The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 01, 2019

Filed:

May. 19, 2016
Applicant:

Cisco Technology, Inc., San Jose, CA (US);

Inventors:

Praveen Jain, Cupertino, CA (US);

Munish Mehta, Fremont, CA (US);

Saurabh Jain, San Jose, CA (US);

Yibin Yang, San Jose, CA (US);

Assignee:

CISCO TECHNOLOGY, INC., San Jose, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); H04L 29/06 (2006.01); H04L 12/931 (2013.01); G06F 9/455 (2018.01); H04L 12/713 (2013.01);
U.S. Cl.
CPC ...
H04L 63/20 (2013.01); G06F 9/455 (2013.01); H04L 45/586 (2013.01); H04L 49/70 (2013.01); H04L 63/0428 (2013.01);
Abstract

Microsegmentation in a heterogeneous software-defined network can be performed by classifying endpoints associated with a first virtualized environment into respective endpoint groups based on respective attributes, and classifying endpoints associated with a second virtualized environment into respective security groups based on respective attributes. Each respective endpoint group can correspond to a respective security group having the same attribute. Each respective endpoint group and corresponding security group can be associated with a respective policy model defining rules for processing associated traffic. Each of the respective security groups can be used to generate a respective network attribute endpoint group, which can include the network addresses of those endpoints in the respective security group. Each respective network attribute endpoint group can inherit the policy model of the respective endpoint group corresponding to the respective security group. Traffic between the endpoints can then be processed based on the various classifications and associated rules.


Find Patent Forward Citations

Loading…