US2021194760A1PendingUtilityA1

Dynamic segmentation in an industrial network based on inventory tags

Assignee: CISCO TECH INCPriority: Dec 20, 2019Filed: Apr 20, 2020Published: Jun 24, 2021
Est. expiryDec 20, 2039(~13.4 yrs left)· nominal 20-yr term from priority
H04L 43/20H04L 43/08H04L 41/147H04L 41/149H04L 41/0894H04L 41/40H04L 63/0263G06Q 10/0875H04L 63/20H04L 63/0245H04L 47/323H04L 47/2441H04L 47/20H04L 12/4641H04L 41/16H04L 43/10H04L 41/142H04L 41/145H04L 43/026H04L 41/0213H04L 41/0803G05B 19/05
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

According to one or more embodiments of the disclosure, a service obtains one or more component tags and one or more activity tags that were assigned to an endpoint device in a network based on deep packet inspection of traffic associated with the endpoint device. The service determines an intent of the endpoint device, using the one or more component tags and the one or more activity tags that were assigned to the endpoint device. The service translates the intent of the endpoint device into a network segmentation policy. The service configures a network overlay in the network that implements the network segmentation policy.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 obtaining, by a service, one or more component tags and one or more activity tags that were assigned to an endpoint device in a network based on deep packet inspection of traffic associated with the endpoint device;   determining, by the service, an intent of the endpoint device, using the one or more component tags and the one or more activity tags that were assigned to the endpoint device;   translating, by the service, the intent of the endpoint device into a network segmentation policy; and   configuring, by the service, a network overlay in the network that implements the ii network segmentation policy.   
     
     
         2 . The method as in  claim 1 , wherein determining the intent of the endpoint device comprises:
 receiving, at the service, an indication of one or more scalable group tags for the endpoint device; and   associating, by the service, the one or more scalable group tags with the endpoint device.   
     
     
         3 . The method as in  claim 2 , wherein translating the intent of the endpoint device into a network segmentation policy comprises:
 generating a security group access control list, based on the one or more scalable group tags associated with the endpoint device; and wherein configuring the network overlay in the network comprises:   sending the security group access control list to networking equipment in the network.   
     
     
         4 . The method as in  claim 2 , wherein indication of the one or more scalable group tags is received via a user interface. 
     
     
         5 . The method as in  claim 1 , wherein the network overlay restricts the endpoint device to communicating only with a subset of senders or receivers via the network, and wherein the network overlay further restricts the endpoint device to sending or receiving only a specific type of application traffic via the network. 
     
     
         6 . The method as in  claim 5 , wherein the one or more component tags are indicative of a physical location of the endpoint device, and wherein one or more of the senders or receivers in the subset are also located in that physical location. 
     
     
         7 . The method as in  claim 1 , wherein the endpoint device comprises a programmable logic controller (PLC) or variable-frequency drive (VFD). 
     
     
         8 . The method as in  claim 1 , wherein the network overlay is implemented as a Virtual Extensible Local Area Network (VxLAN) overlay in the network. 
     
     
         9 . An apparatus, comprising:
 one or more network interfaces to communicate with a network;   a processor coupled to the one or more network interfaces and configured to execute one or more processes; and   a memory configured to store a process that is executable by the processor, the process when executed configured to:
 obtain one or more component tags and one or more activity tags that were assigned to an endpoint device in a network based on deep packet inspection of traffic associated with the endpoint device; 
 determine an intent of the endpoint device, using the one or more component tags and the one or more activity tags that were assigned to the endpoint device; 
 translate the intent of the endpoint device into a network segmentation policy; and 
 is configure a network overlay in the network that implements the network segmentation policy. 
   
     
     
         10 . The apparatus as in  claim 9 , wherein the apparatus determines the intent of the endpoint device by:
 receiving an indication of one or more scalable group tags for the endpoint device; and   associating the one or more scalable group tags with the endpoint device.   
     
     
         11 . The apparatus as in  claim 10 , wherein the apparatus translates the intent of the endpoint device into a network segmentation policy by:
 generating a security group access control list, based on the one or more scalable group tags associated with the endpoint device; and wherein configuring the network overlay in the network comprises:   sending the security group access control list to networking equipment in the network.   
     
     
         12 . The apparatus as in  claim 11 , wherein indication of the one or more scalable group tags is received via a user interface. 
     
     
         13 . The apparatus as in  claim 9 , wherein the network overlay restricts the endpoint device to communicating only with a subset of senders or receivers via the network, and wherein the network overlay further restricts the endpoint device to sending or receiving only a specific type of application traffic via the network. 
     
     
         14 . The apparatus as in  claim 13 , wherein the one or more component tags are indicative of a physical location of the endpoint device, and wherein one or more of the senders or receivers in the subset are also located in that physical location. 
     
     
         15 . The apparatus as in  claim 9 , wherein the endpoint device comprises a programmable logic controller (PLC) or variable-frequency drive (VFD). 
     
     
         16 . The apparatus as in  claim 9 , wherein the network overlay is implemented as a Virtual Extensible Local Area Network (VxLAN) overlay in the network. 
     
     
         17 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a service to execute a process comprising:
 obtaining, by the service, one or more component tags and one or more activity tags that were assigned to an endpoint device in a network based on deep packet inspection of traffic associated with the endpoint device;   determining, by the service, an intent of the endpoint device, using the one or more component tags and the one or more activity tags that were assigned to the endpoint device;   translating, by the service, the intent of the endpoint device into a network segmentation policy; and   configuring, by the service, a network overlay in the network that implements the network segmentation policy.   
     
     
         18 . The computer-readable medium as in  claim 17 , wherein determining the intent of the endpoint device comprises:
 receiving, at the service, an indication of one or more scalable group tags for the endpoint device; and   associating, by the service, the one or more scalable group tags with the endpoint device.   
     
     
         19 . The computer-readable medium as in  claim 18 , wherein translating the intent of the endpoint device into a network segmentation policy comprises:
 generating a security group access control list, based on the one or more scalable group tags associated with the endpoint device; and wherein configuring the network s overlay in the network comprises:   sending the security group access control list to networking equipment in the network.   
     
     
         20 . The computer-readable medium as in  claim 19 , wherein the network overlay restricts the endpoint device to communicating only with a subset of senders or receivers via the network, and wherein the network overlay further restricts the endpoint device to sending or receiving only a specific type of application traffic via the network.

Join the waitlist — get patent alerts

Track US2021194760A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.