Cloud Headend Access Designations for Leaner Routing Tables

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based Secure Access Service Edge (SASE) architectures, managing network traffic between numerous endpoints becomes burdensome due to the need for extensive routing and access control, especially when not all endpoints should be able to communicate with each other, leading to inefficient memory and network resource usage.

Innovation Solution

Implementing access designations for endpoints (isolated, shared, private, public) to streamline routing tables, allowing only permitted communications, reducing the number of entries needed in data nodes' routing tables.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If all endpoints are allowed to access all other locations in a SASE architecture, then network connectivity and accessibility are maximized, but routing table complexity and memory resource consumption increase significantly

Engineering Contradiction:
Improvenetwork connectivityVSAvoidrouting table complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network access permissions by creating hierarchical groups (enterprise-level, location-level, and endpoint-level groups) with defined access policies. Instead of managing individual endpoint-to-endpoint routing rules, the system organizes endpoints into structured groups with inheritance hierarchies, where parent groups contain child groups and policies cascade down the hierarchy. This segmentation reduces routing table complexity while maintaining comprehensive network connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to access control by organizing endpoints into multi-level groups with inheritance relationships. Rather than flat, pairwise access control, the system adds hierarchical layers (enterprise → location → endpoint groups) that enable scalable access management. This dimensional change allows the routing tables to scale efficiently as the network grows.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If extensive routing rules are implemented to control access between specific locations, then security and access control are improved, but network resource usage and processing overhead increase

Engineering Contradiction:
Improveaccess controlVSAvoidnetwork resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by pre-configuring hierarchical access policies at group levels before endpoints need to communicate. Access permissions are established at the enterprise and location group levels in advance, and these policies are automatically inherited by child groups and endpoints. When endpoints need to communicate, the routing decision is made by checking hierarchical group memberships rather than evaluating extensive individual access rules, significantly reducing processing overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates universal access policies at hierarchical group levels that apply to multiple endpoints simultaneously. A single access policy configured at an enterprise group level automatically applies to all location groups and endpoints within that enterprise, eliminating the need to configure and process individual access rules for each endpoint pair. This multi-functionality reduces network resource usage while maintaining comprehensive access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the number of endpoints and services headends scales up, then network coverage and service capability are enhanced, but the number of routing entries and propagation burden increase exponentially

Engineering Contradiction:
Improvenetwork coverageVSAvoidrouting table entries
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent segments the scaling burden by organizing endpoints into hierarchical groups that can be independently managed. As the network scales, new endpoints are added to existing groups or new groups are created within the hierarchical structure, rather than requiring individual routing entries for each new endpoint. This segmentation allows network coverage to expand while routing table entries grow linearly rather than exponentially.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds hierarchical grouping as a new dimension to endpoint organization, transforming the scaling problem from managing individual endpoint relationships to managing group relationships. The hierarchical structure (enterprise groups containing location groups containing endpoint groups) allows the system to scale to thousands of endpoints by managing only the group hierarchy and inheritance relationships, dramatically reducing the number of routing table entries needed.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12457216B2Access control and routing optimization at a cloud headend in a cloud-based secure access service environment
Publication Date: 2025.10.28 CISCO TECHNOLOGY INC
  • US12457216B2 patent drawing
  • US12457216B2 patent drawing
  • US12457216B2 patent drawing

AI summary

In one aspect, the present disclosure is directed to a method that includes receiving, at an edge component of a cloud-based secure access service, a corresponding access designation for each of a plurality of endpoints, each access designation specifying a type of access a corresponding endpoint has to remaining ones of the plurality of endpoints and other accessible network resources; based on the corresponding access designation of each of the plurality of endpoints, updating a routing table at the edge component, to include routing information for a subset of the plurality of endpoints having access to at least one other endpoint of the plurality of endpoints or to the other accessible network resources; and enabling routing of network traffic, via the cloud-based secure access service, between any number of the plurality of endpoints based at least in part on the routing table.