US2021281656A1PendingUtilityA1
Applying application-based policy rules using a programmable application cache
Est. expiryAug 2, 2038(~12 yrs left)· nominal 20-yr term from priority
H04W 40/246H04L 67/5682H04L 67/1095H04L 45/742H04L 69/22H04L 67/2852
64
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A network device receives a packet from a client device, and identifies, based on receiving the packet, a destination of the packet. The network device determines, based on information included in an application cache, an application associated with the destination of the packet, where the first network device, the client device, and the application cache are included in a first local network. The network device determines, based on the information included in the application cache, a policy rule associated with the application, and applies the policy rule to the packet.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A first network device, comprising:
one or more memories; and one or more processors, coupled to the one or more memories, to:
identify, based on receiving a packet from a device of a first local network, a destination of the packet;
determine, based on information included in a first application cache, an application associated with the destination of the packet,
wherein the first network device and the first application cache are associated with the first local network; and
transmit, based on determining that the first network device is unable to determine the application, the packet to a second network device for determining the application,
wherein the second network device is associated with a second local network that is different from the first local network, and
wherein transmitting the packet to the second network device causes synchronization of information in the first application cache with information in a second application cache associated with the second local network.
2 . The first network device of claim 1 , wherein the information in the second application cache includes information associated with the application that includes at least one of:
information associating a destination of the packet with the application, or information associating the application with a policy rule.
3 . The first network device of claim 1 , wherein the one or more processors are further to:
cause the second network device to determine the application associated with the packet; and cause the second network device to store information associated with the application in the second application cache.
4 . The first network device of claim 1 , wherein a connection between the first application cache and the second application cache is authenticated prior to the information in the first application cache being synchronized with the information in the second application cache.
5 . The first network device of claim 1 , wherein synchronization of the information in the first application cache with the information in the second application cache comprises:
transmitting information indicating that the first application cache is available to be synchronized.
6 . The first network device of claim 1 , wherein the packet is a first packet, and wherein the one or more processors are further to:
apply, based on synchronization of the information in the first application cache with the information in the second application cache, policy rules to one or more second packets, including the first packet, associated with the application.
7 . The first network device of claim 1 , wherein the information in the first application cache includes information that is provided by a centralized software-defined networking (SDN) controller using an application programming interface (API).
8 . A method, comprising:
identifying, by a first network device and based on receiving a packet from a device of a first local network, a destination of the packet; determining, by the first network device and based on information included in a first application cache, an application associated with the destination of the packet,
wherein the first network device and the first application cache are associated with the first local network; and
transmitting, by the first network device and based on determining that the first network device is unable to determine the application associated with the destination of the packet, the packet to a second network device for determining the application associated with the packet,
wherein the second network device is associated with a second local network that is different from the first local network, and
wherein transmitting the packet to the second network device causes synchronization of information in the first application cache with information in a second application cache associated with the second local network.
9 . The method of claim 8 , wherein the information in the second application cache includes information associated with the application that includes at least one of:
information associating a destination of the packet with the application, or information associating the application with a policy rule.
10 . The method of claim 8 , further comprising:
causing the second network device to determine the application associated with the packet; and causing the second network device to store information associated with the application in the second application cache.
11 . The method of claim 8 , wherein a connection between the first application cache and the second application cache is authenticated prior to the information in the first application cache being synchronized with the information in the second application cache.
12 . The method of claim 8 , wherein synchronization of the information in the first application cache with the information in the second application cache comprises:
transmitting information indicating that the first application cache is available to be synchronized.
13 . The method of claim 8 , wherein the packet is a first packet; and
the method further comprising:
applying, based on synchronization of the information in the first application cache with the information in the second application cache, policy rules to one or more second packets, including the first packet, associated with the application.
14 . The method of claim 8 , wherein the information in the first application cache includes information that is provided by a centralized software-defined networking (SDN) controller using an application programming interface (API).
15 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a first network device, cause the first network device to:
identify, based on receiving a packet from a device of a first local network, a destination of the packet;
determine, based on information included in a first application cache, an application associated with the destination of the packet,
wherein the first network device and the first application cache are associated with the first local network; and
transmit, based on determining that the first network device is unable to determine the application associated with the destination of the packet, the packet to a second network device for determining the application associated with the packet,
wherein the second network device is associated with a second local network that is different from the first local network, and
wherein transmitting the packet to the second network device causes synchronization of information in the first application cache with information in a second application cache associated with the second local network.
16 . The non-transitory computer-readable medium of claim 15 , wherein the information in the second application cache includes information associated with the application that includes at least one of:
information associating a destination of the packet with the application, or information associating the application with a policy rule.
17 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions further cause the first network device to:
cause the second network device to determine the application associated with the packet; and cause the second network device to store information associated with the application in the second application cache.
18 . The non-transitory computer-readable medium of claim 15 , wherein a connection between the first application cache and the second application cache is authenticated prior to the information in the first application cache being synchronized with the information in the second application cache.
19 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, that cause synchronization of the information in the first application cache with the information in the second application cache, cause the first network device to:
transmit information indicating that the first application cache is available to be synchronized.
20 . The non-transitory computer-readable medium of claim 15 , wherein the packet is a first packet, and
wherein the one or more instructions further cause the first network device to:
apply, based on synchronization of the information in the first application cache with the information in the second application cache, policy rules to one or more second packets, including the first packet, associated with the application.Join the waitlist — get patent alerts
Track US2021281656A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.