IP Library › Granted Patent US 11,632,402
Granted Patent B2
US 11,632,402 · App. 16/938,187 · Granted Apr 18, 2023

Security policy translation in interface to network security functions

Inventor: Jaehoon Jeong (Busan, KR)
Assignee: Research & Business Foundation Sungkyunkwan University
H04L63/205H04L41/0893H04L41/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,632,402
App. No.
16/938,187
Granted
Apr 18, 2023
Kind
B2
Abstract

A method and a device for policy translation of a data converter in a security management system are disclosed.

Claims (26)

1. A method for performing, by a security controller, policy translation in a security management system, the method comprising:

receiving, by the security controller, extracted data from a high-level security policy, that is received from an Interface to Network Security Functions (I2NSF) user via a consumer-facing interface;

searching, by the security controller, a target NSF based on the extracted data and a capability of registered Network Security Function (NSF),

wherein the extracted data is extracted through a first state indicating a start or an end of the high-level security policy, a second state for determining a type of the extracted data, and a third state extracting data;

converting, by the security controller, the extracted data into a capability of the target NSF; and

generating, by the security controller, a low-level security policy for the target NSF based on the capability of the target NSF.

2. The method of claim 1 , wherein the first state, the second state, and the third state are transitioned based on a tag character included in the high-level security policy.

3. The method of claim 1 , wherein the converting into the capability of the target NSF is performed through an NSF database including endpoint information, NSF capability information, and field information.

4. The method of claim 3 , wherein the NSF capability information is acquired from a developer's management system through a registration interface data model and includes an NSF container and an NSF capability container.

5. The method of claim 4 , wherein the NSF capability container includes a capability name and an index indicating a capability field.

6. The method of claim 5 , wherein the NSF container includes an NSF name, an NSF specification, and information related to NSF activation.

7. The method of claim 6 , wherein the field information includes an index related to an NSF-facing interface data model for a low-level security policy.

8. The method of claim 1 , wherein the low-level security policy is generated through a content layer related to the high-level security policy and a structure layer for grouping objects with different tags.

9. A security controller for performing policy translation in a security management system, the security controller configured to:

receive extracted data from a high-level security policy, that is received from an Interface to Network Security Function (I2NSF) user via a consumer-facing interface,

search a target NSF based on the extracted data and a capability of registered Network Security Function (NSF),

wherein the extracted data is extracted through a first state indicating a start or an end of the high-level security policy, a second state for determining a type of the extracted data, and a third state extracting data,

convert the extracted data into a capability of the target NSF, and

generate a low-level security policy for the target NSF based on the capability of the target NSF.

10. The security controller of claim 9 , wherein the first state, the second state, and the third state are transitioned based on a tag character included in the high-level security policy.

11. The security controller of claim 9 , wherein converting into the capability of the target NSF is performed through an NSF database including endpoint information, NSF capability information, and field information.

12. The security controller of claim 11 , wherein the NSF capability information is acquired from a developer's management system through a registration interface data model and includes an NSF container and an NSF capability container.

13. The security controller of claim 12 , wherein the NSF capability container includes a capability name and an index indicating a capability field.

14. The security controller of claim 13 , wherein the NSF container includes an NSF name, an NSF specification, and information related to NSF activation.

15. The security controller of claim 14 , wherein the field information includes an index related to an NSF-facing interface data model for the low-level security policy.

16. The security controller of claim 15 , wherein the low-level security policy is generated through a content layer related to the high-level security policy and a structure layer for grouping objects with different tags.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2020
From: JEONG, JAEHOON
To: RESEARCH & BUSINESS FOUNDATION SUNGKYUNKWAN UNIVERSITY
Reel/Frame 053310/0861 →
Priority Claims (2)
KR 10-2019-0089888 · Jul 24, 2019 · national
KR 10-2019-0139815 · Nov 4, 2019 · national
Continuity (1)
Related Publication 20210029175A1 · Jan 28, 2021