IP Library Granted Patent US 11,252,195
Granted Patent B2
US 11,252,195 · App. 16/812,645 · Granted Feb 15, 2022

Methods and systems for establishment of VPN security policy by SDN application

Inventors: Michael Jau Chen (Livingston, NJ); Tavaris Jason Thomas (New Providence, NJ)
H04L63/20H04L41/0806H04L41/0893H04L63/0272H04L63/0428H04L63/083H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,252,195
App. No.
16/812,645
Granted
Feb 15, 2022
Kind
B2
Abstract

The present application is directed a computer-implemented methods and systems implementing Virtual Private Network (VPN) policies created or modified by Software Defined Network (SDN) applications. The VPN policies can be provided to SDN controllers for implementation. An SDN application can handle a request to establish a VPN by transmitting the request to a VPN provider, obtaining credentials for the VPN, and providing a security policy to an SDN controller.

Claims (49)

1. A computer-implemented method for VPN policy implementation by a Software Defined Network (SDN) application, comprising:

transmitting, using an SDN application, a request to establish a virtual private network (VPN) to a VPN provider;

obtaining, at the SDN application and from the VPN provider, VPN server credentials for a VPN;

generating, using the SDN application, a security policy related to network traffic associated with the VPN;

converting, using the SDN application, the security policy to a table; and

transmitting, using the SDN application, the table to an SDN controller.

2. The computer-implemented method of claim 1 , further comprising:

receiving an alert, at the SDN application, from a network element that enforces a security rule based on the table, of a conflict with the security rule.

3. The computer-implemented method of claim 1 , wherein the VPN is a dynamic VPN.

4. The computer-implemented method of claim 3 , wherein the VPN server is dynamically updated based on a conflict with a security rule based on the table.

5. The computer-implemented method of claim 1 , further comprising:

monitoring, using the SDN application, network traffic information related to the VPN.

6. The computer-implemented method of claim 5 , further comprising:

analyzing, using the SDN application, the network traffic related to the VPN, wherein the security policy is based on analysis of the network traffic related to the VPN.

7. The computer-implemented method of claim 5 , further comprising:

analyzing, using the SDN application, the network traffic related to the VPN,

wherein a conflict with a security rule based on the table is identified based on matching, within the network traffic related to the VPN, a pattern defined in the table.

8. The computer-implemented method of claim 1 , wherein a network element that enforces a security rule based on the table includes a hybrid router, wherein the hybrid router is configured to communicate by conventional and OpenFlow protocols.

9. The computer-implemented method of claim 1 , wherein the table includes at least one OpenFlow Table Type Pattern (TTP).

10. The computer-implemented method of claim 1 , wherein the table includes at least one OpenFlow Multi-Flow Table (MFT).

11. A computer-implemented system for VPN policy implementation by a Software Defined Networking (SDN) application comprising:

a non-transitory memory having instructions stored thereon for implementing elements for network traffic control by the SDN application; and

a processor operatively coupled to the memory and configured to execute the instructions thereby effectuating:

one or more interfaces communicatively coupling the SDN application with user equipment and a virtual private network (VPN) provider, wherein the SDN application is configured to transmit a request to establish a VPN to a VPN provider, and wherein the SDN application is configured to obtain VPN server credentials for the VPN from the VPN provider;

a policy generation module of the SDN application configured to generate a security policy related to network traffic associated with the VPN;

a policy conversion module of the SDN application configured to convert the security policy to table configured for use by an SDN controller; and

a controller communication module of the SDN application configured to provide the table to the SDN controller.

12. The computer-implemented system of claim 11 , wherein the non-transitory memory stores instructions that when executed by the processor are configured to effectuate:

an authentication module of the SDN application configured to authenticate the SDN application to the SDN controller.

13. The computer-implemented system of claim 11 , wherein a network element that enforces a security rule based on the table includes a hybrid router, wherein the hybrid router is configured to communicate by conventional and OpenFlow protocols.

14. The computer-implemented system of claim 11 , wherein the table includes at least one OpenFlow Table Type Pattern (TTP).

15. The computer-implemented system of claim 11 , wherein the table includes at least one OpenFlow Multi-Flow Table (MFT).

16. The computer-implemented system of claim 11 , wherein the non-transitory memory stores instructions that when executed by the processor are configured to effectuate:

a monitor module of the SDN application configured to monitor network traffic associated with the VPN.

17. The computer-implemented system of claim 16 , wherein the non-transitory memory stores instructions that when executed by the processor are configured to effectuate:

an analysis module of the SDN application configured to identify anomalous traffic within the network traffic associated with the VPN, wherein the security policy is based on the anomalous traffic.

18. The computer-implemented system of claim 16 , wherein the non-transitory memory stores instructions that when executed by the processor are configured to effectuate:

an analysis module of the SDN application configured to analyze the network traffic associated with the VPN,

wherein a conflict with a security rule based on the table is identified based on matching, within the network traffic associated with the VPN, a pattern defined in the table.

19. A system, comprising:

a non-transitory memory having instructions stored thereon; and

a processor operatively coupled to the memory, wherein execution of the instructions by the processor causes:

transmitting, using a software defined networking (SDN) application, a request to establish a virtual private network (VPN) to a VPN provider;

obtaining, at the SDN application and from the VPN provider, VPN server credentials for a VPN;

generating, using the SDN application, a security policy related to network traffic associated with the VPN;

converting, using the SDN application, the security policy to a table; and

transmitting, using the SDN application, the table to an SDN controller.

20. The system of claim 19 , wherein execution of the instructions by the processor causes:

monitoring, using the SDN application, network traffic information related to the VPN.

Assignments (4)
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jan 22, 2025
From: CACI LGS INNOVATIONS LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069987/0444 →
CHANGE OF NAME Recorded Nov 4, 2024
From: LGS INNOVATIONS LLC
To: CACI LGS INNOVATIONS LLC
Reel/Frame 069293/0265 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 13, 2021
From: LGS INNOVATIONS LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 058961/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2021
From: CHEN, MICHAEL JAU; THOMAS, TAVARIS JASON
To: LGS INNOVATIONS LLC
Reel/Frame 055510/0099 →
Continuity (6)
Continuation 16172975 · Oct 29, 2018
Continuation In Part 15276046 · Sep 26, 2016
Continuation In Part 15275988 · Sep 26, 2016
Continuation In Part 15275982 · Sep 26, 2016
Provisional Application 62347705 · Jun 9, 2016
Related Publication 20200213363A1 · Jul 2, 2020