Network service access and data routing based on assigned context
Abstract
The present technology discloses methods, systems, and non-transitory computer-readable media for defining, for a network primitive in a network domain, whether the network primitive can receive data carrying an assigned context associated from one or more source nodes through a software-defined wide area network (SDWAN) fabric overlay; advertising a capability of the network primitive, the capability stating whether the network primitive can receive the data carrying the assigned context; and controlling selective transmission of the data carrying the assigned context from the one or more source nodes to the network primitive through the SDWAN fabric overlay based on the capability of the network primitive to receive the data carrying the assigned context.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
defining whether a network primitive in a network domain is configured to receive data carrying an assigned context from a source node through a software-defined wide area network (SDWAN) fabric overlay associated with the network domain; advertising a capability of the network primitive, the capability indicating whether the network primitive is configured to receive the data carrying the assigned context; determining a type of network primitive of the network primitive; and controlling selective transmission of the data carrying the assigned context from the source node to the network primitive through the SDWAN fabric overlay based on the capability of the network primitive to receive the data carrying the assigned context and the type of network primitive of the network primitive.
2 . The method of claim 1 , wherein the network primitive defines whether it is configured to receive the data carrying the assigned context from the source node.
3 . The method of claim 1 , wherein the assigned context is a security group tag assigned to the source node.
4 . The method of claim 3 , wherein the security group tag is specific to a group of source nodes including the source node.
5 . The method of claim 1 , wherein the network primitive includes a virtual private network associated with a network device, a network tunnel associated with the network device, a network prefix associated with the network device, or a combination thereof.
6 . The method of claim 1 , wherein the network primitive is an edge node that is in a specific prefix in the network domain and is configured to receive data through a specific tunnel in a specific virtual private network, the method further comprising:
determining whether the specific tunnel has the capability to receive the data carrying the assigned context; identifying whether the specific virtual private network has the capability to receive the data carrying the assigned context; determining whether the specific prefix has the capability to receive the data carrying the assigned context; and controlling selective transmission of the data carrying the assigned context to the edge node based on whether the specific tunnel, the specific virtual private network, and the specific prefix have the capability to receive the data carrying the assigned context.
7 . The method of claim 6 , wherein controlling selective transmission of the data carrying the assigned context to the edge node further includes refraining from transmitting the data carrying the assigned context to the edge node if the specific tunnel lacks the capability to receive the data carrying the assigned context regardless of whether the specific virtual private network and the specific prefix have the capability to receive the data carrying the assigned context.
8 . The method of claim 6 , wherein controlling selective transmission of the data carrying the assigned context to the edge node further includes refraining from transmitting the data carrying the assigned context to the edge node if the specific virtual private network lacks the capability to receive the data carrying the assigned context regardless of whether the specific prefix has the capability to receive the data carrying the assigned context.
9 . The method of claim 6 , further comprising controlling propagation of the data carrying the assigned context to additional nodes within the specific prefix based on characteristics of the specific prefix in receiving the data carrying the assigned context.
10 . A system comprising:
one or more processors; and a computer-readable medium comprising instructions stored therein, which when executed by the one or more processors, cause the one or more processors to:
define whether a network primitive in a network domain is configured to receive data carrying an assigned context from a source node through a software-defined wide area network (SDWAN) fabric overlay associated with the network domain;
advertise a capability of the network primitive, the capability indicating whether the network primitive is configured to receive the data carrying the assigned context;
determine a type of network primitive of the network primitive; and
control selective transmission of the data carrying the assigned context from the source node to the network primitive through the SDWAN fabric overlay based on the capability of the network primitive to receive the data carrying the assigned context and the type of network primitive of the network primitive.
11 . The system of claim 10 , wherein the network primitive defines whether it is configured to receive the data carrying the assigned context from the source node.
12 . The system of claim 10 , wherein the assigned context is a security group tag assigned to the source node.
13 . The system of claim 12 , wherein the security group tag is specific to a group of source nodes including the source node.
14 . The system of claim 10 , wherein the network primitive includes a virtual private network associated with a network device, a network tunnel associated with the network device, a network prefix associated with the network device, or a combination thereof.
15 . The system of claim 10 , wherein the network primitive is an edge node that is in a specific prefix in the network domain and is configured to receive data through a specific tunnel in a specific virtual private network and the instructions, which when executed by the one or more processors, further cause the one or more processors to:
determine whether the specific tunnel has the capability to receive the data carrying the assigned context; identify whether the specific virtual private network has the capability to receive the data carrying the assigned context; determine whether the specific prefix has the capability to receive the data carrying the assigned context; and control selective transmission of the data carrying the assigned context to the edge node based on whether the specific tunnel, the specific virtual private network, and the specific prefix have the capability to receive the data carrying the assigned context.
16 . The system of claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to refrain from transmitting the data carrying the assigned context to the edge node if the specific tunnel lacks the capability to receive the data carrying the assigned context regardless of whether the specific virtual private network and the specific prefix have the capability to receive the data carrying the assigned context.
17 . The system of claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to refrain from transmitting the data carrying the assigned context to the edge node if the specific virtual private network lacks the capability to receive the data carrying the assigned context regardless of whether the specific prefix has the capability to receive the data carrying the assigned context.
18 . The system of claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to control propagation of the data carrying the assigned context to additional nodes within the specific prefix based on characteristics of the specific prefix in receiving the data carrying the assigned context.
19 . A non-transitory computer-readable storage medium comprising instructions stored therein, which when executed by one or more processors, cause the one or more processors to:
define whether a network primitive in a network domain is configured to receive data carrying an assigned context from a source node through a software-defined wide area network (SDWAN) fabric overlay associated with the network domain; advertise a capability of the network primitive, the capability indicating whether the network primitive is configured to receive the data carrying the assigned context; determine a type of network primitive of the network primitive; and control selective transmission of the data carrying the assigned context from the source node to the network primitive through the SDWAN fabric overlay based on the capability of the network primitive to receive the data carrying the assigned context and the type of network primitive of the network primitive.
20 . The non-transitory computer-readable storage medium of claim 19 , wherein the network primitive is an edge node that is in a specific prefix in the network domain and is configured to receive data through a specific tunnel in a specific virtual private network and the instructions, which when executed by the one or more processors, further cause the one or more processors to:
determine whether the specific tunnel has the capability to receive the data carrying the assigned context; identify whether the specific virtual private network has the capability to receive the data carrying the assigned context; determine whether the specific prefix has the capability to receive the data carrying the assigned context; and control selective transmission of the data carrying the assigned context to the edge node based on whether the specific tunnel, the specific virtual private network, and the specific prefix have the capability to receive the data carrying the assigned context.Join the waitlist — get patent alerts
Track US2022247677A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.