US 12,218,980 B2
Using an end-to-end policy controller to split policies between enforcement points in a network
Andrew E. Ossipov, Lewisville, TX (US); Robert Tappenden, South Melbourne (AU); Janardhanan Radhakrishnan, Dublin, CA (US); and Chandrodaya Prasad, San Jose, CA (US)
Assigned to Cisco Technology, Inc., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Dec. 27, 2022, as Appl. No. 18/089,212.
Prior Publication US 2024/0214424 A1, Jun. 27, 2024
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/20 (2013.01) 20 Claims
OG exemplary drawing
 
1. A method comprising:
receiving data representing an intent-based security policy associated with a network, the intent-based security policy indicating an entity, a resource, and an authorization associated with the entity accessing the resource;
determining a path of network traffic between the entity and the resource based at least in part on the authorization, the path of network traffic including one or more network devices;
identifying, by a Software-Defined Networking (SDN) controller associated with the network and based at least in part on an inventory storing information associated with the network devices, one or more enforcement points associated with the path of network traffic;
determining that a first enforcement point of the one or more enforcement points associated with the path of network traffic has a first capability to implement at least a first portion of the intent-based security policy;
determining that a second enforcement point of the one or more enforcement points associated with the path of network traffic has a second capability to implement at least a second portion of the intent-based security policy;
generating a first chain of enforcement points based at least in part on the first enforcement point and the second enforcement point; and
sending the first portion of the intent-based security policy and the second portion of the intent-based security policy to the first chain of enforcement points.