IP Library Granted Patent US 11,595,305
Granted Patent B2
US 11,595,305 · App. 17/652,129 · Granted Feb 28, 2023

Device information method and apparatus for directing link-layer communication

Inventors: Patrick J. MeLampy (Dunstable, MA); Abilash Menon (Boxborough, MA); Michael Baj (Bedford, MA); Prashant Kumar (Andover, MA)
Assignee: 128 Technology, Inc.
H04L45/66H04L41/0893H04L45/34H04L45/72H04L63/08H04L63/0807H04L63/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,305
App. No.
17/652,129
Granted
Feb 28, 2023
Kind
B2
Abstract

A network device has an input configured to receive a message relating to a given device attempting to forward one or more packets across a computer network. The message has given device information relating to the given device. In addition, the routing device also has a selector, operatively coupled with the input, configured to select (after receiving the given data) a given group routing policy from a plurality of group routing policies. Preferably, the selector is configured to select the given group routing policy as a function of the given device information. The routing device also has an output operatively coupled with the selector. The output is configured to cause routing of device communication across the network using link-layer routes specified by the given group routing policy.

Claims (66)

1. A method comprising:

receiving, by a network device, a request for a device to access a computer network, wherein the request comprises an initial packet of a session for the device, and wherein the initial packet comprises machine-specific information relating to the device and a header for routing the initial packet to a destination address specified within the header;

in response to receiving the request, selecting, by the network device and based on one or more features of the machine-specific information, a routing policy for the device;

assigning, by the network device and based on the routing policy, one or more routes for which the device is permitted to access the computer network;

constructing, by the network device, a modified packet comprising the header of the initial packet and metadata inserted after the header, wherein the metadata specifies tenant information associated with a group of devices to which the device belongs, wherein the tenant information controls forwarding of the modified packet and subsequent packets of the session by network devices of the computer network along the one or more routes for which the device is permitted to access the computer network; and

sending, by the network device, the modified packet.

2. The method of claim 1 , further comprising authenticating, by the network device, the device based on the one or more features of the machine-specific information.

3. The method of claim 1 ,

wherein the initial packet further comprises user information relating to a user of the device, and

wherein selecting the routing policy for the device is based on one or more features of the machine-specific information and one or more features of the user information.

4. The method of claim 1 , further comprising assigning, by the network device and based on the routing policy, one or more of:

a bandwidth allocation for the session for the device;

a bandwidth priority for the session for the device; or

a quality of service definition for the session for the device.

5. The method of claim 1 ,

wherein the metadata that specifies the tenant information comprises a first portion of metadata, and

wherein constructing the modified packet further comprises inserting a second portion of metadata after the header, the second portion of metadata specifying a session identifier for the session associated with the packet.

6. The method of claim 5 , further comprising determining, by the network device and based on the session identifier for the session associated with the packet, a tenant comprising the group of devices to which the device belongs.

7. The method of claim 1 , wherein assigning the one or more routes for which the device is permitted to access the computer network comprises:

applying one or more Boolean expressions to the routing policy to identify the one or more routes for which the device is permitted to access the computer network.

8. The method of claim 1 , wherein selecting the routing policy for the device comprises:

accessing, based on the machine-specific information, a policy database to determine a tenant comprising the group of devices to which the device belongs; and

selecting, based on the tenant, the routing policy for the device.

9. The method of claim 1 , wherein the plurality of group routing policies comprises a hierarchical set of group routing policies, at least one of the plurality of group routing policies having at least one sub-group routing policy.

10. The method of claim 1 , wherein the machine-specific information relating to the device comprises one or more of:

a type of the device;

a manufacturer of the device a serial number of the device;

a geographic location of the device;

one or more certificates assigned to the device; or

an owner of the device.

11. A network device comprising one or more processors configured to:

receive a request for a device to access a computer network, wherein the request comprises an initial packet of a session for the device, and wherein the initial packet comprises machine-specific information relating to the device and a header for routing the initial packet to a destination address specified within the header;

in response to receiving the request, select, based on one or more features of the machine-specific information, a routing policy for the device;

assign, based on the routing policy, one or more routes for which the device is permitted to access the computer network;

construct a modified packet comprising the header of the initial packet and metadata inserted after the header, wherein the metadata specifies tenant information associated with a group of devices to which the device belongs, wherein the tenant information controls forwarding of the modified packet and subsequent packets of the session by network devices of the computer network along the one or more routes for which the device is permitted to access the computer network; and

send the modified packet.

12. The network device of claim 11 , wherein the one or more processors are further configured to authenticate the device based on the one or more features of the machine-specific information.

13. The network device of claim 11 ,

wherein the initial packet further comprises user information relating to a user of the device, and

wherein the one or more processors are configured to select the routing policy for the device based on one or more features of the machine-specific information and one or more features of the user information.

14. The network device of claim 11 , wherein the one or more processors are configured to assign, based on the routing policy, one or more of:

a bandwidth allocation for the session for the device;

a bandwidth priority for the session for the device; or

a quality of service definition for the session for the device.

15. The network device of claim 11 ,

wherein the metadata that specifies the tenant information comprises a first portion of metadata, and

wherein to construct the modified packet, the one or more processors are configured to insert a second portion of metadata after the header, the second portion of metadata specifying a session identifier for the session associated with the packet.

16. The network device of claim 11 , wherein the one or more processors are configured to assign the one or more routes for which the device is permitted to access the computer network by:

applying one or more Boolean expressions to the routing policy to identify the one or more routes for which the device is permitted to access the computer network.

17. The network device of claim 11 , wherein to select the routing policy for the device, the one or more processors are configured to:

access, based on the machine-specific information, a policy database to determine a tenant comprising the group of devices to which the device belongs; and

select, based on the tenant, the routing policy for the device.

18. The network device of claim 11 , wherein the plurality of group routing policies comprises a hierarchical set of group routing policies, at least one of the plurality of group routing policies having at least one sub-group routing policy.

19. The network device of claim 11 , wherein the machine-specific information relating to the device comprises one or more of:

a type of the device;

a manufacturer of the device

a serial number of the device;

a geographic location of the device;

one or more certificates assigned to the device; or

an owner of the device.

20. A non-transitory, computer-readable medium comprising instructions that, when executed, are configured to cause one or more processors of a network device to:

receive a request for a device to access a computer network, wherein the request comprises an initial packet of a session for the device, and wherein the initial packet comprises machine-specific information relating to the device and a header for routing the initial packet to a destination address specified within the header;

in response to receiving the request, select, based on one or more features of the machine-specific information, a routing policy for the device;

assign, based on the routing policy, one or more routes for which the device is permitted to access the computer network;

construct a modified packet comprising the header of the initial packet and metadata inserted after the header, wherein the metadata specifies tenant information associated with a group of devices to which the device belongs, wherein the tenant information controls forwarding of the modified packet and subsequent packets of the session by network devices of the computer network along the one or more routes for which the device is permitted to access the computer network; and

send the modified packet.

Assignments (2)
NUNC PRO TUNC ASSIGNMENT Recorded May 6, 2026
From: 128 TECHNOLOGY, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 075513/0087 →
CONFIRMATORY ASSIGNMENT Recorded Jan 18, 2023
From: MELAMPY, PATRICK J.; MENON, ABILASH; BAJ, MICHAEL; KUMAR, PRASHANT
To: 128 TECHNOLOGY, INC.
Reel/Frame 062417/0079 →
Continuity (2)
Continuation 17011181 · Sep 3, 2020
Related Publication 20220182319A1 · Jun 9, 2022