IP Library Granted Patent US 9,036,647
Granted Patent B2
US 9,036,647 · App. 13/727,978 · Granted May 19, 2015

Method and apparatus for network security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,036,647
App. No.
13/727,978
Granted
May 19, 2015
Kind
B2
Abstract

A method of securely routing data traffic between communication networks. In an integrated security device, a host router supports a virtual router that peers with VRF (virtual routing and forwarding) instances associated with participating networks on the host router. Each VRF instance preferably runs its own dynamic routing protocol and determines when received data traffic may be directly forwarded from one network to another and when it must be forwarded to an OE (offload engine) for enforcement of security policies or NAT (network address translation) processing.

Claims (31)

1. A method of routing data traffic between networks, comprising:

receiving the data traffic from a source network;

determining whether the data traffic may be directly forwarded to a destination network, wherein determining whether the data traffic may be directly forwarded to the destination network comprises running a first instance of VRF (virtual routing and forwarding);

forwarding the data traffic to an OE (offload engine) if it is determined that the data traffic may not be directly forwarded to the destination network;

replacing a delineator associated with any data traffic that has been forwarded to the OE, wherein replacing the delineator comprises removing a delineator associated with the first VRF instance and replacing it with a delineator associated with the second VRF instance; and

forwarding any data traffic that has been forwarded to the OE from the OE to the destination network, wherein forwarding the data traffic from the OE to the destination network comprises running a second instance of VRF.

2. The method of claim 1 , further comprising forwarding the data traffic directly to the destination network if it is determined that the traffic may be forwarded directly to the destination network.

3. The method of claim 1 , further comprising inspecting data traffic that has been forwarded to the OE.

4. The method of claim 1 , wherein forwarding the traffic from the OE comprises reference to static routing tables.

5. The method of claim 1 , further comprising running an instance of a dynamic routing protocol in association with the OE.

6. The method of claim 5 , wherein the dynamic routing protocol is OSPF (open shortest path first).

7. The method of claim 5 , further comprising performing IP (internet protocol) address translation.

8. The method of claim 1 , wherein the delineator is a VID (VLAN (virtual local area network) ID).

9. The method of claim 1 , wherein the delineator is an MPLS (multiprotocol label switching) label.

10. The method of claim 1 , wherein forwarding the data traffic from the OE comprises forwarding the data traffic to a packet processor in communication with the OE.

11. The method of claim 10 , further comprising adding an embedded routing header to the data traffic prior to forwarding the data traffic to the packet processor.

12. The method of claim 11 , wherein the embedded routing header is a HiGig™ header.

13. Apparatus for routing data traffic between networks, comprising:

a processor;

an OE; and

a non-transitory memory device comprising program instructions that when executed cause the apparatus to:

receive data traffic from a source network;

determine whether the data traffic may be directly forwarded to a destination network, wherein determining whether the data traffic may be directly forwarded to the destination network comprises running a first instance of VRF;

forward the data traffic to an OE if it is determined that the data traffic may not be directly forwarded to the destination network;

replace a delineator associated with any data traffic that has been forwarded to the OE, wherein replacing the delineator comprises removing a delineator associated with the first VRF instance and replacing it with a delineator associated with the second VRF instance; and

forward any data traffic that has been forwarded to the OE from the OE to the destination network, wherein forwarding the data traffic from the OE to the destination network comprises running a second instance of VRF.

14. The apparatus of claim 13 , wherein memory device further comprises program instructions that when executed cause the apparatus to forward the data traffic directly to the destination network if it is determined that the traffic may be forwarded directly to the destination network.

15. The apparatus of claim 13 , wherein memory device further comprises program instructions that when executed cause the apparatus to inspect data traffic that has been forwarded to the OE.

16. The apparatus of claim 13 , wherein memory device further comprises program instructions that when executed cause the apparatus to run an instance of a dynamic routing protocol in association with the OE.

17. The apparatus of claim 13 , wherein memory device further comprises program instructions that when executed cause the apparatus to forward data traffic forward data traffic that is being forwarded from the OE to a packet processor in communication with the OE.

18. The apparatus of claim 17 , wherein memory device further comprises program instructions that when executed cause the apparatus to add an embedded routing header to the data traffic prior to forwarding the data traffic to the packet processor.

Assignments (12)
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033949/0016 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2014
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 032121/0290 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2013
From: YEH, CHIANG; HELMERICH, LAWRENCE; MOHANDAS, SINDHU; SINHA, ABHISHEK; PAGE, GREGORY G.; OTT, PETER; FERREIRA, ANDREW
To: ALCATEL-LUCENT USA INC.
Reel/Frame 031272/0491 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →