IP Library Granted Patent US 8,892,733
Granted Patent B2
US 8,892,733 · App. 14/206,262 · Granted Nov 18, 2014

Network adapter based zoning enforcement

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,892,733
App. No.
14/206,262
Granted
Nov 18, 2014
Kind
B2
Abstract

Embodiments of the present invention are directed to enforcing zoning at a network adapter of an end point device. Thus, a network adapter can monitor the communications that are sent and/or received by the adapter and discard communications that are prohibited based on the zoning rules applicable to the adapter. In some embodiments, zoning configuration information can be defined and stored at a central entity and sent to the various network adapters. Alternatively, or in addition, each network adapter can also check outgoing communications to ensure that they include a proper source address. More specifically, outgoing communications may be checked to ensure that their source address is the address (or one of the addresses) that are associated with the network adapter. This can be used to detect and/or prevent malfunctions and/or intentional tampering or hacking.

Claims (30)

1. A method comprising:

receiving a first set of addresses, each address in the first set of addresses corresponding to a network device in a first network zone to which a first virtual device has access, wherein an end point device comprises the first virtual device;

receiving a second set of addresses, each address in the second set of addresses corresponding to a network device in a second network zone to which a second virtual device has access, wherein the end point device comprises the second virtual device;

enforcing network zoning at the first virtual device by monitoring communications of the first virtual device and discarding communications of the first virtual device that do not include an address from the first set of address; and

enforcing network zoning at the second virtual device by monitoring communications of the second virtual device and discarding communications that do not include an address from the second set of addresses;

wherein the endpoint device, the network device in the first network zone, and the network device in the second network zone are communicatively coupled by a network;

wherein the first set of addresses and the second set of addresses are generated by a zoning database module that is communicatively coupled to the end point device through the network.

2. The method of claim 1 , wherein a network adapter comprises one or more elements of the first virtual device and the second virtual device.

3. The method of claim 2 , wherein the network adapter is a host bus adapter.

4. The method of claim 2 , wherein the network adapter is an FCoE adapter.

5. The method of claim 1 , wherein the network is a Fibre Channel network.

6. The method of claim 1 , wherein the network is an FCoE network.

7. The method of claim 1 , wherein the first zone and the second zone are independent.

8. The method of claim 1 , wherein enforcing network zoning at the first virtual device comprises monitoring outgoing communications of the first virtual device and discarding outgoing communications of the first virtual device that do not include a destination address from the first set of addresses.

9. The method of claim 1 , wherein enforcing network zoning at the first virtual device comprises monitoring incoming communications of the first virtual device and discarding incoming communications of the first virtual device that do not include a source address from the first set of addresses.

10. A detachable network adapter card comprising:

a memory operable to store a first set of addresses and a second set of addresses, each address in the first set of addresses corresponding to a network device in a first network zone to which a first virtual device has access, each address in the second set of addresses corresponding to a network device in a second network zone to which a second virtual device has access, wherein an end point device communicatively coupled to the detachable network adapter card comprises the first virtual device and the second virtual device; and

one or more processors operable to execute the memory to enforce network zoning, wherein the enforcement of network zoning comprises:

discarding communications of the first virtual device that do not include an address from the first set of addresses; and

discarding communications of the second virtual device that do not include an address from the second set of addresses;

wherein the endpoint device, the network device in the first network zone, and the network device in the second network zone are connected by a network;

wherein the first set of addresses and the second set of addresses are generated by a zoning database module that is communicatively coupled to the end point device through the network.

11. The network adapter card of claim 10 , wherein the network adapter card comprises one or more elements of the first virtual device and the second virtual device.

12. The network adapter card of claim 10 , wherein the network adapter card is a host bus adapter.

13. The network adapter card of claim 10 , wherein the network adapter card is an FCoE adapter.

14. The network adapter card of claim 10 , wherein the network is a Fibre Channel network.

15. The network adapter card of claim 10 , wherein the network is an FCoE network.

16. The network adapter card of claim 10 , wherein the first zone and the second zone are independent.

17. The network adapter card of claim 10 , wherein the enforcement of network zoning at the first virtual device comprises monitoring outgoing communications of the first virtual device and discarding outgoing communications of the first virtual device that do not include a destination address from the first set of addresses.

18. The network adapter card of claim 10 , wherein enforcing network zoning at the first virtual device comprises monitoring incoming communications of the first virtual device and discarding incoming communications of the first virtual device that do not include a source address from the first set of addresses.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE EXECUTION DATE PREVIOUSLY RECORDED AT REEL: 047422 FRAME: 0464. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 6, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 048883/0702 →
MERGER Recorded Oct 5, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047422/0464 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041710/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037808/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2015
From: EMULEX CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 036942/0213 →