IP Library Granted Patent US 9,203,741
Granted Patent B1
US 9,203,741 · App. 14/516,539 · Granted Dec 1, 2015

Managing multi-customer network traffic using lower layer protocol attributes

Inventors: Paul Michael Martini (San Diego, CA); Peter Anthony Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L45/30H04L45/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,203,741
App. No.
14/516,539
Granted
Dec 1, 2015
Kind
B1
Abstract

Methods and systems for managing packets using lower layer protocol attributes include determining a network address and a lower layer protocol attribute associated with a packet and applying a particular network policy to the packet based on the determined network address and the lower layer protocol attribute. The lower layer protocol attribute is associated with a protocol layer lower than a protocol layer associated with the network address.

Claims (32)

1. A computer-implemented method executed by one or more processors, the method comprising:

determining a network address and a lower layer protocol attribute associated with a packet, the lower layer protocol attribute associated with a protocol layer lower than a protocol layer associated with the network address, wherein the packet is a request to perform an administrative action; and

applying a particular network policy to the packet based on the determined network address and the lower layer protocol attribute, wherein applying the particular network policy includes restricting a scope of the administrative action to resources associated with a particular entity represented by the lower layer protocol attribute.

2. The method of claim 1 , wherein the packet is a first packet, the particular network policy is a first network policy, the network address is a first network address, and the lower layer protocol attribute is a first lower layer protocol attribute, the method further comprising:

determining a second network address and a second lower layer protocol attribute associated with a second packet different than the first packet, the second lower layer protocol attribute being different than the first lower layer protocol attribute; and

applying a second network policy to the second packet based on the second network address and the second lower layer protocol attribute, the second network policy being different than the first network policy.

3. The method of claim 1 , wherein the network address includes an internet protocol (IP) address and the lower layer protocol attributes includes at least one of a Multiprotocol Label Switching (MPLS) tag, an Asynchronous Transfer Mode (ATM) Virtual Path Identifier (VPI), or a Virtual Local Area Network (VLAN) tag.

4. The method of claim 1 , wherein applying the particular network policy to the packet based on the network address and the lower layer protocol attribute includes at least one of blocking the packet, allowing the packet, redirecting the packet, logging the packet, or notifying an entity associated with the particular network policy.

5. The method of claim 1 , wherein the administrative action includes setting a configuration parameter associated with the particular entity, and restricting the scope includes blocking requests to set configuration parameters associated with entities different than the particular entity.

6. The method of claim 5 , wherein setting the configuration parameter includes changing attributes of a network policy.

7. The method of claim 1 , wherein the administrative action includes providing information associated with the particular entity, and restricting the scope includes blocking requests for information associated with entities different than the particular entity.

8. A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:

determining a network address and a lower layer protocol attribute associated with a packet, the lower layer protocol attribute associated with a protocol layer lower than a protocol layer associated with the network address, wherein the packet is a request to perform an administrative action; and

applying a particular network policy to the packet based on the determined network address and the lower layer protocol attribute, wherein applying the particular network policy includes restricting a scope of the administrative action to resources associated with a particular entity represented by the lower layer protocol attribute.

9. The computer-readable medium of claim 8 , wherein the packet is a first packet, the particular network policy is a first network policy, the network address is a first network address, and the lower layer protocol attribute is a first lower layer protocol attribute, the operations further comprising:

determining a second network address and a second lower layer protocol attribute associated with a second packet different than the first packet, the second lower layer protocol attribute being different than the first lower layer protocol attribute; and

applying a second network policy to the second packet based on the second network address and the second lower layer protocol attribute, the second network policy being different than the first network policy.

10. The computer-readable medium of claim 8 , wherein the network address includes an internet protocol (IP) address and the lower layer protocol attributes includes at least one of a Multiprotocol Label Switching (MPLS) tag, an Asynchronous Transfer Mode (ATM) Virtual Path Identifier (VPI), or a Virtual Local Area Network (VLAN) tag.

11. The computer-readable medium of claim 8 , wherein applying the particular network policy to the packet based on the network address and the lower layer protocol attribute includes at least one of blocking the packet, allowing the packet, redirecting the packet, logging the packet, or notifying an entity associated with the particular network policy.

12. The computer-readable medium of claim 8 , wherein the administrative action includes setting a configuration parameter associated with the particular entity, and restricting the scope includes blocking requests to set configuration parameters associated with entities different than the particular entity.

13. The computer-readable medium of claim 12 , wherein setting the configuration parameter includes changing attributes of a network policy.

14. The computer-readable medium of claim 8 , wherein the administrative action includes providing information associated with the particular entity, and restricting the scope includes blocking requests for information associated with entities different than the particular entity.

15. A system comprising:

memory for storing data; and

one or more processors operable to perform operations comprising:

determining a network address and a lower layer protocol attribute associated with a packet, the lower layer protocol attribute associated with a protocol layer lower than a protocol layer associated with the network address, wherein the packet is a request to perform an administrative action; and

applying a particular network policy to the packet based on the determined network address and the lower layer protocol attribute, wherein applying the particular network policy includes restricting a scope of the administrative action to resources associated with a particular entity represented by the lower layer protocol attribute.

16. The system of claim 15 , wherein the packet is a first packet, the particular network policy is a first network policy, the network address is a first network address, and the lower layer protocol attribute is a first lower layer protocol attribute, the operations further comprising:

determining a second network address and a second lower layer protocol attribute associated with a second packet different than the first packet, the second lower layer protocol attribute being different than the first lower layer protocol attribute; and

applying a second network policy to the second packet based on the second network address and the second lower layer protocol attribute, the second network policy being different than the first network policy.

17. The system of claim 15 , wherein the network address includes an internet protocol (IP) address and the lower layer protocol attributes includes at least one of a Multiprotocol Label Switching (MPLS) tag, an Asynchronous Transfer Mode (ATM) Virtual Path Identifier (VPI), or a Virtual Local Area Network (VLAN) tag.

18. The system of claim 15 , wherein applying the particular network policy to the packet based on the network address and the lower layer protocol attribute includes at least one of blocking the packet, allowing the packet, redirecting the packet, logging the packet, or notifying an entity associated with the particular network policy.

Assignments (6)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2014
From: MARTINI, PAUL MICHAEL; MARTINI, PETER ANTHONY
To: IBOSS, INC.
Reel/Frame 034512/0158 →