US2023388188A1PendingUtilityA1

Enforcing policies in cloud domains with different application nomenclatures

Assignee: JUNIPER NETWORKS INCPriority: Mar 23, 2018Filed: Aug 10, 2023Published: Nov 30, 2023
Est. expiryMar 23, 2038(~11.6 yrs left)· nominal 20-yr term from priority
H04L 41/0894G06F 9/5072H04L 41/0893H04L 63/102H04L 63/104H04L 63/20G06F 9/54H04L 41/16
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A device receives policy information indicating a policy to be implemented for an application hosted by multiple cloud domains, and receives, from the multiple cloud domains, different application resource tags and addresses associated with the application. The device maps the different application resource tags to a generic identifier, and associates the policy with the generic identifier and with the addresses associated with the application. The device provides, based on associating the policy with the generic identifier and with the addresses associated with the application, the policy to the multiple cloud domains to permit the multiple cloud domains to implement the policy.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A device, comprising:
 one or more memories; and   one or more processors to:
 map a first application resource tag to a generic identifier based on processing the first application resource tag with a processing technique,
 wherein the first application resource tag is associated with an application and is used by a first cloud domain; 
 
 map a second application resource tag to the generic identifier based on processing the second application resource tag with the processing technique to determine that the second application resource tag relates to the application,
 wherein the second application resource tag is used by a second cloud domain that is different than the first cloud domain; and 
 
 provide information indicating an action to the first cloud domain and the second cloud domain based on the generic identifier to permit the first cloud domain or the second cloud domain to perform the action. 
   
     
     
         2 . The device of  claim 1 , wherein the one or more processors are further to:
 dynamically determine that the application is present in the second cloud domain based on the second application resource tag and a second address associated with the application.   
     
     
         3 . The device of  claim 1 , wherein the one or more processors are further to:
 provide policy information to the first cloud domain based on the generic identifier to permit the first cloud domain to perform the action.   
     
     
         4 . The device of  claim 1 , wherein the first application resource tags is used for identifying the application and an Internet protocol (IP) address associated with the application. 
     
     
         5 . The device of  claim 1 , wherein the one or more processors are further to:
 store the second application resource tag associated with the second cloud domain in a data structure.   
     
     
         6 . The device of  claim 1 , wherein the generic identifier may include a first field to identify the application and a second field to identify types associated with the application. 
     
     
         7 . The device of  claim 1 , wherein the one or more processors, to provide the information, are to:
 provide the information to permit the second cloud domain to perform the action,
 wherein the action includes one or more of the following:
 a security action to be applied to the application, 
 a business action to be applied to the application, or 
 a network action to be applied to the application. 
 
   
     
     
         8 . A method comprising:
 mapping, by a device, a first application resource tag to a generic identifier based on processing the first application resource tag,
 wherein the first application resource tag is associated with an application and is used by a first cloud domain; 
   mapping, by the device, a second application resource tag to the generic identifier based on processing the second application resource tag to determine that the second application resource tag relates to the application,
 wherein the second application resource tag is used by a second cloud domain; and 
   providing, by the device, information indicating an action to the first cloud domain and the second cloud domain based on the generic identifier to permit the first cloud domain or the second cloud domain to perform the action.   
     
     
         9 . The method of  claim 8 , wherein providing information comprises:
 providing the information to permit the second cloud domain to perform the action,
 wherein the action includes one or more of:
 a security action to be applied to the application, 
 a business action to be applied to the application, or 
 a network action to be applied to the application. 
 
   
     
     
         10 . The method of  claim 8 , wherein providing the information indicating the action comprises:
 providing information indicating the action based on the generic identifier and an Internet protocol (IP) address.   
     
     
         11 . The method of  claim 8 , wherein the first application resource tags is used for identifying the application and an Internet protocol (IP) address associated with the application. 
     
     
         12 . The method of  claim 8 , wherein the first cloud domain or the second cloud domain includes:
 a public cloud domain,   a private cloud domain, or   a legacy data center domain.   
     
     
         13 . The method of  claim 8 , further comprising:
 receiving a third application resource tag and a third address associated with a second application;   processing the third application resource tag with to determine which application resource tags relate to the second application and are to be mapped to a second generic identifier; and   mapping the third application resource tag to the second generic identifier based on the third application resource tag being related to the second application.   
     
     
         14 . The method of  claim 8 , wherein mapping the first application resource tag to the generic identifier comprises:
 mapping the first application resource tag to the generic identifier based on processing the first application resource tag with a processing technique; and   wherein mapping the second application resource tag to the generic identifier based on processing the second application resource tag comprises:   mapping the second application resource tag to the generic identifier based on processing the second application resource tag with the processing technique.   
     
     
         15 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
 one or more instructions that, when executed by one or more processors, cause the one or more processors to:
 map a first application resource tag to a generic identifier based on processing the first application resource tag with a processing technique,
 wherein the first application resource tag is associated with an application and is used by a first cloud domain; 
 
 map a second application resource tag to the generic identifier based on processing the second application resource tag with the processing technique to determine that the second application resource tag relates to the application,
 wherein the second application resource tag is used by a second cloud domain that is different than the first cloud domain; and 
 
 provide information indicating an action based on the generic identifier. 
   
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , wherein the generic identifier provides a common nomenclature for the application that maps to different nomenclatures utilized by the first cloud domain and the second cloud domain to identify the application. 
     
     
         17 . The non-transitory computer-readable medium of  claim 15 , wherein the one or more instructions further cause the one or more processors to:
 dynamically determine that the application is present in the second cloud domain based on the second application resource tag and a second address associated with the application.   
     
     
         18 . The non-transitory computer-readable medium of  claim 15 , wherein the one or more instructions, that cause the one or more processors to map the second application resource tag to the generic identifier based on processing the second application resource tag with the processing technique to determine that the second application resource tag relates to the application, cause the one or more processors to:
 map the second application resource tag to the generic identifier based on processing the second application resource tag with one or more of:
 a natural language processing technique, 
 a computational linguistics technique, or 
 a text analysis technique. 
   
     
     
         19 . The non-transitory computer-readable medium of  claim 15 , wherein the one or more instructions further cause the one or more processors to:
 provide policy information to the first cloud domain based on the generic identifier to permit the first cloud domain to perform the action.   
     
     
         20 . The non-transitory computer-readable medium of  claim 15 , wherein the first cloud domain is different than the second cloud domain.

Join the waitlist — get patent alerts

Track US2023388188A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.