IP Library Granted Patent US 12,323,637
Granted Patent B2
US 12,323,637 · App. 17/573,090 · Granted Jun 3, 2025

Method and apparatus for firewalling images at a network endpoint

Inventors: Anurag Sharma (Bangalore, IN); Albert Elcock (West Chester, PA)
Assignee: ARRIS ENTERPRISES LLC
H04N21/23418
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,637
App. No.
17/573,090
Filed
Jan 11, 2022
Granted
Jun 3, 2025
Kind
B2
Art Unit
2426
USPC
725/25
Abstract

A method and apparatus for managing image data transceived via a network endpoint communicatively coupled to one or more image generating devices is disclosed. The method comprises accepting a plurality of data streams in the network endpoint, at least one data stream of the plurality of data streams comprising image data from the one or more image generating devices, analyzing the plurality of data streams to identify the image data and to compare the identified image data with an image signature of a cataloged object, determining, from the comparison, that the image data depicts the cataloged object, modifying the image data according to an network image policy stored by the network endpoint, and transmitting the plurality of data streams including the modified image data.

Claims (85)

1. A method of a network endpoint for managing image data transceived of a network, the network endpoint communicatively coupled to one or more image generating devices, comprising:

accepting a plurality of data streams, from the one or more image generating devices within the network, generated by the one or more image generating devices, wherein the network endpoint is coupled to a network service provider to provide communications outside the network to one or more entities;

parsing the at least one data stream to identify one or more data packets, wherein the one or more data packets comprise one or more individual packets or one or more image frames, wherein the identifying is based on information that identifies the one or more individual packets or the one or more image frames as including the image data;

analyzing the one or more data packets to identify the image data;

comparing a generated image signature for an object depicted in the identified image data with an image signature of a cataloged object;

determining, from the comparison, that the identified image data depicts the cataloged object;

modifying the identified image data according to a network image policy stored by the network endpoint; and

transmitting, to at least one entity of the one or more entities outside the network via the network service provider, the plurality of data streams including the modified identified image data.

2. The method of claim 1 , wherein:

the network image policy relates an image disposition policy to the cataloged object;

modifying the identified image data according to the network image policy stored by the network endpoint comprises:

determining the image disposition policy from the cataloged object; and

modifying the identified image data according to the image disposition policy.

3. The method of claim 2 , wherein:

the network image policy further relates the one or more image generating devices to the image disposition policy; and

the image disposition policy is further determined from the one or more image generating device sourcing the image data.

4. The method of claim 3 , wherein:

the network image policy further relates a destination of the image data to an image disposition policy; and

the image disposition policy is further determined from the destination of the image data.

5. The method of claim 4 , wherein:

the network image policy indicates that the cataloged object is a prohibited object, and wherein modifying the identified image data and transmitting the plurality of data streams including the modified identified image data according to the network image policy comprises:

if the cataloged object is depicted by the identified image data, modifying the identified image data to modify the depiction of the prohibited object according to the network image policy, and transmitting the plurality of data streams including the at least one data stream having the modified identified image data; and

if the prohibited object is not depicted by the identified image data, transmitting the plurality of datastreams including the at least one data stream having the modified identified image data.

6. The method of claim 5 , wherein the modification comprises obfuscation.

7. The method of claim 5 , wherein the modification comprises substituting an image of a proxy identified in the network image policy.

8. The method of claim 7 , wherein the proxy is an augmented reality proxy.

9. The method of claim 1 , wherein:

the image data comprises video data comprising a plurality of temporally sequential frames;

the analyzing the plurality of data streams to identify the image data and to compare the identified image data with an image signature of a cataloged object comprises:

comparing one of the plurality of temporally sequential frames with another one of the plurality of temporally sequential frames to determine that an object has appeared; and

initiating the comparison of the identified image data with an image signature of a cataloged object when it is determined that an object has appeared.

10. An apparatus for managing image data transceived by a network endpoint of a network communicatively coupled to one or more image generating devices, comprising:

a parser of the network endpoint, wherein the parser accepts a plurality of data streams, from the one or more image generating devices within the network, generated by the one or more image generating devices, wherein the network endpoint is coupled to a network service provider to provide communications outside the network to one or more entities; and

a manager, wherein the manager controls:

parsing the at least one data stream to identify one or more data packets, wherein the one or more data packets comprise one or more individual packets or one or more image frames, wherein the identifying is based on information that identifies the one or more individual packets or the one or more image frames as including the image data;

analyzing the one or more data packets to identify image data;

comparing a generated image signature for an object depicted in the identified image data with an image signature of a cataloged object;

determining from the comparison, if the cataloged object is depicted by the identified image data;

modifying the identified image data according to a network image policy stored by the network endpoint; and

transmitting, to at least one entity of the one or more entities outside the network via the network service provider, the plurality of data streams including the modified identified image data.

11. The apparatus of claim 10 , wherein:

the network image policy relates an image disposition policy to the cataloged object and is stored in a policy database;

wherein the identified image data is modified and the plurality of datastreams including the modified identified image data are transmitted according to the network image policy stored in the policy database by:

determining the image disposition policy from the cataloged object; and

modifying the identified image data and transmitting the plurality of data streams including the modified identified image data according to the image disposition policy.

12. The apparatus of claim 11 , wherein:

the network image policy further relates the one or more image generating devices to the image disposition policy; and

the image disposition policy is further determined from the one or more image generating device sourcing the image data.

13. The apparatus of claim 12 , wherein:

the network image policy further relates a destination of the image data to an image disposition policy; and

the image disposition policy is further determined from the destination of the image data.

14. The apparatus of claim 13 , wherein:

the network image policy indicates that the cataloged object is a prohibited object, and wherein the manager further controls modifying the identified image data and transmitting the plurality of data streams including the modified identified image data according to the network image policy by:

modifying the identified image data to modify the depiction of the prohibited object according to the network image policy, and transmitting the plurality of data streams including the at least one data stream having the modified identified image data if the cataloged object is depicted by the identified image data; and

transmitting the plurality of data streams including the at least one data stream having the modified identified image data if the prohibited object is not depicted by the image data.

15. The apparatus of claim 10 , wherein:

the image data comprises video data comprising a plurality of temporally sequential frames;

the manager further controls analyzing the plurality of data streams to identify the image data and to compare the identified image data with an image signature of a cataloged object by:

comparing one of the plurality of temporally sequential frames with another one of the plurality of temporally sequential frames to determine that an object has appeared; and

initiating the comparison of the identified image data with an image signature of a cataloged object when it is determined that an object has appeared.

16. A network endpoint for managing image data transceived via the network endpoint of a network, the network endpoint communicatively coupled to one or more image generating devices, the network endpoint comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

accepting a plurality of data streams from the one or more image generating devices within the network, generated by the one or more image generating devices, wherein the network endpoint is coupled to a network service provider to provide communications outside the network to one or more entities;

parsing the at least one data stream to identify one or more data packets, wherein the one or more data packets comprise one or more individual packets or one or more image frames, wherein the identifying is based on information that identifies the one or more individual packets or the one or more image frames as including the image data;

analyzing the one or more data packets to identify the image data;

comparing a generated image signature for an object depicted in the identified image data with an image signature of a cataloged object;

determining, from the comparison, if the cataloged object is depicted by the identified image data; and

modifying the identified image data according to a network image policy stored by the network endpoint; and

transmitting, to at least one entity of the one or more entities outside the network via the network service provider, the plurality of data streams including the modified identified image data.

17. The apparatus of claim 16 , wherein:

the network image policy relates an image disposition policy to the cataloged object;

the processor instructions for modifying the identified image data and transmitting the plurality of data streams including the modified identified image data according to the network image policy stored by the network endpoint comprises processor instructions for:

determining the image disposition policy from the cataloged object; and

modifying the identified image data and transmitting the plurality of data streams including the modified identified image data according to the image disposition policy.

18. The apparatus of claim 17 , wherein:

the network image policy further relates the one or more image generating devices to the image disposition policy; and

the image disposition policy is further determined from the one or more image generating device sourcing the image data.

19. The apparatus of claim 18 , wherein:

the network image policy further relates a destination of the image data to an image disposition policy; and

the image disposition policy is further determined from the destination of the image data.

20. The apparatus of claim 19 , wherein:

the network image policy indicates that the cataloged object is a prohibited object, and wherein the processor instructions for modifying the identified image data and transmitting the plurality of data streams including the modified identified image data according to the network image policy comprises processor instructions for:

modifying the identified image data to modify the depiction of the prohibited object according to the network image policy, and transmitting the plurality of data streams including the at least one data stream having the modified identified image data if the cataloged object is depicted by the identified image data; and

transmitting the plurality of data streams including the at least one data stream having the modified identified image data if the prohibited object is not depicted by the identified image data.

Assignments (8)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 059350/0743 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074594/0156 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT REEL/FRAME NO. 59710/0506 Recorded Jan 9, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074282/0522 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 059350/0921 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069743/0704 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Mar 9, 2022
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: WILMINGTON TRUST
Reel/Frame 059710/0506 →
TERM LOAN SECURITY AGREEMENT Recorded Mar 8, 2022
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059350/0921 →
ABL SECURITY AGREEMENT Recorded Mar 8, 2022
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059350/0743 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2022
From: SHARMA, ANURAG; ELCOCK, ALBERT
To: ARRIS ENTERPRISES LLC
Reel/Frame 058620/0593 →
Continuity (2)
Provisional Application 63135959 · Jan 11, 2021
Related Publication 20220224955A1 · Jul 14, 2022
References Cited (7)
US 9043826B1 · Patil · 2015 [cited by examiner]
US 20120207356A1 · Murphy · 2012 [cited by applicant]
US 20180041693A1 · Saraya et al. · 2018 [cited by applicant]
EP 2981063 · 2016 [cited by applicant]
EP 2981063A2 · 2016 [cited by examiner]
WO 2018039646 · 2018 [cited by applicant]
International Preliminary Report on Patentability and Written Opinion issued Jul. 20, 2023 in International Application No. PCT/US2022/011968. [cited by applicant]