IP Library Granted Patent US 9,419,941
Granted Patent B2
US 9,419,941 · App. 13/849,315 · Granted Aug 16, 2016

Distributed computer network zone based security architecture

Inventors: Yi Sun (San Jose, CA); Meng Xu (Los Altos, CA); Lee Cheung (Foster City, CA); Hsisheng Wang (Santa Clara, CA); Chuong-Yaw Michael Shieh (Palo Alto, CA)
Assignee: VARMOUR NETWORKS, INC.
H04L63/0209H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,419,941
App. No.
13/849,315
Granted
Aug 16, 2016
Kind
B2
Abstract

A method and apparatus is disclosed herein for distributed zone-based security. In one embodiment, the method comprises: determining an ingress security zone associated with an ingress of a first network device based on a first key and a media access control (MAC) address of a source of a packet; determining an egress security zone of a second network device based on a MAC address of a destination for the packet and a second key; performing a policy lookup based on the ingress security zone and the egress security zone to identify a policy to apply to the packet; and applying the policy to the packet.

Claims (28)

1. A method comprising:

binding individual ports of a first network device to a security zone;

determining an ingress security zone associated with a packet received at an ingress port of the first network device based on a first key that identifies the first network device and a media access control (MAC) address of a source of a packet, wherein the ingress port of the first network device is bound to a first security zone prior to receipt of the packet at the ingress port, wherein the first security zone for the ingress port is defined by a first security level and the first key;

determining, from a MAC address for a destination of the packet, a second key that identifies a second network device that has an egress port for communicating the packet to the destination, wherein a software defined network (SDN) protocol is queried to determine the destination for the packet;

determining an egress security zone associated with the egress port of the second network device based on the egress port and the second key, wherein the egress port of the second network device is bound to a second security zone prior to transmission of the packet at the egress port, wherein the second security zone for the egress port is defined by a second security level and the second key;

performing a policy lookup based on the first security level and the first key of the ingress security zone and the second security level and the second key of the egress security zone in a policy table, wherein the policy lookup identifies a policy to apply to the packet when first security level and the second security level are different security levels, and wherein the policy lookup identifies a second policy allowing the forwarding of the packet when first security level of the first security zone and the second security level of the second security zone are at a same security level regardless of values of the first key and the second key;

applying the policy to the packet based on the first security level and the second security level when the ingress security zone and the egress security zone are different security zones; and

sending the packet to the destination based on the second key and an identifier of the destination, wherein layer 2 (L2) processing is performed at the destination to determine a final physical egress port for the packet, and wherein the L2 processing comprises a MAC lookup operation.

2. The method defined in claim 1 wherein the first network device is a security gateway device.

3. A network device for use in a distributed network environment having a plurality of network devices, the network device comprising:

a memory;

a network interface to receive IP packets; and

a processor, coupled to the memory and the network interface, operable to bind individual ports of a first network device to a security zone;

determine an ingress security zone associated with a packet received at an ingress port of the first network device based on a first key that identifies the first network device and a media access control (MAC) address of a source of a packet, wherein the ingress port of the first network device is bound to a first security zone prior to receipt of the packet at the ingress port, wherein the first security zone for the ingress port is defined by a first security level and the first key;

determine, from a MAC address for a destination of the packet, a second key that identifies a second network device that has an egress port for communicating the packet to the destination, wherein a software defined network (SDN) protocol is queried to determine the destination for the packet;

determine an egress security zone associated with the egress port of the second network device based on the egress port and the second key, wherein the egress port of the second network device is bound to a second security zone prior to transmission of the packet at the egress port, wherein the second security zone for the egress port is defined by a second security level and the second key;

perform a policy lookup based on the first security level and the first key of the ingress security zone and the second security level and the second key of the egress security zone in a policy table, wherein the policy lookup identifies a policy to apply to the packet when first security level and the second security level are different security levels, and wherein the policy lookup identifies a second policy allowing the forwarding of the packet when first security level of the first security zone and the second security level of the second security zone are at a same security level regardless of values of the first key and the second key;

apply the policy to the packet based on the first security level and the second security level when the ingress security zone and the egress security zone are different security zones; and

send the packet to the destination based on the second key and an identifier of the destination, wherein layer 2 (L2) processing is performed at the destination to determine a final physical egress port for the packet, and wherein the L2 processing comprises a MAC lookup operation.

4. The network device defined in claim 3 wherein the processor performs one or more security processing operations to the packet.

5. A computer-readable non-transitory storage medium having instructions stored therein, which when executed by a network device, cause the network device to perform a method, the method comprising:

binding individual ports of a first network device to a security zone;

determining an ingress security zone associated with a packet received at an ingress port of the first network device based on a first key that identifies the first network device and a media access control (MAC) address of a source of a packet, wherein the ingress port of the first network device is bound to a first security zone prior to receipt of the packet at the ingress port, wherein the first security zone for the ingress port is defined by a first security level and the first key;

determining, from a MAC address for a destination of the packet, a second key that identifies a second network device that has an egress port for communicating the packet to the destination, wherein a software defined network (SDN) protocol is queried to determine the destination for the packet;

determining an egress security zone of a second network device based on the egress port and the second key, wherein the egress port of the second network device is bound to a second security zone prior to transmission of the packet at the egress port, wherein the second security zone for the egress port is defined by a second security level and the second key;

performing a policy lookup based on the first security level and the first key of the ingress security zone and the second security level and the second key of the egress security zone in a policy table, wherein the policy lookup identifies a policy to apply to the packet when first security level and the second security level are different security levels, and wherein the policy lookup identifies a second policy allowing the forwarding of the packet when first security level of the first security zone and the second security level of the second security zone are at a same security level regardless of values of the first key and the second key;

applying the policy to the packet based on the first security level and the second security level when the ingress security zone and the egress security zone are different security zones; and

sending the packet to the destination based on the second key and an identifier of the destination, wherein layer 2 (L2) processing is performed at the destination to determine a final physical egress port for the packet, and wherein the L2 processing comprises a MAC lookup operation.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Jul 18, 2025
From: GRYPHO5, LLC
To: EVP CREDIT SPV I LP
Reel/Frame 072053/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: VARMOUR NETWORKS, INC.
To: GRYPHO5, LLC
Reel/Frame 070287/0007 →
SECURITY INTEREST Recorded Feb 22, 2024
From: VARMOUR NETWORKS, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 066530/0399 →
EMPLOYEE INVENTIONS AND PROPRIETARY RIGHTS ASSIGNMENT AGREEMENT Recorded Apr 3, 2018
From: CHEUNG, LEE
To: VARMOUR NETWORKS, INC.
Reel/Frame 045821/0983 →
EMPLOYEE INVENTIONS AND PROPRIETARY RIGHTS ASSIGNMENT AGREEMENT Recorded Mar 29, 2018
From: CHEUNG, LOUIS
To: VARMOUR NETWORKS, INC.
Reel/Frame 045787/0869 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2013
From: SUN, YI; XU, MENG; CHEUNG, LEE; WANG, HSISHENG; SHIEH, CHOUNG-YAW MICHAEL
To: VARMOUR NETWORKS, INC.
Reel/Frame 030217/0873 →
Continuity (2)
Provisional Application 61685697 · Mar 22, 2012
Related Publication 20130254871A1 · Sep 26, 2013