IP Library Granted Patent US 8,051,474
Granted Patent B1
US 8,051,474 · App. 11/535,425 · Granted Nov 1, 2011

Method and apparatus for identifying trusted sources based on access point

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,051,474
App. No.
11/535,425
Granted
Nov 1, 2011
Kind
B1
Abstract

Methods and systems for distinguishing between sources of messages at a computer system resource are provided. In particular, messages are classified according to the physical interface at which the messages are received. A message received at an interface connected to a trusted source has the port address associated with that message mapped to a predefined port address by a firewall computer, before being passed to a server computer or other system resource. A message received at an interface that is connected to an untrusted source is passed to the server computer using the original port address. The server computer may then treat messages associated with one of the reserved port addresses differently from messages associated with a non-reserved port address.

Claims (46)

1. A method for distinguishing sources of data, comprising:

defining a first set of reserved port addresses on a firewall computer;

mapping, by the firewall computer, data comprising a first communication received at a first interface to one of the first set of reserved port addresses;

mapping, by the firewall computer, data comprising a second communication received at a second interface to a port address not included in the first set of reserved port addresses;

based on the mapping of the first communication to one of the first set of reserved port addresses, applying, by the firewall computer, a first type of security measures with respect to the first communication, wherein the first type of security measures are a first level of verification and authentication;

determining that the first interface is interconnected to a trusted data source;

in response to the determining that the first interface is interconnected to the trusted data source, establishing a rule that communications received at the first interface that are not addressed to one of the first set of reserved port addresses are mapped to one of the first set of reserved port addresses;

based on the mapping of the second communication to a port address not included in the first set of reserved port addresses, applying, by the firewall computer, a second type of security measures with respect to the second communication received at the second interface, wherein the second type of security measures are a second level of verification and authentication, wherein the security measures of the first type are a lower level of verification and authentication than the security measures of the second type;

determining that the second interface is interconnected to a data source that is not trusted;

in response to the determining that the second interface is interconnected to the data source that is not trusted, establishing a rule that communications received at the second interface that are not addressed to one of the reserved port addresses are not mapped to one of the reserved port addresses.

2. The method of claim 1 , wherein the first communication received at the first interface, as received at the firewall computer, is not addressed to one of the reserved port addresses, and wherein the second communication received at the second interface, as received at the firewall computer, is not addressed to one of the reserved port addresses.

3. The method of claim 2 , further comprising:

blocking a communication received at any interface that as received is addressed to one of the reserved port addresses.

4. The method of claim 1 , further comprising:

passing the first communication mapped to the one of the reserved port addresses from a first device associated with the first and second interfaces to a second device, wherein the second device applies or causes to be applied the first type of security measures;

passing the second communication addressed to a port not included in the first set of reserved port addresses to the second device, wherein the first device applies or causes to be applied the second type of security measures.

5. The method of claim 1 , wherein the security measures of a first type do not require a user to provide any proof of identity in order to access a resource through the firewall computer, and wherein the security measures of a second type require a user to provide proof of their identity in order to access a resource through the first device.

6. The method of claim 1 , wherein the security measures of a first type require that a user enter a password before accessing a resource, and wherein the security measures of a second type require that a user enter a password and provide proof of their identity in addition to a password.

7. A system for distinguishing and treating messages from different sources differently, comprising:

a firewall computer, including:

a plurality of source interfaces;

a server interface;

a list of reserved port addresses, wherein at least one of the source interfaces is a trusted source interface that is mapped to one of the list of reserved port addresses;

program code configured to implement a set of rules associated with verification and authentication of messages received at the source interface;

wherein a first message received at the at least one trusted source interface is addressed to one of the reserved port addresses and passed to the server interface, wherein, a first level of verification and authentication is applied to the first message based on the first message being addressed to one of the list of reserved port addresses; and

wherein a second message received at one of the source interfaces is not addressed to one of the reserved port addresses, wherein, a second level of verification and authentication is applied to the second message based on the second message being addressed to a port address not included on one of the list of reserved port addresses;

a server computer, including:

an interconnection to the server interface of the firewall computer;

program code configured to direct the first message addressed to one of the reserved port address to a first application and to direct the second message not addressed to one of the reserved port addresses to a second application;

wherein the first application implements a first set of security requirements, wherein the second application implements a second set of security requirements, and wherein the first set of security requirements are a lower level than the second set of security requirements.

8. The system of claim 7 , further comprising:

a first source interconnected to the at least one trusted source interface.

9. The system of claim 8 , wherein the first source is interconnected to the at least one trusted source interface by a wireline connection.

10. The system of claim 8 , further comprising:

a second source interconnected to a source interface that is not mapped to one of the reserved port addresses.

11. The system of claim 8 , wherein the first and second applications are running on the server computer.

12. The system of claim 7 , wherein the programming code configured to implement a set of rules blocks any message received at any source interface that is addressed to a port address included in the list of reserved port addresses.

13. A system for identifying a source of messages, comprising:

means for interfacing a firewall computer with two or more sources

means to receive two or more messages from the two or more sources;

means for identifying a set of reserved port addresses, wherein at least one of the sources is a trusted source interface mapped to one of the set of reserved port addresses on the firewall computer;

means for mapping a first message received from one of the two or more sources to one of said set of reserved port addresses, wherein a first level of authentication and verification is applied to the first message, based on the first message being addressed to one of the reserved port addresses;

means for mapping a second message received from one of the two or more sources to an address port that is not included in said set of reserved port addresses;

means for applying a second level of authentication and verification to the second message received from one of the two or more sources based on the mapping of the second message to the port address not included in said set of reserved port addresses;

means for directing the first message addressed to one of the reserved port address to a first application and means for directing the second message not included in said set of reserved port addresses to a second application;

wherein the first application implements a first set of security requirements, wherein the second application implements a second set of security requirements, and wherein the first set of security requirements are a lower level than the second set of security requirement.

Assignments (23)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
BANKRUPTCY COURT ORDER RELEASING THE SECURITY INTEREST RECORDED AT REEL/FRAME 020156/0149 Recorded Jul 25, 2022
From: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
To: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES
Reel/Frame 060953/0412 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
RELEASE OF SECURITY INTEREST Recorded Jan 9, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.; AVAYA TECHNOLOGY, LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
Reel/Frame 045032/0213 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
REASSIGNMENT Recorded Jun 26, 2008
From: AVAYA TECHNOLOGY LLC
To: AVAYA INC
Reel/Frame 021156/0689 →
SECURITY AGREEMENT Recorded Nov 28, 2007
From: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
To: CITICORP USA, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 020166/0705 →
SECURITY AGREEMENT Recorded Nov 27, 2007
From: AVAYA, INC.; AVAYA TECHNOLOGY LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 020156/0149 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2006
From: BEDIN, OEYSTEIN; BLACK, RODNEY W.; BROWN, STEWART M., JR.
To: AVAYA TECHNOLOGY LLC
Reel/Frame 018311/0013 →