-
公开(公告)号:US20240298180A1
公开(公告)日:2024-09-05
申请号:US18661055
申请日:2024-05-10
Applicant: Cisco Technology, Inc.
Inventor: Stefan Olofsson , Ijsbrand Wijnands , Hendrikus G. P. Bosch , Jeffrey Napper , Anubhav Gupta
IPC: H04W12/086 , H04L9/40 , H04L45/64 , H04W12/37
CPC classification number: H04W12/086 , H04L63/0272 , H04L63/20 , H04W12/37 , H04L45/64
Abstract: In one embodiment, a router includes one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors. The one or more computer-readable non-transitory storage media include instructions that, when executed by the one or more processors, cause the router to perform operations including receiving software-defined networking in a wide area network (SD-WAN) policies from a component of an SD-WAN network. The operations also include establishing a session with a mobile device and receiving information associated with the mobile device in response to establishing the session with the mobile device. The operations further include filtering the SD-WAN policies based on the information associated with the mobile device to generate SD-WAN device-specific policies and communicating the SD-WAN device-specific policies to the mobile device.
-
公开(公告)号:US20220417158A1
公开(公告)日:2022-12-29
申请号:US17357461
申请日:2021-06-24
Applicant: Cisco Technology, Inc.
Inventor: Vincent Parla , Andrew Zawadowskiy , Oleg Bessonov , Hendrikus G. P. Bosch
IPC: H04L12/851
Abstract: A method of defining priority of a number of data packets within a queue includes generating a policy. The policy defines a first multiplexed channel of a plurality of multiplexed channels. The first multiplexed channel having a first priority. The policy also defines a second multiplexed channel of the plurality of multiplexed channels. The second multiplexed channel having a second priority. The first priority is defined as being of a higher priority relative to the second priority. The method further includes receiving the number of data packets over the plurality of multiplexed channels associated with a session based at least in part on the policy.
-
公开(公告)号:US11516260B2
公开(公告)日:2022-11-29
申请号:US17166921
申请日:2021-02-03
Applicant: Cisco Technology, Inc.
Inventor: Alessandro Duminuco , Hendrikus G. P. Bosch , Jeffrey Michael Napper , Vinny Parla , Julien Barbot , Sape Jurrien Mullender
IPC: G06F17/00 , H04L9/40 , H04L67/141 , H04L67/146 , H04L61/4511 , H04L67/01
Abstract: Techniques for utilizing an enterprise traffic interception service (TIS) to enforce policies that mandate how clients access software as a service (SaaS) offered by service providers and selectively intercept enterprise network traffic utilizing a domain name service (DNS) and a single sign-on (SSO) service on a per-client per-service basis. The TIS may include a DNS server, an identity provider service, a TLS inspecting proxy, and/or a policy server. The DNS server may handle requests to resolve an address of a service, and identify a policy, stored in the policy server, to redirect the client based on the identity of the client and the service. The identity provider service may later query the policy server during client authorization for the service to verify that the client request is in line with the policy and allow or deny access to the service.
-
公开(公告)号:US11129023B2
公开(公告)日:2021-09-21
申请号:US16574963
申请日:2019-09-18
Applicant: Cisco Technology Inc.
Inventor: Stefan Olofsson , Ijsbrand Wijnands , Hendrikus G. P. Bosch , Jeffrey Napper , Anubhav Gupta
IPC: H04W12/086 , H04L29/06 , H04W12/37 , H04L12/715
Abstract: In one embodiment, a router includes one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors. The one or more computer-readable non-transitory storage media include instructions that, when executed by the one or more processors, cause the router to perform operations including receiving software-defined networking in a wide area network (SD-WAN) policies from a component of an SD-WAN network. The operations also include establishing a session with a mobile device and receiving information associated with the mobile device in response to establishing the session with the mobile device. The operations further include filtering the SD-WAN policies based on the information associated with the mobile device to generate SD-WAN device-specific policies and communicating the SD-WAN device-specific policies to the mobile device.
-
公开(公告)号:US11012251B2
公开(公告)日:2021-05-18
申请号:US16149756
申请日:2018-10-02
Applicant: Cisco Technology, Inc.
Inventor: Hendrikus G. P. Bosch , Sape Jurriën Mullender , Ijsbrand Wijnands , Alessandro Duminuco , Jeffrey Michael Napper , Subhasri Dhesikan
IPC: H04L12/18 , H04L12/801 , H04L12/863 , H04L12/931 , H04L12/937
Abstract: In one example embodiment, a server generates a candidate instantiation of virtual applications among a plurality of hosts in a data center to support a multicast stream. The server provides, to a first set of agents corresponding to a first set of the plurality of hosts, a command to initiate a test multicast stream. The server provides, to a second set of agents corresponding to a second set of the plurality of hosts, a command to join the test multicast stream. The server obtains, from the second set of agents, a message indicating whether the second set of agents received the test multicast stream. If the message indicates that the second set of agents received the test multicast stream, the server causes the virtual applications to be instantiated in accordance with the candidate instantiation of the virtual applications.
-
96.
公开(公告)号:US10904240B2
公开(公告)日:2021-01-26
申请号:US16705652
申请日:2019-12-06
Applicant: Cisco Technology, Inc.
Inventor: Hendrikus G. P. Bosch , Alessandro Duminuco , Jeffrey Napper , David Delano Ward , Syed Khalid Raza , Sape Jurrien Mullender
IPC: H04L29/06 , H04L12/725 , H04L12/721
Abstract: Disclosed are concepts for provided for managing application traffic. A method includes receiving a request to access a service from an application, confirming an entity of a user of the application and, based on the confirmation, generating, via an authentication service, a routing policy for data flows between the application and the service. The routing policy defines a mandated path between the application and the service. The method also can include storing proof-of-transit data in the traffic flow for tracking an actual path from the application to the service and determining whether the data path complies with the mandated path defined in the policy. When the determination indicates that the actual path followed the mandated path defined in the routing policy, the method includes granting access to the user for the service. When the actual path differs from the mandated path, the method includes denying access to the user.
-
公开(公告)号:US10798187B2
公开(公告)日:2020-10-06
申请号:US15627084
申请日:2017-06-19
Applicant: CISCO TECHNOLOGY, INC.
Inventor: Sape Jurriën Mullender , Hendrikus G. P. Bosch , Alessandro Duminuco , Jeffrey Napper
Abstract: In one embodiment, secure service chaining can be implemented efficiently for content delivery systems. An orchestrator can determine a service chain for processing a request from a client for content. The orchestrator can determine a capability identifying nodes of the service chain. The orchestrator can then transmit, to the client, a redirect message having the capability, wherein the redirect message redirects the request to a first node of the service chain. The nodes of the service chain can verify the capability and carry out the service chain. Service functions can be applied to the traffic flow associated with delivering the content to the user.
-
公开(公告)号:US10594513B2
公开(公告)日:2020-03-17
申请号:US15925731
申请日:2018-03-19
Applicant: Cisco Technology, Inc.
Inventor: Pablo Camarillo Garvia , Hendrikus G. P. Bosch , Clarence Filsfils
IPC: H04L12/46 , H04L12/741 , H04W84/04 , H04L12/723
Abstract: In one embodiment, a segment routing and tunnel exchange provides packet forwarding efficiencies in a network, including providing an exchange between a segment routing domain and a packet tunnel domain. One application includes the segment routing and tunnel exchange interfacing segment routing packet forwarding (e.g., in a Evolved Packet Core (EPC) and/or 5-G user plane) and packet tunnel forwarding in access networks (e.g., replacing a portion of a tunnel between an access node and a user plane function for accessing a corresponding data network). In one embodiment, a network provides mobility services using a segment routing data plane that spans segment routing and tunnel exchange(s) and segment routing-enabled user plane functions. One embodiment uses the segment routing data plane without any modification to a (radio) access network (R)AN (e.g., Evolved NodeB, Next Generation NodeB) nor to user equipment (e.g., any end user device).
-
99.
公开(公告)号:US20190356590A1
公开(公告)日:2019-11-21
申请号:US16531549
申请日:2019-08-05
Applicant: Cisco Technology, Inc.
Inventor: Hendrikus G. P. Bosch , Sape Jurriën Mullender , Keith Burns , Jeffrey Napper , William Mark Townsley , Alessandro Duminuco , Andre Surcouf , Ijsbrand Wijnands , Humberto J. La Roche
IPC: H04L12/749 , H04L29/08 , H04L12/761 , H04L29/06 , H04L12/717
Abstract: A method is provided in one example embodiment and may include determining at a parent content node that a plurality of recipient content nodes are to receive a same content; generating, based on a determination that the same content is available at the parent content node, a multi-delivery header comprising a plurality of identifiers, wherein each identifier of the plurality of identifiers indicates each recipient content node that is to receive the same content; appending the multi-delivery header to one or more packets of an Internet Protocol (IP) flow associated with the same content; and transmitting packets for the IP flow to each of the plurality of the recipient content nodes.
-
100.
公开(公告)号:US10469379B2
公开(公告)日:2019-11-05
申请号:US15436540
申请日:2017-02-17
Applicant: CISCO TECHNOLOGY, INC.
Inventor: Hendrikus G. P. Bosch , Sape Jurriën Mullender , Keith Burns , Jeffrey Napper , William Mark Townsley , Alessandro Duminuco , Andre Surcouf , Ijsbrand Wijnands , Humberto J. La Roche
IPC: H04L12/749 , H04L12/717 , H04L29/06 , H04L12/761 , H04L29/08 , H04L29/12
Abstract: A method is provided in one example embodiment and may include determining at a parent content node that a plurality of recipient content nodes are to receive a same content; generating, based on a determination that the same content is available at the parent content node, a multi-delivery header comprising a plurality of identifiers, wherein each identifier of the plurality of identifiers indicates each recipient content node that is to receive the same content; appending the multi-delivery header to one or more packets of an Internet Protocol (IP) flow associated with the same content; and transmitting packets for the IP flow to each of the plurality of the recipient content nodes.
-
-
-
-
-
-
-
-
-