IP Library Granted Patent US 11,799,871
Granted Patent B2
US 11,799,871 · App. 17/077,513 · Granted Oct 24, 2023

Managing security of network communications in an information handling system

Inventors: Dileep Kumar Soma (Austin, TX); Harpreet Narula (Austin, TX); Brian E. Manser (Round Rock, TX)
Assignee: Dell Products L.P.
H04L63/105H04L63/164H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,871
App. No.
17/077,513
Granted
Oct 24, 2023
Kind
B2
Abstract

A security level of data generated by an application may be communicated from the application layer to the network layer and that security level used to determine of several available network connects for transmitting the data. A method of communicating may include associating the plurality of network connections with security levels to form associations, the associations indicating security levels of data that may be transmitted over each of the plurality of network connections; receiving, at the network layer, data for transmission; determining, at the network layer, a security level for the data; determining, at the network layer, at least one network connection of a plurality of network connections to transmit the data based, at least in part, on the security level; and transmitting the data packet over the at least one network connection.

Claims (43)

1. A method, comprising:

receiving, at a device at a network layer, data for transmission;

receiving, at the device at the network layer from an application layer, an indication associated with the data;

determining, by the device at the network layer, a security level for the data based, at least in part, on the indication according to a mapping of indicators to security levels;

determining, by the device at the network layer, at least one network connection of a plurality of network connections to transmit the data in at least one data packet based, at least in part, on the security level and an association of the at least one network connection with the security level, the at least one network connection determined further based on an application priority level associated with the data; and

transmitting, by the device, the at least one data packet over the at least one network connection.

2. The method of claim 1 , wherein receiving the indication comprises receiving information through an application interface for passing information from a software module executing in a user mode to a software module executing in a kernel mode.

3. The method of claim 1 , wherein determining the at least one network connection comprises:

determining a secure network connection from the plurality of network connections for transmission of the data in a first condition when the security level corresponds to secure data;

determining any of the plurality of network connections for transmission of the data in a second condition when the security level corresponds to insecure data and the application priority level corresponds to high-priority data; and

determining an insecure network connection from the plurality of network connections for transmission of the data in a third condition when the data packet does not correspond to the first condition and does not correspond to the second condition.

4. The method of claim 1 , further comprising associating the plurality of network connections with security levels to form associations, the associations indicating security levels of data that may be transmitted over each of the plurality of network connections.

5. An apparatus, comprising:

a memory; and

a processor coupled to the memory and configured to perform steps comprising:

receiving, at a network layer, data for transmission;

receiving, at the network layer from an application layer, an indication associated with the data;

determining, at the network layer, a security level for the data based, at least in part, the indication according to a mapping of indicators to security levels;

determining, at the network layer, at least one network connection of a plurality of network connections to transmit the data in at least one data packet based, at least in part, on the security level and an association of the at least one network connection with the security level, the at least one network connection determined further based on an application priority level associated with the data; and

transmitting the at least one data packet over the at least one network connection.

6. The apparatus of claim 5 , wherein receiving the indication comprises receiving information through an application interface for passing information from a software module executing in a user mode to a software module executing in a kernel mode.

7. The apparatus of claim 5 , wherein determining the application priority level comprises receiving an indication of the application priority level from the application layer.

8. The apparatus of claim 5 , wherein determining the at least one network connection comprises:

determining a secure network connection from the plurality of network connections for transmission of the data in a first condition when the security level corresponds to secure data;

determining any of the plurality of network connections for transmission of the data in a second condition when the security level corresponds to insecure data and the application priority level corresponds to high-priority data; and

determining an insecure network connection from the plurality of network connections for transmission of the data in a third condition when the data packet does not correspond to the first condition and does not correspond to the second condition.

9. The apparatus of claim 5 , wherein the processor is further configured to associate the plurality of network connections with security levels to form associations, the associations indicating security levels of data that may be transmitted over each of the plurality of network connections.

10. An information handling system, comprising:

a first network adaptor configured to transmit data over a first network connection of a plurality of network connections;

a second network adaptor configured to transmit data over a second network connection of the plurality of network connections;

a memory; and

a processor coupled to the first network adaptor, to the second network adaptor, and to the memory, wherein the processor is configured to perform steps comprising:

associating the plurality of network connections with security levels to form associations, the associations indicating security levels of data that may be transmitted over each of the plurality of network connections, including a first security level for the first network adaptor and a second security level for the second network adaptor;

receiving, at a network layer, data for transmission;

determining, at the network layer, a security level for the data, wherein determining the security level for the data comprises receiving an indication of the security level from an application layer;

determining, at the network layer, at least one network connection of the plurality of network connections to transmit the data in at least one data packet based, at least in part, on the security level and an association of the at least one network connection with the security level, the at least one network connection determined further based, at least in part, on an application priority level associated with the data; and

transmitting the at least one data packet over the at least one network connection.

11. The information handling system of claim 10 , wherein receiving the indication comprises receiving information through an application interface for passing information from a software module executing in a user mode on the processor to a software module executing in a kernel mode on the processor.

12. The information handling system of claim 10 , wherein determining the at least one network connection comprises:

determining a secure network connection from the plurality of network connections for transmission of the data in a first condition when the security level corresponds to secure data;

determining any of the plurality of network connections for transmission of the data in a second condition when the security level corresponds to insecure data and the application priority level corresponds to high-priority data; and

determining an insecure network connection from the plurality of network connections for transmission of the data in a third condition when the data packet does not correspond to the first condition and does not correspond to the second condition.

13. The information handling system of claim 10 , wherein the processor is configured to execute a driver operating at the network layer for accessing the first network adaptor and the second network adaptor, and wherein the processor is configured to execute a filtering platform, wherein the filtering platform provides an application interface to the network layer for receiving the indication of the security level from the application layer.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0523) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0664 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0434) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 060332/0740 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (054475/0609) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0570 →
RELEASE OF SECURITY INTEREST AT REEL 054591 FRAME 0471 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0463 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 054475/0609 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0434 →
SECURITY INTEREST Recorded Nov 18, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 054475/0523 →
SECURITY AGREEMENT Recorded Nov 13, 2020
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 054591/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2020
From: SOMA, DILEEP KUMAR; NARULA, HARPREET; MANSER, BRIAN E.
To: DELL PRODUCTS L.P.
Reel/Frame 054143/0113 →