IP Library Granted Patent US 12706912
Granted Patent B1
US 12706912 · App. 17/966,790 · Granted Aug 11, 2026

Dynamic centralized access list/firewall management

Inventor: Bradley Hultine (Centennial, CO)
Assignee: CHARTER COMMUNICATIONS OPERATING, LLC
H04L63/101H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706912
App. No.
17/966,790
Granted
Aug 11, 2026
Kind
B1
Abstract

For a communications network having a plurality of network security elements and a plurality of existing network security element specification files which limit packet flow on the network security elements, obtain, from a user, instructions to compose at least one of: a new network security element specification file; or one of the existing network security element specification files. Facilitate queuing a configuration change request that implements the instructions in an implementation pipeline. Facilitate pushing the configuration change request to at least one corresponding network security element of the plurality of network security elements.

Claims (82)

1 . A method comprising:

for a communications network having a plurality of network security elements and a plurality of existing network security element specification files which limit packet flow on the network security elements, obtaining, from a user, instructions to compose at least one of:

a new network security element specification file; or

one of the existing network security element specification files;

facilitating generating a configuration change request by translating at least one fully qualified domain name into at least one corresponding internet protocol address for inclusion in the configuration change request;

facilitating queuing the configuration change request that implements the instructions in an implementation pipeline;

facilitating recording the configuration change request into a version control mechanism;

facilitating pushing the configuration change request to at least one corresponding network security element of the plurality of network security elements; and

facilitating rolling back the configuration change request based on the version control mechanism in response to a detection of a failure associated with the configuration change request.

2 . The method of claim 1 , further comprising inventorying the plurality of network security elements and the plurality of existing network security element specification files in a database.

3 . The method of claim 2 , wherein the plurality of network security elements comprise a plurality of routers, the plurality of network security element specification files comprise a plurality of router access control lists, and the at least one corresponding network security element of the plurality of network security elements comprises at least one corresponding router of the plurality of routers.

4 . The method of claim 3 , further comprising:

updating the database to reflect the configuration change request; and

memorializing the configuration change request in a configuration management system.

5 . The method of claim 4 , further comprising assigning a unique name to each of the plurality of router access control lists, wherein each of the plurality of router access control lists is identified in the database by the assigned unique name.

6 . The method of claim 5 , further comprising employing a given one of the router access control lists on at least two routers of the plurality of routers.

7 . The method of claim 4 , further comprising, prior to queuing the configuration change request that implements the instructions:

displaying changes resulting from the instructions to the user; and

obtaining, from the user, verification to proceed with the displayed changes.

8 . The method of claim 4 , further comprising operating the communications network having the plurality of routers and the plurality of router access control lists in accordance with the pushed configuration change request.

9 . The method of claim 8 , wherein the operating includes blocking inbound traffic on at least one port of the at least one corresponding router in accordance with the pushed configuration change request.

10 . The method of claim 8 , wherein the communications network comprises a video content network and wherein the operating of the network includes carrying at least 10 Gbps of video content, without the use of firewalls.

11 . The method of claim 4 , wherein the configuration change request is pushed automatically.

12 . The method of claim 4 , wherein the configuration change request is pushed responsive to approval by an administrator.

13 . The method of claim 4 , wherein the configuration change request is pushed responsive to a daemon detecting a change in a configuration change request queue.

14 . The method of claim 3 , wherein:

the plurality of router access control lists limit the packet flow on the routers based on given internet protocol addresses; and

in the step of obtaining, from the user, the instructions to compose one of the router access control lists, the instructions specify rules based on the at least one fully qualified domain name.

15 . The method of claim 2 , wherein the plurality of network security elements comprise a plurality of firewalls, the plurality of network security element specification files comprise a plurality of firewall configuration files, and the at least one corresponding network security element of the plurality of network security elements comprises at least one corresponding firewall of the plurality of firewalls.

16 . A non-transitory computer readable medium comprising computer executable instructions which when executed by a computer cause the computer to perform a method comprising:

for a communications network having a plurality of network security elements and a plurality of existing network security element specification files which limit packet flow on the network security elements, obtaining, from a user, instructions to compose at least one of:

a new network security element specification file; or

one of the existing network security element specification files;

facilitating generating a configuration change request by translating at least one fully qualified domain name into at least one corresponding internet protocol address for inclusion in the configuration change request;

facilitating queuing the configuration change request that implements the instructions in an implementation pipeline;

facilitating recording the configuration change request into a version control mechanism;

facilitating pushing the configuration change request to at least one corresponding network security element of the plurality of network security elements; and

facilitating rolling back the configuration change request based on the version control mechanism in response to a detection of a failure associated with the configuration change request.

17 . A system comprising:

a memory; and

at least one processor, coupled to the memory, and operative to:

for a communications network having a plurality of network security elements and a plurality of existing network security element specification files which limit packet flow on the network security elements, obtain, from a user, instructions to compose at least one of:

a new network security element specification file; or

one of the existing network security element specification files;

facilitate generating a configuration change request by translating at least one fully qualified domain name into at least one corresponding internet protocol address for inclusion in the configuration change request;

facilitate queuing the configuration change request that implements the instructions in an implementation pipeline;

facilitate recording the configuration change request into a version control mechanism;

facilitate pushing the configuration change request to at least one corresponding network security element of the plurality of network security elements; and

facilitate rolling back the configuration change request based on the version control mechanism in response to a detection of a failure associated with the configuration change request.

18 . The system of claim 17 , wherein the at least one processor is further operative to inventory the plurality of network security elements and the plurality of existing network security element specification files in a database.

19 . The system of claim 18 , wherein the plurality of network security elements comprise a plurality of routers, the plurality of network security element specification files comprise a plurality of router access control lists, and the at least one corresponding network security element of the plurality of network security elements comprises at least one corresponding router of the plurality of routers.

20 . The system of claim 19 , wherein the at least one processor is further operative to:

update the database to reflect the configuration change request; and

memorialize the configuration change request in a configuration management system.

21 . The system of claim 20 , wherein the at least one processor is further operative to assign a unique name to each of the plurality of access control lists, wherein each of the plurality of access control lists is identified in the database by the assigned unique name.

22 . The system of claim 21 , wherein the at least one processor is further operative to employ a given one of the access control lists on at least two routers of the plurality of routers.

23 . The system of claim 20 , wherein the at least one processor is further operative to facilitate operating the communications network having the plurality of routers and the plurality of access control lists in accordance with the pushed configuration change request.

24 . The system of claim 23 , wherein the operating includes blocking inbound traffic on at least one port of the at least one corresponding router in accordance with the pushed configuration change request.

25 . The system of claim 23 , wherein the communications network comprises a video content network and wherein the operating of the network includes carrying at least 10 Gbps of video content, without the use of firewalls.

26 . The system of claim 18 , wherein the plurality of network security elements comprise a plurality of firewalls, the plurality of network security element specification files comprise a plurality of firewall configuration files, and the at least one corresponding network security element of the plurality of network security elements comprises at least one corresponding firewall of the plurality of firewalls.

27 . A system comprising:

a communications network having a plurality of network security elements and a plurality of existing network security element specification files which limit packet flow on the network security elements; and

a backend coupled to the plurality of network security elements;

wherein:

the backend is configured to obtain, from a user, instructions to compose at least one of:

a new network security element specification file; or

one of the existing network security element specification files; and

the backend is configured to facilitate generating a configuration change request by translating at least one fully qualified domain name into at least one corresponding internet protocol address for inclusion in the configuration change request; facilitate recording the configuration change request into a version control mechanism, facilitate queuing the configuration change request that implements the instructions in an implementation pipeline, to cause the configuration change request to be pushed to at least one corresponding network security element of the plurality of network security elements, and facilitate rolling back the configuration change request based on the version control mechanism in response to a detection of a failure associated with the configuration change request.

28 . The system of claim 27 , further comprising a database coupled to the backend, wherein the backend is configured to inventory the plurality of network security elements and the plurality of existing network security element specification files in the database.

29 . The system of claim 28 , wherein the plurality of network security elements comprise a plurality of routers, the plurality of network security element specification files comprise a plurality of router access control lists, and the at least one corresponding network security element of the plurality of network security elements comprises at least one corresponding router of the plurality of routers.

30 . The system of claim 29 , wherein a given one of the access control lists is employed on at least two routers of the plurality of routers.

31 . The system of claim 30 , wherein at least one of the routers is configured to block inbound traffic on at least one port in accordance with the pushed configuration change request.

32 . The system of claim 30 , wherein the communications network comprises a video content network that carries at least 10 Gbps of video content, without the use of firewalls.

33 . The system of claim 28 , wherein the plurality of network security elements comprise a plurality of firewalls, the plurality of network security element specification files comprise a plurality of firewall configuration files, and the at least one corresponding network security element of the plurality of network security elements comprises at least one corresponding firewall of the plurality of firewalls.

34 . A method comprising:

for a communications network having a plurality of network security elements and a plurality of existing network security element specification files which limit packet flow on the network security elements, obtaining, from a user, instructions to compose at least one of:

a new network security element specification file; or

one of the existing network security element specification files;

facilitating queuing a configuration change request that implements the instructions in an implementation pipeline;

facilitating pushing the configuration change request to at least one corresponding network security element of the plurality of network security elements;

wherein the plurality of network security elements comprise a plurality of routers, the plurality of network security element specification files comprise a plurality of router access control lists, the at least one corresponding network security element of the plurality of network security elements comprises at least one corresponding router of the plurality of routers, wherein the communications network comprises a video content network, and wherein the operating of the network includes carrying at least 10 Gbps of video content, without the use of firewalls;

further comprising operating the communications network having the plurality of routers and the plurality of router access control lists in accordance with the pushed configuration change request.