Policy-Based Packet Inspection via SmartNICs for Zero-Trust Workloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional perimeter-based security models are inadequate in modern networks due to the dispersion of data and access points beyond the traditional network perimeter, making it difficult to enforce security controls effectively against sophisticated cyber threats that can bypass defenses and move laterally within the network.

Innovation Solution

Implementing a transparent intercepting agent within network interfaces, such as SmartNICs or DPUs, to perform policy-based deep packet inspection and enforce zero-trust principles by continuously verifying and blocking malicious content at the endpoint level, using a control plane to dynamically update security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If perimeter-based security models are used, then network boundary protection is simplified, but security effectiveness deteriorates due to dispersed data and access points beyond the traditional perimeter

Engineering Contradiction:
Improvesecurity model complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security function by deploying intercepting agents at individual endpoint devices rather than relying on a centralized perimeter firewall. Each endpoint device independently performs packet inspection and security enforcement, dividing the security function across multiple distributed locations to address the dispersion of data and access points beyond the traditional network perimeter.

Inventive Principle:
Principle #1Segmentation

2Reliability

If deep packet inspection is performed at the endpoint level, then threat detection capability is improved, but processing time and network throughput are reduced

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by enabling each endpoint device to perform security inspection only for packets relevant to its specific workload and policy requirements, rather than inspecting all traffic uniformly. The intercepting agent selectively inspects packets based on local security policies and packet characteristics, optimizing the balance between detection capability and processing efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs partial deep packet inspection by examining only the necessary portions of packets based on policy rules and threat indicators, rather than always performing full inspection. This selective inspection approach maintains threat detection capability while reducing processing overhead for legitimate traffic.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If transparent intercepting agents are injected into network interfaces, then zero-trust verification is achieved, but device complexity and configuration overhead increase

Engineering Contradiction:
Improvezero-trust verificationVSAvoidendpoint device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intercepting agents perform self-service by automatically enforcing security policies locally at each endpoint without requiring manual configuration or intervention. The agents independently make security decisions based on received policies, eliminating the need for complex centralized management and reducing configuration overhead while maintaining zero-trust verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary control plane that communicates security policies to the intercepting agents, separating the complex policy management function from the endpoint devices. This intermediary layer simplifies endpoint configuration by delivering pre-processed security rules rather than requiring direct configuration of complex security logic at each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4633085A1Policy-based transparent packet inspection for last mile zerotrust workload protection
Publication Date: 2025.10.15 CISCO TECHNOLOGY INC
  • EP4633085A1 patent drawingFigure 1
  • EP4633085A1 patent drawingFigure 2
  • EP4633085A1 patent drawingFigure 3

AI summary

Disclosed are systems, apparatuses, methods, and computer-readable media for policy-based transparent packet inspection for last mile zero-trust workload protection. The method comprises receiving a packet on a network interface of a provisioned resource in a data center or a user device within a network; determining, by a first intercepting agent provisioned within the network interface, whether to inspect the packet based on rules received from a control plane of the network, wherein the network interface comprises a smart network interface card (SmartNIC) or a data processing unit (DPU) and is configured with the first intercepting agent based on the control plane; selectively invoking a deep packet inspection of the packet based on inspection of the packet by the first intercepting agent using the rules from the control plane; and blocking the packet at the network interface based on the deep packet inspection identifying malicious content within the packet.