Invention Grant
US09509574B2 End-to-end policy enforcement in the presence of a traffic midpoint device
有权
在流量中点设备存在的情况下实施端到端策略
- Patent Title: End-to-end policy enforcement in the presence of a traffic midpoint device
- Patent Title (中): 在流量中点设备存在的情况下实施端到端策略
-
Application No.: US14934850Application Date: 2015-11-06
-
Publication No.: US09509574B2Publication Date: 2016-11-29
- Inventor: Paul J. Kirner , Hai Xiao , Juraj G. Fandli , Michael J. Carlton
- Applicant: Illumio, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Illumio, Inc.
- Current Assignee: Illumio, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Fenwick & West LLP
- Main IPC: G06F15/177
- IPC: G06F15/177 ; H04L12/24

Abstract:
A global manager computer generates management instructions for a particular managed server within an administrative domain according to a set of rules. A global manager computer identifies a traffic midpoint device through which the provider managed server provides a service to a user device. The global manager determines a relevant rule from the set of rules that is applicable to communication between the provider managed server and the user device and generates a backend rule that is applicable to communication between the provider managed server and the traffic midpoint device. The global managed generates a backend function-level instruction including a reference to an actor-set authorized to communicate with the provider managed server to use the service. The global manager sends the backend function-level instruction to the provider managed server to configure the provider managed server to enforce the backend rule on communication with the actor-set including the traffic midpoint device.
Public/Granted literature
- US20160294646A1 END-TO-END POLICY ENFORCEMENT IN THE PRESENCE OF A TRAFFIC MIDPOINT DEVICE Public/Granted day:2016-10-06
Information query