DNS or network metadata policy for network control

US9736185B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9736185-B1
Application numberUS-201514806476-A
CountryUS
Kind codeB1
Filing dateJul 22, 2015
Priority dateApr 21, 2015
Publication dateAug 15, 2017
Grant dateAug 15, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for configuring a network based on a Domain Name System (DNS) or network metadata policy for network control are disclosed. In some embodiments, a system, process, and/or computer program product for a DNS or network metadata policy for network control includes receiving a DNS or network metadata update at a DNS server (e.g., an authoritative or recursive DNS server) or an IP Address Management (IPAM) server, in which the DNS or network metadata update is determined to be relevant to the DNS or network metadata policy for network control; and sending the DNS or network metadata update to a network controller for a network, in which the network controller configures a plurality of network devices on the network based on the DNS or network metadata policy for network control.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for a Domain Name System (DNS) or network metadata policy for network control, comprising: a processor of a DNS or an IP Address Management (IPAM) server configured to: receive a DNS or network metadata update at the DNS or IPAM server, wherein the DNS or network metadata update is determined to be relevant to the DNS or network metadata policy for network control, and wherein the DNS or network metadata policy for network control includes a policy based on Domain Name System (DNS) zones, subzones, DNS wildcards, or any combination thereof or metadata associated with network configuration data including network CIDR blocks, network ranges, IP addresses, DNS records, or any combination thereof; send the DNS or network metadata update to a network controller for a network, wherein the network controller configures a plurality of network devices on the network based on the DNS or network metadata policy for network control, and wherein the sending of the DNS or network metadata update to the network controller to: perform one or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the metadata to an access control list; or move an IP address from a first set of IP addresses relevant to the policy or the metadata to a second set of IP addresses relevant to the policy or the metadata; and a memory coupled to the processor and configured to provide the processor with instructions. 2. The system of claim 1 , wherein the network controller is a Software Defined Networking (SDN) network controller, and wherein the plurality of network devices includes physical, virtual, or SDN based routers and/or switches. 3. The system of claim 1 , wherein the plurality of network devices includes physical, virtual, or Software Defined Networking (SDN) based routers and/or switches, and wherein the network includes network devices from a plurality of different vendors. 4. The system of claim 1 , wherein the DNS server is an authoritative DNS server or a recursive DNS server. 5. The system of claim 1 , wherein the network controller subscribes to DNS or network metadata updates from the DNS or IPAM server. 6. The system of claim 1 , wherein the DNS or IPAM server publishes DNS or network metadata updates to the network controller. 7. The system of claim 1 , wherein the DNS or IPAM server communicates with the network controller via an Application Programming Interface (API). 8. The system of claim 1 , wherein the DNS or IPAM server communicates with the network controller via a messaging protocol. 9. The system of claim 1 , wherein the processor is further configured to: determine whether the DNS or network metadata update is relevant to the DNS or network metadata policy for network control. 10. The system of claim 1 , wherein the sending of the DNS or network metadata update to the network controller to: perform two or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the metadata to an access control list; or move an IP address from a first set of IP addresses relevant to the policy or the metadata to a second set of IP addresses relevant to the policy or the metadata. 11. The system of claim 1 , wherein the sending of the DNS or network metadata update to the network controller to: perform three or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the metadata to an access control list; or move an IP address from a first set of IP addresses relevant to the policy or the metadata to a second set of IP addresses relevant to the policy or the metadata. 12. A method for a Domain Name System (DNS) or network metadata policy for network control, comprising: receiving a DNS or network metadata update at a DNS or IP Address Management (IPAM) server, wherein the DNS or network metadata update is determined to be relevant to the DNS or network metadata policy for network control, and wherein the DNS or network metadata policy for network control includes a policy based on Domain Name System (DNS) zones, subzones, DNS wildcards, or any combination thereof or metadata associated with network configuration data including network CIDR blocks, network ranges, IP addresses, DNS records, or any combination thereof; sending the DNS or network metadata update to a network controller for a network, wherein the network controller configures a plurality of network devices on the network based on the DNS or network metadata policy for network control, and wherein the sending of the DNS or network metadata update to the network controller to: perform one or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the metadata to an access control list; or move an IP address from a first set of IP addresses relevant to the policy or the metadata to a second set of IP addresses relevant to the policy or the metadata. 13. The method of claim 12 , wherein the DNS server is an authoritative DNS server or a recursive DNS server. 14. The method of claim 12 , wherein the network controller is a Software Defined Networking (SDN) network controller, wherein the plurality of network devices includes physical, virtual, or SDN based routers and/or switches, and wherein the network includes network devices from a plurality of different vendors. 15. The method of claim 12 , further comprising: determining whether the DNS or network metadata update is relevant to the DNS or network metadata policy for network control. 16. A computer program product for a Domain Name System (DNS) or network metadata policy for network control, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions for: receiving a DNS or network metadata update for a DNS or IP Address Management (IPAM) server, wherein the DNS or network metadata update is determined to be relevant to the DNS or network metadata policy for network control, and wherein the DNS or network metadata policy for network control includes a policy based on Domain Name System (DNS) zones, subzones, DNS wildcards, or any combination thereof or metadata associated with network configuration data including network CIDR blocks, network ranges, IP addresses, DNS records, or any combination thereof; sending the DNS or network metadata update to a network controller for a network, wherein the network controller configures a plurality of network devices on the network based on the DNS or network metadata policy for network control, and wherein the sending of the DNS or network metadata update to the network controller to: perform one or more of the following: add an IP address to a set of IP addresses relevant to the policy or the metadata; remove an IP address from the set of IP addresses relevant to the policy or the metadata; add the set of IP addresses relevant to the policy or the m

Assignees

Inventors

Classifications

  • Network management software packages · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Multiple levels of security · CPC title

  • Electricity · mapped topic

  • using domain name system [DNS] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9736185B1 cover?
Techniques for configuring a network based on a Domain Name System (DNS) or network metadata policy for network control are disclosed. In some embodiments, a system, process, and/or computer program product for a DNS or network metadata policy for network control includes receiving a DNS or network metadata update at a DNS server (e.g., an authoritative or recursive DNS server) or an IP Address…
Who is the assignee on this patent?
Infoblox Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 15 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).