IP Library Granted Patent US 11,336,622
Granted Patent B2
US 11,336,622 · App. 16/689,003 · Granted May 17, 2022

Apparatus and method for deploying firewall on SDN and network using the same

Inventors: Hyuk Lim (Gwangju, KR); Sung Hwan Kim (Gwangju, KR); Jargalsaikhan Narantuya (Gwangju, KR); Seung Hyun Yoon (Gwangju, KR)
Assignee: GWANGJU INSTITUTE OF SCIENCE AND TECHNOLOGY
H04L63/0263H04L9/0825H04L43/08H04L45/38H04L49/25H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,622
App. No.
16/689,003
Granted
May 17, 2022
Kind
B2
Abstract

An apparatus for deploying a firewall on a software-defined network (SDN) includes a public key distributor configured to transmit a public key, a resource monitor configured to monitor resources of a network, a host monitor configured to receive a firewall rule of at least one host, which is encrypted by the public key, a decryption unit configured to decrypt information received from the host monitor by using a secret key, a merge unit configured to merge the decrypted information to provide a merged firewall rule, and a firewall deployment unit configured to deploy the merged firewall rule to a switch.

Claims (35)

1. An apparatus for deploying a firewall on a software-defined network (SDN), the apparatus comprising:

a public key distributor configured to transmit a public key;

a resource monitor configured to monitor resources of a network;

a host monitor configured to receive a firewall rule of at least one host, which is encrypted by the public key;

a decryption unit configured to decrypt information received from the host monitor by using a secret key;

a merge unit configured to merge the decrypted information to provide a merged firewall rule; and

a firewall deployment unit configured to deploy the merged firewall rule to a switch;

wherein the public key is transmitted to the switch through a control plane, and the switch is directly connected to the host, and

the host, to which the public key is transmitted, is configured to transmit a firewall rule of the host to the host monitor through a data plane.

2. The apparatus according to claim 1 , wherein the switch, to which the public key is transmitted, is configured to transmit the public key to the host through the data plane, and

the host, to which the public key is transmitted, is configured to encrypt the firewall rule of the host by using the public key and transmit the encrypted firewall rule to the host monitor.

3. The apparatus according to claim 1 , wherein the host monitor is configured to periodically receive the firewall rule of the host.

4. The apparatus according to claim 1 , wherein the merged firewall rule is integrated with a flow rule of the switch, or is the same as the flow rule of the switch.

5. An apparatus for deploying a firewall on a software-defined network (SDN), the apparatus comprising:

a public key distributor configured to transmit a public key;

a resource monitor configured to monitor resources of a network;

a host monitor configured to receive a firewall rule of at least one host, which is encrypted by the public key;

a decryption unit configured to decrypt information received from the host monitor by using a secret key;

a merge unit configured to merge the decrypted information to provide a merged firewall rule; and

a firewall deployment unit configured to deploy the merged firewall rule to a switch,

wherein the firewall deployment unit is configured to select the switch to which the merged firewall rule is transmitted, and

the switch, to which the merged firewall rule is transmitted, is selected as the switches that maximize a total data traffic reduced in the network.

6. The apparatus according to claim 5 , wherein a total number of the merged firewall rule does not exceed the capacity of the switch.

7. The apparatus according to claim 5 , wherein the merged firewall rule for any one host is placed on only one switch.

8. A method for deploying a firewall on a software-defined network (SDN), the method comprising:

gathering firewall rules of at least two hosts;

merging the firewall rules to provide a merged firewall rule; and

transmitting the merged firewall rule to only a selected switch,

wherein the switch, to which the merged firewall rule is transmitted, is selected as switches that maximize a total data traffic reduced in the network,

wherein the gathering of the firewall rules of the at least two hosts is performed by an encryption process, the encryption process comprising:

distributing a public key by using a control plane of a network;

assigning, by the switch receiving the public key, the public key to a host directly connected to the switch; and

encrypting the firewall rule of the host by using the public key and transmitting the encrypted firewall rule to a data plane.

9. The method according to claim 8 , wherein a total number of the merged firewall rules does not exceed the capacity of the switch.

10. The method according to claim 8 , wherein the merged firewall rule for any one host is placed on only one switch.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2026
From: RP INTELLECTUAL PARTNERS LLC
To: ARC LINK LLC
Reel/Frame 074845/0439 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2024
From: GWANGJU INSTITUTE OF SCIENCE AND TECHNOLOGY
To: IP3 2023, SERIES 923 OF ALLIED SECURITY TRUST I
Reel/Frame 066614/0703 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2019
From: LIM, HYUK; KIM, SUNG HWAN; NARANTYUA, JARGALSAIKHAN; YOON, SEUNG HYUN
To: GWANGJU INSTITUTE OF SCIENCE AND TECHNOLOGY
Reel/Frame 051067/0351 →
Priority Claims (1)
KR 10-2018-0143393 · Nov 20, 2018 · national
Continuity (1)
Related Publication 20200162430A1 · May 21, 2020