Cisco Systems, Inc.
In-data-plane network policy enforcement using IP addresses

Last updated:

Abstract:

The present disclosure provides a method of embedding finer grained information such as user identity and application identity in IPv6 addresses used for end-to-end communications within a network. The finer grained information can be used for improved policy enforcement within the network. In one aspect, generating an address for an end-to-end communication within a network, the address including a user identifier and an application identifier for network policy enforcement; assigning the address to an application used in the end-to-end communication; and performing network segmentation and the network policy enforcement within the network using the address.

Status:
Grant
Type:

Utility

Filling date:

6 Jun 2019

Issue date:

24 Aug 2021