-
公开(公告)号:US20240012921A1
公开(公告)日:2024-01-11
申请号:US17859720
申请日:2022-07-07
Applicant: Cisco Technology, Inc.
Inventor: Marcelo Yannuzzi , Hervé MUYAL , Jean Andrei DIACONU , Frank BROCKNERS , Carlos GONCALVES PEREIRA
CPC classification number: G06F21/6218 , G06F9/543
Abstract: In one embodiment, a device may obtain a location of an endpoint that communicates with an application service. The device may match the location of the endpoint to a data compliance policy. The device may identify sensitive data within the application service to which the data compliance policy applies. The device may configure the application service to permit the endpoint to at least one of access or send the sensitive data when permitted by the data compliance policy.
-
公开(公告)号:US20240039958A1
公开(公告)日:2024-02-01
申请号:US17877508
申请日:2022-07-29
Applicant: Cisco Technology, Inc.
Inventor: Marcelo Yannuzzi , Benjamin William RYDER , Jean Andrei DIACONU , Hervé MUYAL , Hitesh S. SAIJPAL
IPC: H04L9/40
CPC classification number: H04L63/20
Abstract: In one embodiment, a device may obtain an identifier of a proof of location process (PLP) and an identifier of a node where the PLP is executed. The device may receive a query from a compliance engine for a proof of location of the node where the PLP is executed. The device may identify, based on the identifier of the PLP and the identifier of the node, a physical location of the node. The device may provide, to the compliance engine, a response to the query that is indicative of the physical location of the node, wherein the compliance engine enforces one or more data compliance policies with respect to a workload executed by the node and based on the physical location of the node.
-
公开(公告)号:US20240037132A1
公开(公告)日:2024-02-01
申请号:US17877529
申请日:2022-07-29
Applicant: Cisco Technology, Inc.
Inventor: Marcelo YANNUZZI , Hervé MUYAL , Jean Andrei DIACONU , Jelena KLJUJIC , Carlos GONCALVES PEREIRA
CPC classification number: G06F16/367 , G06F16/86
Abstract: In one embodiment, a device obtains an ontology derived from a data usage restriction document and indicative of a category of protected data. The device obtains metadata indicative of a type of data handled by an application. The device creates a mapping between the type of data handled by the application and the category of protected indicated by the ontology. The device generates, based on the mapping, a data compliance manifest used by a workload engine to constrain use of the type of data during execution of the application or used to constrain use of the type of data during deployment of the application.
-
公开(公告)号:US20240039959A1
公开(公告)日:2024-02-01
申请号:US17877989
申请日:2022-07-31
Applicant: Cisco Technology, Inc.
Inventor: Marcelo Yannuzzi , Benjamin William RYDER , Jean Andrei DIACONU , Hervé MUYAL , Hitesh S. SAIJPAL
Abstract: In one embodiment, a device may determine a compliance status of a communication of a type of data between a first workload and a second workload based on a data compliancy policy and a verified node location of at least one of the first workload and the second workload. The device may send, based on the compliance status of the communication, an instruction for handling the communication to at least one of a node executing the first workload and a node executing the second workload.
-
公开(公告)号:US20240012931A1
公开(公告)日:2024-01-11
申请号:US17859715
申请日:2022-07-07
Applicant: Cisco Technology, Inc.
Inventor: Marcelo Yannuzzi , Hervé MUYAL , Jean Andrei DIACONU , Frank BROCKNERS , Carlos GONCALVES PEREIRA
CPC classification number: G06F21/6245 , G06F21/51
Abstract: In one embodiment, a device determines a category of sensitive data processed by an application, based on annotations embedded into programming code of the application and protection bindings, which associate the category of sensitive data with one or more data types used by the application. The device computes, based on one or more data compliance constraints for the category of sensitive data, a set of one or more execution constraints for the application. The device identifies target infrastructure to execute a workload of the application that satisfies the set of one or more execution constraints. The device causes a deployment of the workload of the application for execution by the target infrastructure.
-
公开(公告)号:US20240012911A1
公开(公告)日:2024-01-11
申请号:US17859707
申请日:2022-07-07
Applicant: Cisco Technology, Inc.
Inventor: Marcelo Yannuzzi , Hervé MUYAL , Jean Andrei DIACONU , Frank BROCKNERS , Carlos GONCALVES PEREIRA
CPC classification number: G06F21/602 , G06F21/6245
Abstract: In one embodiment, an observability and assurance service, associated with various clusters of application services for an application that are executed in a data mesh, may configure a data compliance filter for a particular application service in one of the clusters of application services according to a data compliance policy. The observability and assurance service may monitor the data and traffic associated with the particular application service, wherein the data compliance filter is applied to the traffic to restrict sensitive data in the traffic from being processed by the particular application service. The observability and assurance service may make a determination that the data compliance policy has been violated by the particular application service. The observability and assurance service may modify, based on the determination, the data compliance filter for the particular application service.
-
公开(公告)号:US20230102475A1
公开(公告)日:2023-03-30
申请号:US17483969
申请日:2021-09-24
Applicant: Cisco Technology, Inc.
Inventor: Marcelo Yannuzzi , Hervé MUYAL , Benjamin William RYDER , Jean Andrei DIACONU
Abstract: In one embodiment, a brokering service receives, from a requesting device, a request to verify an online claim associated with an online resource. The brokering service identifies, based upon the request, a proving entity for the online claim. The brokering service obtains, from the proving entity, digitally verifiable proof that indicates that the online claim has been securely verified by the proving entity. The brokering service provides the digitally verifiable proof to the requesting device, wherein the digitally verifiable proof causes the requesting device to display an indication that the online claim has been securely verified.
-
-
-
-
-
-