IP Library Granted Patent US 7,739,728
Granted Patent B1
US 7,739,728 · App. 11/329,854 · Granted Jun 15, 2010

End-to-end IP security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,739,728
App. No.
11/329,854
Granted
Jun 15, 2010
Kind
B1
Abstract

End-to-end security is established automatically for network communications. In one embodiment a first host is associated with a policy manager that determines, for the first host, whether a secure session is permissible. If the secure session is determined to be permissible then the policy manager signals to intermediate devices in order to prompt establishment of SA/DA pinholes. In an alternative embodiment a neutral policy broker determines, for both first and second hosts, whether the secure session is permissible and signals to the intermediate devices to establish the pinholes if the secure session is permissible. In another embodiment the end-to-end session includes back-to-back tunnel mode sessions linked by at least one intermediate device. The intermediate device is operative to decrypt and re-encrypt traffic in the session, and may be configured by a policy manager or policy broker. Further, another security association can be nested in one or more segments of the session in a manner that permits one host to access a third host or secure resource which is shielded from the second host.

Claims (44)

1. Apparatus for facilitating secure network communications between a first host in a first network and a second host in a second network, where a first policy enforcement point can disallow communications from the first host to the second host and an intermediate network device is logically interposed between the first policy enforcement point and the second host, comprising:

a first policy manager in the first network which is a physical device independent of the first and second hosts comprising:

physical storage including a security policy database operable to store data indicative of security policy applicable to the first host;

policy management logic operable in response to a request to establish a secure session between the first host and second host to determine based on data in the security policy database whether to allow the request; and

communication logic operable, if the request is determined to be allowed by the policy management logic, to signal to the intermediate network device in order to prompt automated establishment of a security pinhole for use by communications between the first host and the second host.

2. The apparatus of claim 1 wherein the secure session is a transport level session based encryption method, and the security pinhole is a source address/destination address (“SA/DA”) pinhole.

3. The apparatus of claim 1 wherein the communication logic is further operable to periodically signal to the intermediate network device in order to maintain the security pinhole.

4. The apparatus of claim 1 further including a second policy manager in the second network and second policy enforcement point for the second host.

5. The apparatus of claim 4 further including the option of providing for a common public key infrastructure (“PKI”) accessible by both the first and second policy mangers.

6. Apparatus for facilitating secure network communications between a first host in a first network and a second host in a second network, where a first policy enforcement point can disallow communications from the first host to the second host, a second policy enforcement point can disallow communications from the second host to the first host, and an intermediate network device is logically interposed between the first and second policy enforcement points, comprising:

a neutral policy broker, which is a physical device, in communication with both the first and second networks, but not logically disposed in either the first or second network, comprising:

physical storage including a master security policy database operable to store data indicative of security policy applicable to the first and second hosts;

policy management logic operable in response to a request to establish a secure session between the first host and second host to determine based on data in the security policy database whether to allow the request; and

communication logic operable, if the request is determined to be allowed by the policy management logic, to signal to the intermediate network device in order to prompt automated establishment of a security pinhole for use by communications between the first host and the second host.

7. The apparatus of claim 6 wherein the secure session is a transport level encrypted session such as IPsec transport mode, and the security pinhole is a source address/destination address (“SA/DA”) pinhole.

8. The apparatus of claim 6 wherein the communication logic is further operable to periodically signal to the intermediate network device in order to maintain the security pinhole.

9. Apparatus for facilitating secure network communications between a first host in a first network and a second host in a second network, where a first policy enforcement point can disallow communications from the first host to the second host, a second policy enforcement point can disallow communications from the second host to the first host, and an intermediate network device is logically interposed between the first and second policy enforcement points, comprising:

a neutral policy broker, which is a physical device, in communication with both the first and second networks, but not logically disposed in either the first or second network, comprising:

physical storage including a master security policy database operable to store data indicative of security policy applicable to the first and second hosts;

policy management logic operable in response to a request to establish a secure session between the first host and second host to determine based on data in the security policy database whether to allow the request; and

communication logic operable, if the request is determined to be allowed by the policy management logic, to signal to the intermediate network device in order to prompt automated establishment of a first encrypted tunnel mode session between the first host and the intermediate network device, and also to prompt automated establishment of a second encrypted tunnel mode session between the intermediate network device and the second host, thereby providing back-to-back encrypted tunnel mode sessions for which decryption and re-encryption is executed by the intermediate network device.

10. The apparatus of claim 9 further including logic operable in response to a request from the first host to prompt establishment of a security association between the first host and a third host, the security association being nested in the first encrypted tunnel and also being shielded from access by the second host.

11. A method for facilitating secure network communications between a first host in a first network and a second host in a second network, where a first policy enforcement point can disallow communications from the first host to the second host and an intermediate network device is logically interposed between the first policy enforcement point and the second host, comprising the steps of:

in a first policy manager which is a physical device independent of the first and second hosts in the first network,

storing, in a security policy database in physical storage, data indicative of security policy applicable to the first host;

determining, with policy management logic operable in response to a request to establish a secure session between the first host and second host, whether to allow the request based on data in the security policy database; and

signaling, with communication logic if the request is determined to be allowed by the policy management logic, to the intermediate network device in order to prompt automated establishment of a security pinhole for use by communications between the first host and the second host.

12. The method of claim 11 wherein the secure session is a transport level session based encryption method, and the security pinhole is a source address/destination address (“SA/DA”) pinhole.

13. The method of claim 11 further including the step of periodically signaling with the communication logic to the intermediate network device in order to maintain the security pinhole.

14. The method of claim 11 further including a second policy manager in the second network and second policy enforcement point for the second host.

15. The method of claim 14 further including the option of providing for a common public key infrastructure (“PKI”) accessible by both the first and second policy mangers.

16. A method for facilitating a secure network communications between a first host in a first network and a second host in a second network, where a first policy enforcement point can disallow communications from the first host to the second host, a second policy enforcement point can disallow communications from the second host to the first host, and an intermediate network device is logically interposed between the first and second policy enforcement points, comprising the steps of:

with a neutral policy broker, which is a physical device, in communication with both the first and second networks, but not logically disposed in either the first or second network,

storing data indicative of security policy applicable to the first and second hosts in a master security policy database in physical storage;

determining whether to allow the request, with policy management logic operable in response to a request to establish a secure session between the first host and second host, based on data in the security policy database; and

signaling, with communication logic operable if the request is determined to be allowed by the policy management logic, to the intermediate network device in order to prompt automated establishment of a security pinhole for use by communications between the first host and the second host.

17. The method of claim 16 wherein the secure session is a transport level encrypted session such as IPsec transport mode, and the security pinhole is a source address/destination address (“SA/DA”) pinhole.

18. The method of claim 16 including the further step of periodically signaling with the communication logic to the intermediate network device in order to maintain the security pinhole.

19. A method for facilitating secure network communications between a first host in a first network and a second host in a second network, where a first policy enforcement point can disallow communications from the first host to the second host, a second policy enforcement point can disallow communications from the second host to the first host, and an intermediate network device is logically interposed between the first and second policy enforcement points, comprising the steps of:

with a neutral policy broker, which is a physical device, in communication with both the first and second networks, but not logically disposed in either the first or second network,

storing data indicative of security policy applicable to the first and second hosts in a master security policy database in physical storage;

determining, with policy management logic operable in response to a request to establish a secure session between the first host and second host, based on data in the security policy database whether to allow the request; and

signaling, with communication logic operable if the request is determined to be allowed by the policy management logic, to the intermediate network device in order to prompt automated establishment of a first encrypted tunnel mode session between the first host and the intermediate network device, and also to prompt automated establishment of a second encrypted tunnel mode session between the intermediate network device and the second host, thereby providing back-to-back encrypted tunnel mode sessions for which decryption and re-encryption is executed by the intermediate network device.

20. The method of claim 19 further including the step of prompting establishment of a security association between the first host and the third host with logic operable in response to a request from the first host, the security association being nested in the first encrypted tunnel and also being shielded from access by the second host.

Assignments (23)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.
Reel/Frame 045045/0564 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 023892/0500 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.
Reel/Frame 044891/0564 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2010
From: NORTEL NETWORKS LIMITED
To: AVAYA INC.
Reel/Frame 023998/0878 →
SECURITY AGREEMENT Recorded Feb 5, 2010
From: AVAYA INC.
To: CITICORP USA, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 023905/0001 →
SECURITY AGREEMENT Recorded Feb 4, 2010
From: AVAYA INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 023892/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2006
From: KOEHLER, EDWIN JR.; SLEIMAN, CHERIF
To: NORTEL NETWORKS LIMITED
Reel/Frame 017464/0214 →