IP Library › Granted Patent US 12,621,180
Granted Patent B2
US 12,621,180 · App. 18/139,449 · Granted May 5, 2026

Fine-grained SD-WAN optimization services for cloud-native applications

Inventors: Sridhar Subramanian (Fremont, CA); Fabio Rodolfo Maino (Palo Alto, CA); Alberto Rodriguez Natal (Mountain View, CA); Vijoy Anand Pandey (San Jose, CA); Edward A. Warnicke (Austin, TX); John Andrew Joyce (Nashua, NH); Timothy James Swanson (Westford, MA); Loránd Jakab (sat Gheorghieni, RO)
H04L12/2803H04L12/28H04L41/0894H04L41/0895H04L41/20H04L45/50H04L47/20H04L67/02H04L67/10H04L67/12H04L67/14H04L69/16H04L41/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,180
App. No.
18/139,449
Granted
May 5, 2026
Kind
B2
Abstract

In one embodiment, a device of a software-defined wide area network (SD-WAN) receives, from a cloud-native application, contextual data for the cloud-native application that identifies microservices of the cloud-native application. The device translates the contextual data for the cloud-native application into a network policy for traffic in the SD-WAN associated with the cloud-native application. The device applies the network policy to a traffic flow in the SD-WAN between an endpoint and a particular microservice of the cloud-native application.

Claims (41)

1 . A method comprising:

receiving, at a device of a software-defined wide area network (SD-WAN) and from a cloud-native application, contextual data for the cloud-native application that identifies microservices of the cloud-native application;

identifying, by the device, network requirements for each of the microservices specified in the contextual data for the cloud-native application;

translating, by the device and based on the network requirements identified for each of the microservices, the contextual data for the cloud-native application into a network policy for traffic in the SD-WAN associated with the microservices, wherein the network policy comprises a plurality of corresponding access policies for each of the microservices; and

applying, by the device, an access policy from the plurality of corresponding access policies to a traffic flow in the SD-WAN between an endpoint and particular microservice of the microservices.

2 . The method as in claim 1 , wherein applying the access policy to the traffic flow comprises:

preventing the endpoint from accessing the particular microservice of the cloud-native application.

3 . The method as in claim 2 , wherein the access policy for the particular microservice specifies a user group to which the endpoint belongs.

4 . The method as in claim 1 , wherein the contextual data specifies one or more SD-WAN services to be applied to traffic in the SD-WAN associated with the particular microservice.

5 . The method as in claim 4 , wherein the one or more SD-WAN services comprise at least one of: a path visibility service, a Transport Control Protocol (TCP) optimization service, a Forward Error Control (FEC) service, a packet duplication service, or a firewall service.

6 . The method as in claim 4 , wherein application of the network policy causes the one or more SD-WAN services specified in the contextual data to be applied to the traffic flow between the endpoint and the particular microservice.

7 . The method as in claim 1 , wherein receiving the contextual data for the cloud-native application that identifies microservices of the cloud-native application comprises:

extracting the contextual data from a Hypertext Transfer Protocol (HTTP) header of traffic sent by the cloud-native application.

8 . The method as in claim 1 , wherein receiving the contextual data for the cloud-native application that identifies microservices of the cloud-native application comprises:

receiving the contextual data via an application programming interface (API).

9 . The method as in claim 1 , wherein the device is an edge router in the SD-WAN.

10 . The method as in claim 9 , wherein the edge router extracts the contextual data from data traffic for the cloud-native application.

11 . An apparatus, comprising:

one or more network interfaces to communicate with a software-defined wide area network (SD-WAN);

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

receive, from a cloud-native application, contextual data for the cloud-native application that identifies microservices of the cloud-native application;

identify network requirements for each of the microservices specified in the contextual data for the cloud-native application;

translate, based on the network requirements identified for each of the microservices, the contextual data for the cloud-native application into a network policy for traffic in the SD-WAN associated with the microservices, wherein the network policy comprises a plurality of corresponding access policies for each of the microservices; and

applying, by the device, an access policy from the plurality of corresponding access policies to a traffic flow in the SD-WAN between an endpoint and particular microservice of the microservices.

12 . The apparatus as in claim 11 , wherein the apparatus applies the network policy to the traffic flow by:

preventing the endpoint from accessing the particular microservice of the cloud-native application.

13 . The apparatus as in claim 12 , wherein the access policy for the particular microservice specifies a user group to which the endpoint belongs.

14 . The apparatus as in claim 11 , wherein the contextual data specifies one or more SD-WAN services to be applied to traffic in the SD-WAN associated with the particular microservice.

15 . The apparatus as in claim 14 , wherein the one or more SD-WAN services comprise at least one of: a path visibility service, a Transport Control Protocol (TCP) optimization service, a Forward Error Control (FEC) service, a packet duplication service, or a firewall service.

16 . The apparatus as in claim 14 , wherein application of the network policy causes the one or more SD-WAN services specified in the contextual data to be applied to the traffic flow between the endpoint and the particular microservice.

17 . The apparatus as in claim 11 , wherein the apparatus receives the contextual data for the cloud-native application that identifies microservices of the cloud-native application by:

extracting the contextual data from a Hypertext Transfer Protocol (HTTP) header of traffic sent by the cloud-native application.

18 . The apparatus as in claim 11 , wherein the apparatus receives the contextual data for the cloud-native application that identifies microservices of the cloud-native application by:

receiving the contextual data via an application programming interface (API).

19 . The apparatus as in claim 11 , wherein the apparatus is an edge router in the SD-WAN.

20 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a device of a software-defined wide area network (SD-WAN) to execute a process comprising:

receiving, at the device and from a cloud-native application, contextual data for the cloud-native application that identifies microservices of the cloud-native application;

identifying, by the device, network requirements for each of the microservices specified in the contextual data for the cloud-native application;

translating, by the device and based on the network requirements identified for each of the microservices, the contextual data for the cloud-native application into a network policy for traffic in the SD-WAN associated with the microservices, wherein the network policy comprises a plurality of corresponding access policies for each of the microservices; and

applying, by the device, an access policy from the plurality of corresponding access policies to a traffic flow in the SD-WAN between an endpoint and particular microservice of the microservices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2023
From: SUBRAMANIAN, SRIDHAR; MAINO, FABIO RODOLFO; RODRIGUEZ NATAL, ALBERTO; PANDEY, VIJOY ANAND; WARNICKE, EDWARD A.; JOYCE, JOHN ANDREW; SWANSON, TIMOTHY JAMES; JAKAB, LORÁND
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063445/0305 →
Continuity (3)
Continuation 16983346 · Aug 3, 2020
Provisional Application 62979807 · Feb 21, 2020
Related Publication 20230261999A1 · Aug 17, 2023
References Cited (31)
US 10212041B1 · Rastogi · 2019 [cited by examiner]
US 10999326B1 · Pollitt · 2021 [cited by examiner]
US 11032389B1 · Chaubey et al. · 2021 [cited by applicant]
US 20090055888A1 · Little · 2009 [cited by applicant]
US 20160164826A1 · Riedel et al. · 2016 [cited by applicant]
US 20160308905A1 · Stiekes · 2016 [cited by examiner]
US 20170230467A1 · Salgueiro et al. · 2017 [cited by applicant]
US 20190036814A1 · Aranha · 2019 [cited by examiner]
US 20190394286A1 · Chunduru Venkata · 2019 [cited by examiner]
US 20200012483A1 · Nassaur · 2020 [cited by applicant]
US 20200112487A1 · Inamdar et al. · 2020 [cited by applicant]
US 20200322262A1 · Maino et al. · 2020 [cited by applicant]
US 20200366574A1 · Schubert · 2020 [cited by examiner]
US 20200366697A1 · Vittal · 2020 [cited by examiner]
US 20200366759A1 · Sinha · 2020 [cited by examiner]
US 20200396141A1 · Sundararajan et al. · 2020 [cited by applicant]
US 20200413283A1 · Shen et al. · 2020 [cited by applicant]
US 20210204091A1 · Schubert · 2021 [cited by examiner]
US 20220029921A1 · Rodriguez-Natal et al. · 2022 [cited by applicant]
CN 110704164A · 2020 [cited by applicant]
Venkatesh, P., “Enabling Intelligent Branch with SD-WAN and Kubernetes”, online: https://www.onug.net/blog/enabling-intelligent-branch-with-sd-wan-and-kubernetes/, Oct. 2018 [printed May 2020], 11 pages, ONUG.net. [cited by applicant]
Wilkins, Sean, “Policy Based Routing (PBR) Fundamentals”, Aug. 2010, 5 pages, Pluralsight LLC. [cited by applicant]
Yaguache, et al., “Containerized Services Orchestration for Edge Computing in Software-Defined Wide Area Networks”, International Journal of Computer Networks & Communications (IJCNC) vol. 11, No. 5, Sep. 2019, pp. 113-… [cited by applicant]
“Kubernetes”, online: https://en.wikipedia.org/wiki/Kubernetes, 9 pages, May 2020, Wikimedia Foundation, Inc. [cited by applicant]
“What is Istio?”, online: https://istio.io/docs/concepts/what-is-istio/, May 2020, 3 pages, Istio Authors. [cited by applicant]
Sun, Yuqiong, “Security-as-a-Servive for Microservices-Based Cloud Applications”, 2015 IEEE 7th International Conference on Cloud Computing Technology and Science (Cloudcom), Iee, Nov. 30, 2015, pp. 50-57, XPO32859051. [cited by applicant]
International Search Report issued on Apr. 16, 2021 in connection with International Patent Application No. PCT/US2021/016694. [cited by applicant]
Apostolopoulos J., et al., “Cloud-Native SD-WAN: The WAN Your Kubernetes Applications Deserve,” Published Aug. 20, 2020, 08 pages, Retrieved from URL: https://blogs.cisco.com/networking/introducing-the-cloud-native-sd-w… [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2022/016607, mailed May 19, 2022, 19 Pages. [cited by applicant]
SunSince90: “Service Registry,” Published Jan. 22, 2021, 05 pages, [Retrieved on Apr. 20, 2021] from GitHub. [cited by applicant]
Tato G., “Lazy and Locality-Aware Building Blocks for Fog Middleware: A Service Discovery Use Case,” published May 12, 2020, 126 pages, Retrieved from URL: https://tel.archives-ouvertes.fr. [cited by applicant]