IP Library Granted Patent US 11,394,693
Granted Patent B2
US 11,394,693 · App. 16/805,371 · Granted Jul 19, 2022

Establishing network tunnel in response to access request

Inventors: Kurt Glazemakers (Grembergen, BE); Gokhan Berberoglu (Gothenburg, SE); Kosmas Valianos (Ojersjo, SE); Per Johan Allansson (Kungsbacka, SE); Hoang Long Nguyen (Gothenburg, SE); Thomas Bruno Emmanuel Cellerier (Kungalv, SE); Aitor Perez Iturri (Gothenburg, SE); Harish Dinne (Gothenburg, SE); Salvatore Tomaselli (Gothenburg, SE)
Assignee: Cyxtera Cybersecurity, Inc.
H04L63/029H04L12/4633H04L12/4641H04L12/66H04L45/54H04L45/74H04L63/0272H04L63/08H04L63/10H04W48/16H04W48/18H04W76/12H04W88/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,394,693
App. No.
16/805,371
Granted
Jul 19, 2022
Kind
B2
Abstract

Network access is provided to a networking device. In one approach, a method includes: obtaining, by a gateway, access rules for a networking device; providing, by the gateway, one or more dedicated networking tunnels between the gateway and respective remote gateways to one or more respective network segments, wherein the networking device is authorized to access the one or more network segments by the access rules; and routing, by the gateway, networking packets from the networking device based on source address information in the networking packets to the one or more dedicated networking tunnels, and based on destination address information in the networking packets, routing the networking packets to a selection of the one or more dedicated networking tunnels.

Claims (47)

1. A method comprising:

providing, by an access controller, one or more dedicated networking tunnels between the access controller and one or more respective remote gateways;

routing, by the access controller, networking packets from a first networking device to the one or more dedicated networking tunnels based on source address information in each respective networking packet;

routing, by the access controller, the networking packets to a selection of the one or more dedicated networking tunnels based on destination address information in the respective networking packet;

receiving, by the access controller from a server, access rules for the first networking device, wherein the first networking device is authorized by the access rules to access one or more network segments;

receiving, by the access controller, a request from the first networking device for a hardware address associated with a network address of the access controller;

determining, using the access rules, whether the access controller is a default gateway for the first networking device; and

in response to determining that the access controller is a default gateway for the first networking device, providing the hardware address to the first networking device.

2. The method of claim 1 , wherein the access rules have been determined based on a network address request from the first networking device.

3. The method of claim 2 , wherein:

a device type of the first networking device is determined from the hardware address; and

the access rules are based on the device type.

4. The method of claim 1 , wherein the access controller maintains separate routing tables for each of a plurality of networking devices, including the first networking device.

5. A method comprising:

receiving, by at least one server from a networking device, a request for a network address;

determining, by the at least one server, access rules based on data associated with the request;

receiving, by an access controller from the at least one server, the access rules;

establishing, by the access controller based on the access rules, a set of networking tunnels;

receiving, by the access controller from the networking device, a network packet;

selecting, by the access controller based on a source address of the network packet, the set of networking tunnels;

selecting, by the access controller based on a destination address of the network packet, a first networking tunnel of the set of networking tunnels; and

routing, by the access controller, the network packet to the first networking tunnel.

6. The method of claim 5 , wherein the data associated with the request comprises a hardware address of the networking device.

7. The method of claim 5 , further comprising determining a type or class of device based on the data associated with the request, wherein the access rules are determined based at least in part on the type or class of device.

8. The method of claim 7 , wherein the type or class of device is determined based on a hardware address of the networking device provided with the request.

9. The method of claim 7 , further comprising determining a fingerprint of the networking device, wherein the access rules are determined further based on the fingerprint.

10. The method of claim 5 , further comprising selecting, for the networking device, a first network segment and a default gateway.

11. The method of claim 10 , further comprising determining at least one of a selection of network segments to which the networking device is allowed network access, or a selection of networking devices within the first network segment with which the networking device is allowed to communicate.

12. The method of claim 5 , wherein determining the access rules comprises generating an access list.

13. The method of claim 12 , wherein the access list includes firewall rules for a gateway, the method further comprising:

sending, by the access controller, the access list to the gateway.

14. The method of claim 13 , wherein the access list further includes conditions and corresponding addresses, wherein each condition must be satisfied in order for the networking device to have access to the corresponding address.

15. The method of claim 5 , wherein:

determining the access rules comprises generating a tunnel list;

the tunnel list includes at least one of a destination address of a gateway or a destination port of the gateway; and

establishing the set of networking tunnels includes setting up a tunnel at the destination address, the destination port, or the destination address and the destination port.

16. The method of claim 15 , wherein the tunnel list further includes authentication information to authenticate the access controller with the gateway.

17. A system comprising:

a processor; and

memory containing instructions configured to instruct the processor to:

provide one or more dedicated networking tunnels to one or more respective remote gateways;

route networking packets from a networking device to the one or more dedicated networking tunnels based on respective source address information in each networking packet;

route the networking packets to a selection of the one or more dedicated networking tunnels based on respective destination address information in each networking packet;

receive access rules for a first networking device, wherein the first networking device is authorized by the access rules to access one or more network segments;

receive a request from the first networking device for a hardware address associated with a network address of an access controller;

determine, using the access rules, whether the access controller is a default gateway for the first networking device; and

in response to determining that the access controller is a default gateway for the first networking device, provide the hardware address to the first networking device.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
CHANGE OF NAME Recorded Jul 28, 2022
From: CYXTERA CYBERSECURITY, INC.
To: APPGATE CYBERSECURITY, INC.
Reel/Frame 060663/0045 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2020
From: GLAZEMAKERS, KURT; BERBEROGLU, GOKHAN; VALIANOS, KOSMAS; ALLANSSON, PER JOHAN; NGUYEN, HOANG LONG; CELLERIER, THOMAS BRUNO EMMANUEL; ITURRI, AITOR PEREZ; DINNE, HARISH; TOMASELLI, SALVATORE
To: CYXTERA CYBERSECURITY, INC.
Reel/Frame 054963/0597 →
Continuity (2)
Provisional Application 62813610 · Mar 4, 2019
Related Publication 20200287750A1 · Sep 10, 2020