US 12,425,371 B2
System and method for providing SCHC-based edge firewalling
Pascal Thubert, Roquefort-les-Pins (FR); Jonas Zaddach, Antibes (FR); Patrick Wetterwald, Mouans Sartoux (FR); and Eric Levy-Abegnoli, Valbonne (FR)
Assigned to CISCO TECHNOLOGY, INC., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Sep. 16, 2022, as Appl. No. 17/932,754.
Prior Publication US 2024/0098063 A1, Mar. 21, 2024
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/0263 (2013.01) [H04L 63/0245 (2013.01); H04L 63/029 (2013.01)] 11 Claims
OG exemplary drawing
 
1. A system, comprising:
one or more processors; and
one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations comprising:
programming, using a Static Context Header Compression (SCHC) rules engine, a plurality of rules expressing a plurality of firewall decisions;
identifying, using the SCHC rules engine, one or more packets matching a rule, wherein the rule represents a compression format;
compressing the one or more packets in accordance with the compression format;
after compressing the one or more packets, selecting a firewall decision from the plurality of firewall decisions;
decompressing the one or more packets based on the compression format;
after decompressing the one or more packets, applying the firewall decision to the one or more packets, wherein:
applying the firewall decision comprises applying a tag associated with a firewall action to the one or more packets; and
the firewall action is associated with a route map, a punt decision, or a drop decision;
identifying the tag applied to the one or more packets; and
performing the firewall action on the one or more packets based on the identified tag, wherein the firewall action is performed by an external engine.