IP Library Granted Patent US 11,683,346
Granted Patent B2
US 11,683,346 · App. 17/558,661 · Granted Jun 20, 2023

Methods and systems for establishment of VPN security policy by SDN application

Inventors: Michael Jau Chen (Livingston, NJ); Tavaris Jason Thomas (New Providence, NJ)
H04L63/20H04L41/0806H04L41/0893H04L63/0272H04L63/0428H04L63/083H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,683,346
App. No.
17/558,661
Granted
Jun 20, 2023
Kind
B2
Abstract

The present application is directed to a non-transitory computer readable medium. The medium includes program instructions that, upon being executed by a processor, effectuate detecting a virtual private network (VPN) provider in a network. The program instructions also effectuate receiving, from the VPN provider, server credentials for a VPN. The program instructions further effectuate generating a security policy based upon a type or pattern of network traffic associated with the VPN. The program instructions even further effectuate converting the security policy to a table interpretable by a node in the network.

Claims (30)

1. A non-transitory computer readable medium including program instructions that, upon being executed by a processor, effectuate:

detecting, via a software defined network (SDN) application, a virtual private network (VPN) provider in a network;

receiving, from the VPN provider, server credentials for a VPN;

generating a security policy based upon a type or pattern of network traffic associated with the VPN; and

converting the security policy to a table interpretable by a node in the network.

2. The non-transitory computer readable medium of claim 1 , wherein the program instructions further effectuate receiving an alert from a network element that enforces a security rule based on the table.

3. The non-transitory computer readable medium of claim 2 , wherein the network element is a hybrid router configured to communicate via OpenFlow protocols.

4. The non-transitory computer readable medium of claim 2 , wherein the table includes an OpenFlow Table Type Pattern.

5. The non-transitory computer readable medium of claim 2 , wherein the table includes an OpenFlow Multi-Flow Table.

6. The non-transitory computer readable medium of claim 1 , wherein the security policy is based on an assessment of the network traffic related to the VPN.

7. The non-transitory computer readable medium of claim 6 , wherein the VPN is dynamically updated based on a conflict with the security policy.

8. The non-transitory computer readable medium of claim 7 , wherein the conflict is identified by associating a pattern in the table with the network traffic.

9. The non-transitory computer readable medium of claim 1 , wherein the VPN is a dynamic VPN.

10. The non-transitory computer readable medium of claim 9 , wherein the program instructions further effectuate monitoring the network traffic related to the dynamic VPN.

11. A non-transitory computer readable medium including program instructions that, upon being executed by a processor, effectuate:

detecting a software defined network (SDN) controller in a network;

authenticating with the SON controller;

receiving, via a virtual private network (VPN) provider, server credentials for a VPN;

generating a security policy related to network traffic associated with the VPN;

converting the security policy to a table; and

transmitting the table to the SDN controller.

12. The non-transitory computer readable medium of claim 11 , wherein the security policy is based on an assessment of the network traffic related to the VPN.

13. The non-transitory computer readable medium of claim 12 , wherein the VPN is dynamically updated based on a conflict with the security policy.

14. The non-transitory computer readable medium of claim 13 , wherein the conflict is identified by associating a pattern in the table with the network traffic.

15. The non-transitory computer readable medium of claim 11 , wherein the VPN is a dynamic VPN.

16. The non-transitory computer readable medium of claim 15 , wherein the program instructions further effectuate monitoring the network traffic related to the dynamic VPN.

17. The non-transitory computer readable medium of claim 11 , where the medium and the SON controller reside on a node.

18. The non-transitory computer readable medium of claim 11 , wherein the program instructions further effectuate communicating with a network element via OpenFlow protocols.

19. The non-transitory computer readable medium of claim 11 , wherein the table includes an OpenFlow Table Type Pattern.

20. The non-transitory computer readable medium of claim 11 , wherein the table includes an OpenFlow Multi-Flow Table.

Assignments (4)
SECURITY INTEREST Recorded Jul 22, 2025
From: CACI LGS INNOVATIONS LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 072172/0666 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jan 22, 2025
From: CACI LGS INNOVATIONS LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069987/0444 →
CHANGE OF NAME Recorded Nov 4, 2024
From: LGS INNOVATIONS LLC
To: CACI LGS INNOVATIONS LLC
Reel/Frame 069293/0265 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2022
From: CHEN, MICHAEL JAU; THOMAS, TAVARIS JASON
To: LGS INNOVATIONS LLC
Reel/Frame 058537/0806 →