Using an end-to-end policy controller to split policies between enforcement points in a network

    公开(公告)号:US12218980B2

    公开(公告)日:2025-02-04

    申请号:US18089212

    申请日:2022-12-27

    Abstract: Techniques for using an end-to-end policy controller to utilize an inventory of enforcement points to generate a chain of enforcement points having capabilities to enforcement individual operations of an intent-based security policy associated with an entity accessing a resource. A network controller may intelligently split an intent-based security policy and send portions thereof to enforcement points along a path configured for an entity to access a resource. For example, a portion of a security policy corresponding to an operation may be mapped to and implemented by an enforcement point having a capability to perform the operation. Once each operation of a security policy has been mapped to an enforcement point, a chain of enforcement points may be generated.

    MANAGED ACCESS TO MOBILE ENDPOINTS
    2.
    发明申请
    MANAGED ACCESS TO MOBILE ENDPOINTS 审中-公开
    管理访问移动终端

    公开(公告)号:US20150078202A1

    公开(公告)日:2015-03-19

    申请号:US14542227

    申请日:2014-11-14

    Abstract: A network device may be configured to provide a gateway between a remote host and a mobile node using multiple interconnection protocols. The network device may include database circuitry configured to query a database for a first or second address of a mobile node using a domain name of the mobile node. The addresses may be associated with different interconnection protocols. The network device may include communication interface circuitry configured to receive a request from a remote host to communicate with the mobile node. The request may include the domain name. The interface circuitry may also be configured to transmit a message indicating the request using the first address, and transmit the second address to the remote host so that the remote host can communicate with the mobile node using the second address. The message may include a command to establish a data bearer through the second address.

    Abstract translation: 网络设备可以被配置为使用多个互连协议在远程主机和移动节点之间提供网关。 网络设备可以包括数据库电路,其被配置为使用移动节点的域名来查询数据库中的移动节点的第一或第二地址。 地址可能与不同的互连协议相关联。 网络设备可以包括被配置为从远程主机接收与移动节点通信的请求的通信接口电路。 请求可能包含域名。 接口电路还可以被配置为使用第一地址发送指示请求的消息,并且将第二地址发送到远程主机,使得远程主机可以使用第二地址与移动节点进行通信。 消息可以包括通过第二地址建立数据承载的命令。

    USING AN END-TO-END POLICY CONTROLLER TO SPLIT POLICIES BETWEEN ENFORCEMENT POINTS IN A NETWORK

    公开(公告)号:US20240214424A1

    公开(公告)日:2024-06-27

    申请号:US18089212

    申请日:2022-12-27

    CPC classification number: H04L63/20

    Abstract: Techniques for using an end-to-end policy controller to utilize an inventory of enforcement points to generate a chain of enforcement points having capabilities to enforcement individual operations of an intent-based security policy associated with an entity accessing a resource. A network controller may intelligently split an intent-based security policy and send portions thereof to enforcement points along a path configured for an entity to access a resource. For example, a portion of a security policy corresponding to an operation may be mapped to and implemented by an enforcement point having a capability to perform the operation. Once each operation of a security policy has been mapped to an enforcement point, a chain of enforcement points may be generated.

Patent Agency Ranking