IP Library Granted Patent US 11,916,966
Granted Patent B2
US 11,916,966 · App. 17/366,285 · Granted Feb 27, 2024

Access policy management

Inventor: Miika Anttoni Klemetti (Kanata, CA)
Assignee: Adaptiv Networks Inc.
H04L63/20H04L63/029H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,966
App. No.
17/366,285
Granted
Feb 27, 2024
Kind
B2
Abstract

A system for access policy management of a plurality of valid entities communicating over a network comprising a server executing an application programming interface for registration and authentication of said entities directly or via an edge router, one or more encrypted tunnels between entities and one or more gateways. Wherein said server assigns a private IP address to each authenticated entities and propagates said IP address and associated access policies to each of said one or more gateway; and said one or more gateway processing and routing a plurality of packets received from each entity and enforcing one or more access policies associated with the private IP address assigned to the authenticated entity; and said one or more gateways manage routes based on the propagated private IP addresses of each authenticated entities and routes packets to reach one or more remote entities via one or more tunnels to one or more other gateways creating a network overlay between authenticated entities.

Claims (17)

1. A system for access policy management of a plurality of valid entities communicating over a network comprising:

a server executing an authentication application programming interface (API) for registration and authentication of said entities;

one or more encrypted tunnels between entities; and

one or more gateways;

wherein said server authenticates and registers each entity and assigns a private IP address to each authenticated entity and propagates said private IP address and one or more associated access policies to each of said one or more gateways; and

said one or more gateways processing and routing a plurality of packets received from each of said entities and enforcing, by respective data plane modules associated with said one or more gateways, said one or more access policies associated with the private IP address assigned to the each of said authenticated entities; and

said one or more gateways managing routes based on the private IP addresses of each authenticated entities and routes packets to reach one or more remote entities via one or more tunnels to one or more other gateways creating a network overlay between authenticated entities.

2. The system of claim 1 further comprising an edge router performing the authentication and registration for said entities.

3. A method for access policy management of a plurality of entities communicating over a network comprising:

managing one or more encrypted tunnels between entities and one or more gateways;

authenticating and registering said entities by a server;

assigning, by said server, a private IP address to each authenticated entities and propagating said private IP address and associated access policies to each of said one or more gateways; and

processing and routing, by each of said one or more gateways, a plurality of packets received from each entity and enforcing one or more access policies, using a data plane module coupled to the gateway, associated with the private IP address assigned to the authenticated entity; and

managing, by said one or more gateways, routes based on the private IP addresses of each authenticated entities and routing packets to reach one or more remote entities via one or more tunnels to one or more other gateways creating a network overlay between authenticated entities.

4. The method of claim 3 further comprising performing, by an edge router, the authentication and registration for said entities.

5. The system of claim 1 wherein said data plane module matches the private IP address of each entity with configured access policies.

6. The method of claim 3 wherein said data plane module matches the private IP address of each entity with configured access policies.

Assignments (6)
CHANGE OF NAME Recorded Mar 31, 2026
From: ADEIA MEDIA HOLDINGS LLC
To: ADEIA MEDIA HOLDINGS INC.
Reel/Frame 075306/0115 →
SECURITY INTEREST Recorded May 28, 2025
From: ADEIA INC. (F/K/A XPERI HOLDING CORPORATION); ADEIA HOLDINGS INC.; ADEIA MEDIA HOLDINGS INC.; ADEIA IMAGING LLC; ADEIA MEDIA LLC; ADEIA MEDIA SOLUTIONS INC.; ADEIA SEMICONDUCTOR BONDING TECHNOLOGIES INC.; ADEIA TECHNOLOGIES INC.; ADEIA GUIDES INC.; ADEIA SOLUTIONS LLC; ADEIA SEMICONDUCTOR ADVANCED TECHNOLOGIES INC.; ADEIA SEMICONDUCTOR SOLUTIONS LLC; ADEIA SEMICONDUCTOR INTELLECTUAL PROPERTY LLC; ADEIA SEMICONDUCTOR TECHNOLOGIES LLC; ADEIA PUBLISHING INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 071454/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2025
From: ADAPTIV NETWORKS INC.
To: ADEIA MEDIA HOLDINGS LLC
Reel/Frame 069975/0375 →
SECURITY INTEREST Recorded Apr 2, 2023
From: ADAPTIV NETWORKS INC.
To: BDC CAPITAL INC.
Reel/Frame 063232/0415 →
SECURITY INTEREST Recorded Mar 28, 2023
From: ADAPTIV NETWORKS INC.
To: BDC CAPITAL INC.
Reel/Frame 063174/0621 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2021
From: KLEMETTI, MIIKA ANTTONI
To: ADAPTIV NETWORKS INC.
Reel/Frame 056741/0973 →