IP Library Granted Patent US 11,223,654
Granted Patent B2
US 11,223,654 · App. 16/706,621 · Granted Jan 11, 2022

System and method for managing secured communication channel sessions for applications sharing a port

Inventors: Venkata L. R. Ippatapu (Westborough, MA); Kenneth M. Dorman (West Brookfield, MA)
Assignee: EMC IP Holding Company LLC
H04L63/168H04L63/0236H04L63/20H04L69/329
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,223,654
App. No.
16/706,621
Granted
Jan 11, 2022
Kind
B2
Abstract

Embodiments described herein relate to techniques for establishing a secure communication channel. The techniques may include making, by an upper level protocol application, a request for an interface identifier using an interface information set; receiving the interface identifier in response to the request; providing the interface identifier and an additional information set to a security module; making a first determination, by the security module, that a protocol socket is associated with the interface identifier; making a second determination, by the security module and based on the additional information set, that a security policy is configured for establishing the secure communication channel with a remote peer device; and establishing, using the protocol socket and the security policy, the secure communication channel with the remote peer device.

Claims (39)

1. A method for establishing a secure communication channel, the method comprising:

making, by an upper level protocol application, a request for an interface identifier using an interface information set, wherein the request is made based on a session initiation request from a remote peer device;

receiving the interface identifier in response to the request, wherein the interface identifier identifies an interface associated with a physical port, and the physical port is shared between the upper level protocol application and a second upper level protocol application;

providing the interface identifier and an additional information set to a security module, wherein the additional information set comprises at least one selected from a group consisting of a receiving protocol socket at which the session initiation request was received, a second interface identifier associated with a protocol socket, a physical port associated with the second interface identifier, a local Internet Protocol (IP) address associated with the second interface identifier, and a remote IP address of the remote peer device;

making a first determination, by the security module, that the protocol socket is associated with the interface identifier;

making a second determination, by the security module and based on the additional information set, that a security policy is configured for establishing the secure communication channel with the remote peer device; and

establishing, using the protocol socket and the security policy, the secure communication channel with the remote peer device.

2. The method of claim 1 , wherein the interface information set comprises at least one selected from a group consisting of a physical port identifier, a network identifier, a virtual local area network identifier, and a local Internet Protocol (IP) address.

3. The method of claim 1 , wherein the additional information set comprises at least one selected from group consisting of a physical port identifier, a local Internet Protocol (IP) address, a remote IP address, and an upper level protocol of the upper level protocol application.

4. The method of claim 1 , wherein the upper level protocol application comprises a data replication application.

5. The method of claim 1 , wherein the upper level protocol application comprises a host-storage application.

6. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for establishing a secure communications channel, the method comprising

making, by an upper level protocol application, a request for an interface identifier using an interface information set, wherein the request is made based on a session initiation request from a remote peer device;

receiving the interface identifier in response to the request, wherein the interface identifier identifies an interface associated with a physical port, and the physical port is shared between the upper level protocol application and a second upper level protocol application;

providing the interface identifier and an additional information set to a security module, wherein the additional information set comprises at least one selected from a group consisting of a receiving protocol socket at which the session initiation request was received, a second interface identifier associated with a protocol socket, a physical port associated with the second interface identifier, a local Internet Protocol (IP) address associated with the second interface identifier, and a remote IP address of the remote peer device;

making a first determination, by the security module, that the protocol socket is associated with the interface identifier;

making a second determination, by the security module and based on the additional information set, that a security policy is configured for establishing the secure communication channel with the remote peer device; and

establishing, using the protocol socket and the security policy, the secure communication channel with the remote peer device.

7. The non-transitory computer readable medium of claim 6 , wherein the interface information set comprises at least one selected from a group consisting of a physical port identifier, a network identifier, a virtual local area network identifier, and a local Internet Protocol (IP) address.

8. The non-transitory computer readable medium of claim 6 , wherein the additional information set comprises at least one selected from group consisting of a physical port identifier, a local Internet Protocol (IP) address, a remote IP address, and an upper level protocol of the upper level protocol application.

9. The non-transitory computer readable medium of claim 6 , wherein the upper level protocol application comprises a data replication application.

10. The non-transitory computer readable medium of claim 6 , wherein the upper level protocol application comprises a host-storage application.

11. A system for establishing a secure communication channel, the system comprising:

a processor;

a memory device;

a persistent storage device;

an upper level protocol application executing on the processor and configured to:

make a request for an interface identifier using an interface information set, wherein the request is made based on a session initiation request from a remote peer device;

receive the interface identifier in response to the request, wherein the interface identifier identifies an interface associated with a physical port, and the physical port is shared between the upper level protocol application and a second upper level protocol application;

provide the interface identifier and an additional information set to a security module, wherein the additional information set comprises at least one selected from a group consisting of a receiving protocol socket at which the session initiation request was received, a second interface identifier associated with a protocol socket, a physical port associated with the second interface identifier, a local Internet Protocol (IP) address associated with the second interface identifier, and a remote IP address of the remote peer device;

the security module, comprising circuitry, and configured to:

make a first determination that the protocol socket is associated with the interface identifier;

make a second determination, based on the additional information set, that a security policy is configured for establishing the secure communication channel with the remote peer device; and

establish, using the protocol socket and the security policy, the secure communication channel with the remote peer device.

12. The system of claim 11 , wherein

the interface information set comprises at least one selected from a group consisting of a physical port identifier, a network identifier, a virtual local area network identifier, and a local Internet Protocol (IP) address, and

the additional information set comprises at least one selected from group consisting of the physical port identifier, the local Internet Protocol (IP) address, a remote IP address, and an upper level protocol of the upper level protocol application.

13. The system of claim 11 , wherein the upper level protocol application comprises a data replication application.

14. The system of claim 11 , wherein the upper level protocol application comprises a host-storage application.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2019
From: IPPATAPU, VENKATA L.R.; DORMAN, KENNETH M.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 051263/0706 →