IP Library Granted Patent US 7,404,206
Granted Patent B2
US 7,404,206 · App. 10/198,728 · Granted Jul 22, 2008

Network security devices and methods

Assignee: YottaYotta, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,404,206
App. No.
10/198,728
Filed
Jul 16, 2002
Granted
Jul 22, 2008
Kind
B2
Art Unit
2131
USPC
713/153
Abstract

An OSI layer 2 network device on the edge of a network such as a SAN is configured to replace the original source address of traffic entering the network with a known identifier or address, which is used to signify that entry point as the traffic source to the other nodes of the network. Nodes of the network recognize the new source address as a valid source address. The network device also maintains state (e.g., association of original source address with new source address/identifier) so as to translate addresses to enable reply traffic to be sent back to the original sender.

Claims (37)

1. A method of providing enhanced security to a network using a network entry device, comprising:

receiving a first data packet from a host device at a first port of the network entry device, said first data packet having a source address field including a first layer 2 source address identifying the host device, a destination address field including a destination address identifying a destination device on the network, and a payload field including data;

replacing the first layer 2 source address with a private address identifying the first port on the network device so as to produce a first modified data packet; and

sending the first modified data packet to the destination device over the network, wherein nodes on the network recognize the private address as a valid address.

2. The method of claim 1 , wherein the network is a Fibre Channel network.

3. The method of claim 1 , wherein the network is a storage area network.

4. The method of claim 1 , wherein the network entry device is a controller card.

5. The method of claim 4 , wherein the controller card is implemented in an edge switch.

6. The method of claim 1 , wherein the host has a dedicated connection to the first port of the network entry device.

7. The method of claim 1 , further including:

creating an entry in an address table in the network entry device, said entry including the private address and the first layer 2 source address.

8. The method of claim 7 , further including, for subsequent packets received from the first host at the first port:

performing a lookup in the address table using the first layer 2 source address identifying the first host to obtain the corresponding private address; and

replacing the first layer 2 source address with said corresponding private address.

9. The method of claim 1 , further comprising:

receiving a reply data packet from the destination device, the reply data packet having said private address in a destination address field;

replacing the private address in the destination address field of the reply packet with said first layer 2 source address identifying the host so as to produce a modified reply packet; and

sending the modified reply packet to the host device.

10. A network device that provides enhanced security to a network, the device comprising:

a first network entry port for receiving data packets from a host device external to the network, wherein a first data packet is received from the host, said first data packet having a source address field including a first layer 2 source address identifying the host device, a destination address field including a destination address identifying a destination device on the network, and a payload field including data;

an address replacement module configured to replace layer 2 source addresses with private addresses, wherein the first layer 2 source address of the first data packet is replaced with a first private address identifying the first network entry port on the network device so as to produce a first modified data packet; and

a network port coupled to the network,

wherein the first modified data packet is sent from the network port to the destination device over the network, and wherein nodes on the network recognize the first private address as a valid address.

11. The device of claim 10 , wherein the network is a Fibre Channel network.

12. The device of claim 10 , wherein the network is a storage area network.

13. The device of claim 10 , wherein the device is implemented in a controller card on the edge of the network.

14. The device of claim 10 , further including a memory for storing an address table, wherein the address replacement module creates an entry in the address table, said entry including the first private address and the first layer 2 source address.

15. The device of claim 14 , wherein for subsequent packets received from the first host at the first network entry port, the address replacement module performs a lookup in the address table using the first layer 2 source address identifying the first host to obtain the corresponding private address, and replaces the first layer 2 source address with said corresponding private address.

16. The device of claim 10 , wherein the device receives a reply data packet from the destination device via the network port, the reply data packet having said private address in a destination address field, wherein the address replacement module is configured to replace the private address in the destination address field of the reply packet with said first layer 2 source address identifying the host so as to produce a modified reply packet, and wherein the modified reply packet is sent to the host device via the first network entry port.

17. The device of claim 10 , further including an encapsulation/decapsulation module, coupled to the address replacement module, configured to encapsulate modified data packets and decapsulate encapsulated modified reply packets.

18. A network device that provides enhanced security to a network, the device comprising:

one or more network entry ports for receiving data packets from one or more host devices external to the network, wherein a first data packet is received from a first host, said first data packet having a source address field including a first layer 2 source address identifying the first host device, a destination address field including a destination address identifying a destination device on the network, and a payload field including data;

an address replacement module configured to generate private addresses identifying network entry ports on the network device and to replace layer 2 source addresses with the private addresses, wherein the first layer 2 source address of the first data packet is replaced with a first private address identifying the first network entry port on the network device so as to produce a first modified data packet; and

a network port coupled to the network,

wherein the first modified data packet is sent from the network port to the destination device over the network, and wherein nodes on the network recognize the first private address as a valid address.

19. The device of claim 18 , further including a memory for storing an address table, wherein the address replacement module creates an entry in the address table, said entry including the first private address and the first layer 2 source address.

20. The device of claim 19 , wherein for subsequent packets received from the first host at the first network entry port, the address replacement module performs a lookup in the address table using the first layer 2 source address identifying the first host to obtain the corresponding private address, and replaces the first layer 2 source address with said corresponding private address.

Assignments (14)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2008
From: EMC CORPORATION OF CANADA
To: EMC CORPORATION
Reel/Frame 021936/0238 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2008
From: YOTTAYOTTA, INC.
To: EMC CORPORATION OF CANADA
Reel/Frame 021561/0597 →
SECURITY AGREEMENT Recorded Apr 10, 2007
From: YOTTAYOTTA, INC.
To: 1172038 ALBERTA ULC; PRYCES (BARBADOS) LTD. (C/O US VENTURES); TECHNOANGE, INC.; BANC OF AMERICA STRATEGIC INVESTMENTS CORPORATION; SHIGEMURA, BARTON; KARPOFF, WAYNE
Reel/Frame 019140/0340 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2003
From: MULLEN, PATRICK
To: YOTTA YOTTA, INC.
Reel/Frame 013950/0485 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2003
From: NOGHANIAN, SIMA; DWIVEDI, HIMANSHU; HAYWARD, GEOFF
To: YOTTA YOTTA, INC.
Reel/Frame 014385/0415 →
Continuity (2)
Provisional Application 6030653300 · Jul 17, 2001
Related Publication 20030126467A1 · Jul 3, 2003