant]
WO WO2020106973A1 · 2020 [cited by applicant]
United States Office Action, U.S. Appl. No. 16/775,248, Dec. 10, 2021, 17 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/775,248, Jun. 17, 2022, 17 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/775,248, Feb. 6, 2023, 17 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/775,248, Sep. 6, 2023, 16 pages. [cited by applicant]