Patent · US Active

Microsegmentation in heterogeneous software defined networking environments

US10171507B2 · kind B2 · utility

4Cited by
3References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 19, 2016
Grant dateJan 1, 2019
Priority date
Expiry dateDec 16, 2036

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0428
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Microsegmentation in a heterogeneous software-defined network can be performed by classifying endpoints associated with a first virtualized environment into respective endpoint groups based on respective attributes, and classifying endpoints associated with a second virtualized environment into respective security groups based on respective attributes. Each respective endpoint group can correspond to a respective security group having the same attribute. Each respective endpoint group and corresponding security group can be associated with a respective policy model defining rules for processing associated traffic. Each of the respective security groups can be used to generate a respective network attribute endpoint group, which can include the network addresses of those endpoints in the respective security group. Each respective network attribute endpoint group can inherit the policy model of the respective endpoint group corresponding to the respective security group. Traffic between the endpoints can then be processed based on the various classifications and associated rules.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.