IP Library Granted Patent US 9,590,998
Granted Patent B2
US 9,590,998 · App. 14/322,043 · Granted Mar 7, 2017

Network switch with hierarchical security

Inventors: Jitender Miglani (Hollis, NH); Vijayan Thattai (Goleta, CA)
Assignee: Calient Technologies, Inc.
H04L63/102H04L49/25H04L63/20H04L12/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,590,998
App. No.
14/322,043
Granted
Mar 7, 2017
Kind
B2
Abstract

Network switches and methods are disclosed. A network switch may include multiple input ports and multiple output ports, a switch fabric, and switch controller. The controller may receive and store data identifying a plurality of users and data defining which input ports and which output ports each user has authority over. The controller may receive, from a requesting user from the plurality of users, a request to make a connection between a selected input port and a selected output port. The controller may determine, based on the stored data, if the requesting user has authority over both the selected input port and the selected output port. The controller may refuse to make the requested connection if the requesting user does not have authority over both the selected input port and the selected output port.

Claims (52)

1. A network circuit switch, comprising:

a plurality of input ports and a plurality of output ports;

a switch fabric coupled to the plurality of input ports and the plurality of output ports; and

a switch controller configured to:

receive and store configuration data including data identifying a plurality of users and data defining which of the plurality of input ports and which of the plurality of output ports each user has authority over;

receive, from a requesting user from the plurality of users, a request to make a requested connection between a select input port from the plurality of input ports and a selected output port from the plurality of output ports,

determine, based on the stored configuration data, if the requesting user has authority over both the selected input port and the selected output port, and

refuse to make the requested connection if the requesting user does not have authority over both the selected input port and the selected output port.

2. The network circuit switch of claim 1 , the switch controller further configured to:

cause the requested connection to be made from the selected input port to the selected output port via the switch fabric if the requesting user has authority over both the selected input port and the selected output port.

3. The network circuit switch of claim 1 , the switch controller further configured to:

determine if the requested connection violates any of one or more rules associated with the selected input port and/or the selected output port,

refuse to make the requested connection if one or more rule is violated, and

cause the requested connection to be made from the selected input port to the selected output port via the switch fabric if the requesting user has authority over both the selected input port and the selected output port and no rule is violated.

4. The network circuit switch of claim 1 , wherein

each of the plurality of input ports and each of the plurality of output ports is associated with one or more user from the plurality of users.

5. The network circuit switch of claim 4 , wherein the requesting user has authority to make the requested connection if the requesting user is associated with both the selected input port and the selected output port.

6. The network circuit switch of claim 4 , wherein

the plurality of users have a hierarchical organization wherein some users supervise other users, and

the requesting user has authority to make the requested connection if, for both the selected input port and the selected output port, the requesting user is either associated with the port or supervises another user that is associated with the port.

7. The network circuit switch of claim 4 , wherein

each of the plurality of users is assigned to a level from two or more hierarchical security levels, and

the requesting user has authority to make the requested connection if, for both the selected input port and the selected output port, the requesting user is either associated with the port or assigned to a higher security level that another user that is associated with the port.

8. The network circuit switch of claim 4 , wherein

the plurality of input ports and the plurality of output ports are organized as two or more ports groups, each port group containing one or more input and/or output port,

each of the two or more port groups is associated with one or more user from the plurality of users, and

each of the plurality of input ports and the plurality of output ports is a member of exactly one port group and inherits user associations from the port group of which it is a member.

9. A method for making connections in a network circuit switch having a plurality of input ports and a plurality of output ports, the method comprising:

receiving and storing configuration data including data identifying a plurality of users and data defining which of the plurality of input ports and which of the plurality of output ports each user has authority over;

receiving, from a requesting user from the plurality of users, a request to make a requested connection between a selected input port from the plurality of input ports and a selected output port from the plurality of output ports;

determining, based on the stored configuration data, if the requesting user has authority over both the selected input port and the selected output port; and

refusing to make the requested connection if the requesting user does not have authority over both the selected input port and the selected output port.

10. The method of claim 9 , further comprising:

causing the requested connection to be made from the selected input port to the selected output port via a switch fabric if the requesting user has authority over both the selected input port and the selected output port.

11. The method of claim 9 , further comprising:

determining if the requested connection violates any of one or more rules associated with the selected input port and/or the selected output port,

refusing to make the requested connection if one or more rule is violated, and

causing the requested connection to be made from the selected input port to the selected output port via a switch fabric if the requesting user has authority over both the selected input port and the selected output port and no rule is violated.

12. The method of claim 9 , further comprising:

associating each of the plurality of input ports and each of the plurality of output ports with one or more user from the plurality of users.

13. The method of claim 12 , wherein

the requesting user has authority to make the requested connection if the requesting user is associated with both the selected input port and the selected output port.

14. The method of claim 12 , wherein

the plurality of users have a hierarchical organization wherein some users supervise other users, and

the requesting user has authority to make the requested connection if, for both the selected input port and the selected output port, the requesting user is either associated with the port or supervises another user that is associated with the port.

15. The method of claim 12 , wherein

each of the plurality of users is assigned to a level from two or more hierarchical security levels, and

the requesting user has authority to make the requested connection if, for both the selected input port and the selected output port, the requesting user is either associated with the port or assigned to a higher security level that another user that is associated with the port.

16. The method of claim 12 , wherein

the plurality of input ports and the plurality of output ports are organized as two or more ports groups, each port group containing one or more input and/or output port,

each of the two or more port groups is associated with one or more user from the plurality of users, and

each of the plurality of input ports and the plurality of output ports is a member of exactly one port group and inherits user associations from the port group of which it is a member.

Assignments (5)
CHANGE OF NAME Recorded Aug 30, 2024
From: CALIENT TECHNOLOGES, INC.
To: CALIENT.AI INC.
Reel/Frame 068819/0993 →
CHANGE OF NAME Recorded Jul 19, 2024
From: CALIENT TECHNOLOGIES, INC.
To: CALIENT.AI INC.
Reel/Frame 068459/0031 →
RELEASE OF SECURITY INTEREST Recorded Jul 20, 2020
From: CALIENT HOLDINGS, LLC
To: CALIENT TECHNOLOGIES, INC.
Reel/Frame 053251/0224 →
SECURITY INTEREST Recorded Dec 19, 2017
From: CALIENT TECHNOLOGIES, INC.
To: CALIENT HOLDINGS, LLC
Reel/Frame 044914/0972 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2014
From: MIGLANI, JITENDER; THATTAI, VIJAYAN
To: CALIENT TECHNOLOGIES, INC.
Reel/Frame 033232/0422 →
Continuity (1)
Related Publication 20160006741A1 · Jan 7, 2016