IP Library Granted Patent US 12,659,350
Granted Patent B2
US 12,659,350 · App. 18/385,607 · Granted Jun 16, 2026

Industrial network security policy mapping and translation

Inventors: Elango Ganesan (Palo Alto, CA); Swapna Anandan (Fremont, CA); Akshay Khushu (San Jose, CA); Flemming Stig Andreasen (Marlboro, NJ)
Assignee: Cisco Technology, Inc.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,350
App. No.
18/385,607
Granted
Jun 16, 2026
Kind
B2
Abstract

In one implementation, a method is disclosed comprising: determining, by a process, a network topology of a particular computer network and capabilities of particular devices within the network topology; determining, by the process, a logical framework of the particular computer network; mapping, by the process, access control and segmentation features of the particular devices to the logical framework based on the capabilities of the particular devices; and causing, by the process, mapped access control and segmentation features to be implemented to enforce the logical framework within the network topology.

Claims (41)

1 . A method, comprising:

determining, by a process, a network topology of a particular computer network and policy enforcement capabilities of particular devices within the network topology, wherein determining the policy enforcement capabilities includes determining one or more technical features of the particular devices, the one or more technical features including at least one technical feature selected from a group consisting of: virtual local area network (VLAN) enforcement; access control list (ACL) enforcement; and group-based policy enforcement for access control;

determining, by the process, a logical framework of the particular computer network;

mapping, by the process, access control and segmentation features of the particular devices to the logical framework based on the policy enforcement capabilities of the particular devices; and

causing, by the process, mapped access control and segmentation features to be implemented to enforce the logical framework within the network topology.

2 . The method as in claim 1 , wherein the logical framework is based on a model according to an IEC-62443 standard.

3 . The method as in claim 1 , wherein causing the access control and segmentation features to be implemented includes enforcing a zone and conduit model within the network topology.

4 . The method as in claim 1 , wherein determining the policy enforcement capabilities of the particular devices within the network topology includes determining one or more resources of the particular devices selected from a group consisting of: central processing unit processing capacity; memory; and ternary content-addressable memory.

5 . The method as in claim 1 , further comprising:

determining, based on a comparison of the policy enforcement capabilities of the particular devices to requirements of the logical framework, a feasibility of enforcing the logical framework within the network topology using the policy enforcement capabilities of the particular devices.

6 . The method as in claim 5 , further comprising:

providing, responsive to determining that enforcing the logical framework within the network topology is not feasible, proposed changes to at least one of the network topology or the particular devices that will enable adequate access control and segmentation features to enforce the logical framework within the network topology.

7 . The method as in claim 1 , wherein determining the network topology includes discovering network elements and operational technology devices within the network topology.

8 . The method as in claim 1 , further comprising:

determining, for each grouping of operational technology assets in the network topology, a networking technology to be used to place operational technology assets into a respective same group based on the network topology and the policy enforcement capabilities of the particular devices.

9 . The method as in claim 1 , further comprising:

determining, for each grouping of operational technology assets in the network topology, a location in the network topology where security policies for all operational technology assets in a respective same group can be enforced.

10 . The method as in claim 1 , further comprising:

determining, for each grouping of operational technology assets in the network topology, resource usage loads on underlying network elements of the network topology for each possible combination of a networking technology to place operational technology assets in a respective same group and a location in the network topology where security policies for all the operational technology assets in the respective same group is enforced.

11 . The method as in claim 1 , wherein causing the access control and segmentation features to be implemented to enforce the logical framework within the network topology comprises:

generating a proposed configuration for acceptance by a network administrator.

12 . The method as in claim 1 , further comprising:

determining a change in the network topology; and

determining an updated mapping for the access control and the segmentation features of the particular devices to enforce the logical framework for the change in the network topology.

13 . The method as in claim 1 , wherein the particular computer network comprises an industrial network.

14 . A tangible, non-transitory, computer-readable medium having computer-executable instructions stored thereon that, when executed by a processor on a computer, cause the computer to perform a method comprising:

determining a network topology of a particular computer network and policy enforcement capabilities of particular devices within the network topology, wherein determining the policy enforcement capabilities includes determining one or more technical features of the particular devices, the one or more technical features including at least one technical feature selected from a group consisting of: virtual local area network (VLAN) enforcement; access control list (ACL) enforcement; and group-based policy enforcement for access control;

determining a logical framework of the particular computer network;

mapping access control and segmentation features of the particular devices to the logical framework based on the policy enforcement capabilities of the particular devices; and

causing mapped access control and segmentation features to be implemented to enforce the logical framework within the network topology.

15 . The tangible, non-transitory, computer-readable medium as in claim 14 , wherein the logical framework is based on a model according to an IEC-62443 standard.

16 . The tangible, non-transitory, computer-readable medium as in claim 14 , wherein causing the access control and segmentation features to be implemented includes enforcing a zone and conduit model within the network topology.

17 . The tangible, non-transitory, computer-readable medium as in claim 14 , wherein determining the policy enforcement capabilities of the particular devices within the network topology includes determining one or more resources of the particular devices selected from a group consisting of: central processing unit processing capacity; memory; and ternary content-addressable memory.

18 . An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process, when executed, configured to:

determine a network topology of a particular computer network and policy enforcement capabilities of particular devices within the network topology, wherein determining the policy enforcement capabilities includes determining one or more technical features of the particular devices, the one or more technical features including at least one technical feature selected from a group consisting of: virtual local area network (VLAN) enforcement; access control list (ACL) enforcement; and group-based policy enforcement for access control;

determine a logical framework of the particular computer network;

map access control and segmentation features of the particular devices to the logical framework based on the policy enforcement capabilities of the particular devices; and

cause mapped access control and segmentation features to be implemented to enforce the logical framework within the network topology.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2023
From: GANESAN, ELANGO; ANANDAN, SWAPNA; KHUSHU, AKSHAY; ANDREASEN, FLEMMING STIG
To: CISCO TECHNOLOGY, INC.
Reel/Frame 065405/0735 →
Continuity (1)
Related Publication 20250141927A1 · May 1, 2025
References Cited (12)
US 9781162B2 · Overby, Jr. · 2017 [cited by examiner]
US 10243926B2 · Thubert et al. · 2019 [cited by applicant]
US 10721275B2 · Kung · 2020 [cited by examiner]
US 11025590B1 · Kovenat · 2021 [cited by examiner]
US 20160381076A1 · Kamble et al. · 2016 [cited by applicant]
US 20170295063A1 · Yang et al. · 2017 [cited by applicant]
US 20180367563A1 · Pfleger De Aguiar et al. · 2018 [cited by applicant]
US 20210352110A1 · Huffman et al. · 2021 [cited by applicant]
US 20210409426A1 · Engelberg · 2021 [cited by examiner]
US 20220060445A1 · Kovenat et al. · 2022 [cited by applicant]
US 20240154970A1 · Cheethirala · 2024 [cited by examiner]
US 20240333721A1 · Iqbal · 2024 [cited by examiner]