US2022247677A1PendingUtilityA1

Network service access and data routing based on assigned context

Assignee: CISCO TECH INCPriority: Aug 14, 2020Filed: Apr 13, 2022Published: Aug 4, 2022
Est. expiryAug 14, 2040(~14 yrs left)· nominal 20-yr term from priority
H04L 45/76H04L 45/64H04L 45/02H04L 63/0272H04L 45/30H04L 12/4633H04L 47/2475H04L 63/029
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present technology discloses methods, systems, and non-transitory computer-readable media for defining, for a network primitive in a network domain, whether the network primitive can receive data carrying an assigned context associated from one or more source nodes through a software-defined wide area network (SDWAN) fabric overlay; advertising a capability of the network primitive, the capability stating whether the network primitive can receive the data carrying the assigned context; and controlling selective transmission of the data carrying the assigned context from the one or more source nodes to the network primitive through the SDWAN fabric overlay based on the capability of the network primitive to receive the data carrying the assigned context.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 defining whether a network primitive in a network domain is configured to receive data carrying an assigned context from a source node through a software-defined wide area network (SDWAN) fabric overlay associated with the network domain;   advertising a capability of the network primitive, the capability indicating whether the network primitive is configured to receive the data carrying the assigned context;   determining a type of network primitive of the network primitive; and   controlling selective transmission of the data carrying the assigned context from the source node to the network primitive through the SDWAN fabric overlay based on the capability of the network primitive to receive the data carrying the assigned context and the type of network primitive of the network primitive.   
     
     
         2 . The method of  claim 1 , wherein the network primitive defines whether it is configured to receive the data carrying the assigned context from the source node. 
     
     
         3 . The method of  claim 1 , wherein the assigned context is a security group tag assigned to the source node. 
     
     
         4 . The method of  claim 3 , wherein the security group tag is specific to a group of source nodes including the source node. 
     
     
         5 . The method of  claim 1 , wherein the network primitive includes a virtual private network associated with a network device, a network tunnel associated with the network device, a network prefix associated with the network device, or a combination thereof. 
     
     
         6 . The method of  claim 1 , wherein the network primitive is an edge node that is in a specific prefix in the network domain and is configured to receive data through a specific tunnel in a specific virtual private network, the method further comprising:
 determining whether the specific tunnel has the capability to receive the data carrying the assigned context;   identifying whether the specific virtual private network has the capability to receive the data carrying the assigned context;   determining whether the specific prefix has the capability to receive the data carrying the assigned context; and   controlling selective transmission of the data carrying the assigned context to the edge node based on whether the specific tunnel, the specific virtual private network, and the specific prefix have the capability to receive the data carrying the assigned context.   
     
     
         7 . The method of  claim 6 , wherein controlling selective transmission of the data carrying the assigned context to the edge node further includes refraining from transmitting the data carrying the assigned context to the edge node if the specific tunnel lacks the capability to receive the data carrying the assigned context regardless of whether the specific virtual private network and the specific prefix have the capability to receive the data carrying the assigned context. 
     
     
         8 . The method of  claim 6 , wherein controlling selective transmission of the data carrying the assigned context to the edge node further includes refraining from transmitting the data carrying the assigned context to the edge node if the specific virtual private network lacks the capability to receive the data carrying the assigned context regardless of whether the specific prefix has the capability to receive the data carrying the assigned context. 
     
     
         9 . The method of  claim 6 , further comprising controlling propagation of the data carrying the assigned context to additional nodes within the specific prefix based on characteristics of the specific prefix in receiving the data carrying the assigned context. 
     
     
         10 . A system comprising:
 one or more processors; and   a computer-readable medium comprising instructions stored therein, which when executed by the one or more processors, cause the one or more processors to:
 define whether a network primitive in a network domain is configured to receive data carrying an assigned context from a source node through a software-defined wide area network (SDWAN) fabric overlay associated with the network domain; 
 advertise a capability of the network primitive, the capability indicating whether the network primitive is configured to receive the data carrying the assigned context; 
 determine a type of network primitive of the network primitive; and 
 control selective transmission of the data carrying the assigned context from the source node to the network primitive through the SDWAN fabric overlay based on the capability of the network primitive to receive the data carrying the assigned context and the type of network primitive of the network primitive. 
   
     
     
         11 . The system of  claim 10 , wherein the network primitive defines whether it is configured to receive the data carrying the assigned context from the source node. 
     
     
         12 . The system of  claim 10 , wherein the assigned context is a security group tag assigned to the source node. 
     
     
         13 . The system of  claim 12 , wherein the security group tag is specific to a group of source nodes including the source node. 
     
     
         14 . The system of  claim 10 , wherein the network primitive includes a virtual private network associated with a network device, a network tunnel associated with the network device, a network prefix associated with the network device, or a combination thereof. 
     
     
         15 . The system of  claim 10 , wherein the network primitive is an edge node that is in a specific prefix in the network domain and is configured to receive data through a specific tunnel in a specific virtual private network and the instructions, which when executed by the one or more processors, further cause the one or more processors to:
 determine whether the specific tunnel has the capability to receive the data carrying the assigned context;   identify whether the specific virtual private network has the capability to receive the data carrying the assigned context;   determine whether the specific prefix has the capability to receive the data carrying the assigned context; and   control selective transmission of the data carrying the assigned context to the edge node based on whether the specific tunnel, the specific virtual private network, and the specific prefix have the capability to receive the data carrying the assigned context.   
     
     
         16 . The system of  claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to refrain from transmitting the data carrying the assigned context to the edge node if the specific tunnel lacks the capability to receive the data carrying the assigned context regardless of whether the specific virtual private network and the specific prefix have the capability to receive the data carrying the assigned context. 
     
     
         17 . The system of  claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to refrain from transmitting the data carrying the assigned context to the edge node if the specific virtual private network lacks the capability to receive the data carrying the assigned context regardless of whether the specific prefix has the capability to receive the data carrying the assigned context. 
     
     
         18 . The system of  claim 15 , wherein the instructions, which when executed by the one or more processors, further cause the one or more processors to control propagation of the data carrying the assigned context to additional nodes within the specific prefix based on characteristics of the specific prefix in receiving the data carrying the assigned context. 
     
     
         19 . A non-transitory computer-readable storage medium comprising instructions stored therein, which when executed by one or more processors, cause the one or more processors to:
 define whether a network primitive in a network domain is configured to receive data carrying an assigned context from a source node through a software-defined wide area network (SDWAN) fabric overlay associated with the network domain;   advertise a capability of the network primitive, the capability indicating whether the network primitive is configured to receive the data carrying the assigned context;   determine a type of network primitive of the network primitive; and   control selective transmission of the data carrying the assigned context from the source node to the network primitive through the SDWAN fabric overlay based on the capability of the network primitive to receive the data carrying the assigned context and the type of network primitive of the network primitive.   
     
     
         20 . The non-transitory computer-readable storage medium of  claim 19 , wherein the network primitive is an edge node that is in a specific prefix in the network domain and is configured to receive data through a specific tunnel in a specific virtual private network and the instructions, which when executed by the one or more processors, further cause the one or more processors to:
 determine whether the specific tunnel has the capability to receive the data carrying the assigned context;   identify whether the specific virtual private network has the capability to receive the data carrying the assigned context;   determine whether the specific prefix has the capability to receive the data carrying the assigned context; and   control selective transmission of the data carrying the assigned context to the edge node based on whether the specific tunnel, the specific virtual private network, and the specific prefix have the capability to receive the data carrying the assigned context.

Join the waitlist — get patent alerts

Track US2022247677A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.