IP Library Granted Patent US 8,977,775
Granted Patent B2
US 8,977,775 · App. 13/905,308 · Granted Mar 10, 2015

Techniques for identity and policy based routing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,977,775
App. No.
13/905,308
Granted
Mar 10, 2015
Kind
B2
Abstract

Techniques for identity and policy based routing are presented. A resource is initiated on a device with a resource identity and role assignments along with policies are obtained for the resource. A customized network is created for the resource using a device address for the device, the resource identity, the role assignments, and the policies.

Claims (27)

1. A method implemented in a non-transitory machine-readable storage medium and processed by one or more processors configured to perform the method, comprising:

registering a workload via its authenticated workload identity as a customized network, the customized network a Virtual Private Network (VPN) that defines resources and devices visible to the workload, and at least some devices dynamically join the VPN; and

dynamically building network routes for the workload that defines access routes to other devices and other workloads based on customized network and detecting a new role assigned to the workload identity in response thereto contacting an identity service with the new role and receiving from the identity service one or more new routes from the identity service to a new customized network based on the new role supplied to the identity service and dynamically joining the workload to the new customized network.

2. The method of claim 1 , wherein registering further includes recognizing the workload as being active on a phone or a tablet.

3. The method of claim 2 , wherein recognizing further includes provisioning services for the workload on the phone or the tablet.

4. The method of claim 3 , wherein provisioning further includes assigning security roles to each provisioned service, each security role assigned to the workload on the phone or the tablet.

5. The method of claim 1 , wherein registering further includes authenticating the workload for a device processing the workload to acquire the authenticated workload identity.

6. The method of claim 5 , wherein authenticating further includes dynamically acquiring credentials from a principal tied to the workload for authenticating the workload.

7. The method of claim 1 , wherein registering further includes assigning security settings for the workload based on the workload identity.

8. The method of claim 7 , wherein registering further includes acquiring policies for enforcement against the customized network based on the workload identity.

9. The method of claim 8 , wherein acquiring further includes building the network routes based on the workload identity, the policies, and the security settings.

10. A method implemented in a non-transitory machine-readable storage medium and processed by one or more processors configured to perform the method, comprising:

acquiring role assignments and policies for the resource based on an authenticated resource identity; and

building network routes for a custom network having the resource identity based on the role assignments, the policies, and the authenticated resource identity and dynamically moving the resource to a new custom network based on when a new role assigned to the resource and contacting an identity service with the new role and receiving from the identity service one or more new routes from the identity service to the new custom network based on the new role supplied to the identity service and dynamically joining the resource to the new custom network.

11. The method of claim 10 further comprising, installing the network routes as one or more routing tables in one or more network routers.

12. The method of claim 10 further comprising, dynamically updating the network routes in response to a detected role or policy change.

13. The method of claim 10 , wherein acquiring further includes obtaining a machine address that is processing the resource.

14. The method of claim 13 , wherein building further includes also using the machine address to build the network routes.

15. The method of claim 14 , wherein using further includes recognizing the machine as a phone or a tablet device.

16. The method of claim 10 , wherein building further includes creating the network routes in a format recognized by a router that is to enforce the network routes.

17. The method of claim 10 , wherein building further includes creating the network routes on demand.

18. A multi-processor implemented system, comprising:

a memory having a provisioning service configured to execute on one or more processors from the memory; and

the memory having a registration service configured to execute on one or more of the processors from the memory;

the provisioning service is configured to instantiate a resource on a mobile device, the registration service is configured to use an authenticated resource identity for the resource, role assignments and policies to build network routes for a custom network that the resource belongs to and the custom network is a virtual network having other resources and other devices defined that a workload can see and can access and wherein other workloads and other devices dynamically register and join the custom network and the provisions service configured to move the resource to a new custom network based on when a new role assigned to that resource by contacting an identity service with the new role and receiving from the identity service one or more new routes from the identity service to the new custom network based on the new role supplied to the identity service and dynamically joining the resource to the new custom network.

19. The system of claim 18 , wherein the mobile device is a phone or a tablet device.

20. The system of claim 18 , wherein an identity service is consulted to authenticate the resource and provided the authenticated resource identity, the role assignments, and the policies.

Assignments (7)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →