IP Library Granted Patent US 10,027,677
Granted Patent B2
US 10,027,677 · App. 15/498,263 · Granted Jul 17, 2018

Security access for a switch device

Inventors: Hung Nguyen (San Jose, CA); Jay Han Yu (San Jose, CA); Patrick Allen Riley (San Jose, CA); Hoang Nguyen Bao Nguyen (San Jose, CA)
Assignee: Gigamon Inc.
H04L63/105H04L41/0803H04L63/0254H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,027,677
App. No.
15/498,263
Granted
Jul 17, 2018
Kind
B2
Abstract

A method for providing user access to a network switch appliance, includes: receiving from a user a request to access configuration item for the network switch appliance, the network switch appliance configured to pass packets received from a network to network monitoring instruments; and determining, using a processing unit, whether to allow the user to access the configuration item for the network switch appliance based on information regarding the user.

Claims (41)

1. A method comprising:

receiving a request, from a user, to implement a configuration item for a network switch appliance, the configuration item relating to a network port of the network switch appliance configured to receive packets from a network and an instrument port of the network switch appliance configured to pass received packets a network monitoring instrument;

ascertaining, by a processor, an access level associated with the user for the configuration item for the network switch appliance based on information regarding the user and access level assignment information,

wherein the access level assignment information includes a first set of access levels associated with the network port and a second set of access levels associated with the instrument port; and

authorizing or denying implementation of the configuration item based on the ascertained access level associated with the user.

2. The method of claim 1 , further comprising:

ascertaining allowable tasks associated with the determined access level.

3. The method of claim 2 , further comprising:

implementing the configuration item for the network switch appliance in response to ascertaining the request to implement the configuration item is among allowable tasks associated with the ascertained access level.

4. The method of claim 2 , further comprising:

denying implementation of the configuration item for the network switch appliance in response to ascertaining the request to implement the configuration item is not among allowable tasks associated with the determined access level.

5. The method of claim 4 , further comprising:

receiving a share access request for the user from another user;

ascertaining if the share access request is among allowable tasks associated with the another user; and

implementing the configuration item for the network switch appliance in response to ascertaining that the share access request is among allowable tasks associated with the another user.

6. The method of claim 1 , wherein ascertaining the access level associated with the user comprises looking up a table in which multiple access levels are associated with respective sets of allowable tasks.

7. The method of claim 6 , wherein the table comprises:

a first access level associated with a first set of one or more allowable tasks; and

a second access level associated with a second set of one or more allowable tasks that is different from the first set.

8. The method of claim 7 , wherein the one or more allowable tasks in the first set comprises one or a combination of: view, create tool-mirror, delete tool-mirror, edit tool port list, add map rule, delete map rule, add map, delete map, add port-pair, edit port-pair, and change port configuration.

9. The method of claim 6 , wherein ascertaining the access level associated with the user further comprises identifying which of the first and second access levels matches with the access level for the user.

10. The method of claim 1 , wherein the network switch appliance provides visibility to network parts by operating as a circuit switch.

11. The method of claim 1 , wherein the network switch appliance operates as an out-of-band device with respect to a first set of packets and an in-band device with respect to a second set of packets.

12. An apparatus, comprising:

a processor; and

a memory having instructions which, when executed by the processor, configures the processor to perform operations including:

receive a request, from a user, to implement a configuration item for a network switch appliance, the configuration item relating to a network port of the network switch appliance configured to receive packets from a network and an instrument port of the network switch appliance configured to pass received packets a network monitoring instrument;

ascertain an access level associated with the user for the configuration item for the network switch appliance based on information regarding the user and access level assignment information,

wherein the access level assignment information includes a first set of access levels associated with a network port and a second set of access levels associated with an instrument port; and

authorize or deny implementation of the configuration item based on the ascertained access level associated with the user.

13. The apparatus of claim 12 , wherein the processor is configured to ascertain whether to allow the user to implement the configuration by looking up a table in which multiple access levels are associated with respective sets of allowable tasks.

14. The apparatus of claim 13 , wherein the table comprises:

a first access level associated with a first set of one or more allowable tasks; and

a second access level associated with a second set of one or more allowable tasks that is different from the first set.

15. The apparatus of claim 14 , wherein the one or more allowable tasks in the first set comprises one or a combination of: view, create tool-mirror, delete tool-mirror, edit tool port list, add map rule, delete map rule, add map, delete map, add port-pair, edit port-pair, and change port configuration.

16. The apparatus of claim 14 , wherein the processor is configured to ascertain whether to allow the user to implement the configuration by identifying which of the first and second access levels matches with the access level for the user.

17. The apparatus of claim 12 , wherein the processor is communicatively coupled to the network switch appliance.

18. The apparatus of claim 12 , wherein the configuration item is associated with a configuration of the network switch appliance.

19. The apparatus of claim 12 , wherein the configuration item comprises a parameter for configuring the network switch appliance.

20. The apparatus of claim 12 , wherein the processor is further configured to enable a user to select one of a plurality of transmission schemes for transmitting the packets between a plurality of network ports and a plurality of instrument ports of the network switch appliance.

21. The apparatus of claim 20 , wherein the one of the plurality of transmission schemes includes transmitting the packets between the network ports and the instrument ports using any of one-to-one transmission scheme, one-to-many transmission scheme, many-to-one transmission scheme, or many-to-many transmission scheme.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: JEFFERIES FINANCE LLC
To: GIGAMON INC.
Reel/Frame 059362/0491 →
SECURITY INTEREST Recorded Mar 11, 2022
From: GIGAMON INC.; ICEBRG LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 059362/0717 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 11, 2020
From: GIGAMON INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 051898/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2017
From: NGUYEN, HUNG; YU, JAY HAN; RILEY, PATRICK ALLEN; NGUYEN, HOANG NGUYEN BAO
To: GIGAMON INC.
Reel/Frame 043376/0196 →
Continuity (2)
Continuation 13915490 · Jun 11, 2013
Related Publication 20170230380A1 · Aug 10, 2017