IP Library Granted Patent US 11,652,696
Granted Patent B1
US 11,652,696 · App. 17/703,249 · Granted May 16, 2023

Zoned mesh network isolation

Inventors: Pierre-Yves Chibon (Saint-Pol-de-Léon, FR); Leigh Griffin (Waterford City, IE)
Assignee: Red Hat, Inc.
H04L41/12H04L41/0893H04L63/0428H04L63/20G16Y30/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,696
App. No.
17/703,249
Granted
May 16, 2023
Kind
B1
Abstract

Embodiments of the present disclosure include a processing device that determines that a first node device of a plurality of node devices in a network is non-compliant with a network policy, identifies a subset of the plurality of node devices that is associated with the first node device, and disrupts, by the processing device, a communication path of the subset of the plurality of node devices and the first node device within the network.

Claims (32)

1. A method comprising:

determining that a first node device of a plurality of node devices in a network is non-compliant with a network policy;

identifying a first subset of the plurality of node devices that are associated with the first node device and a second subset of the plurality of node devices that are not associated with the first node device; and

in response to determining that the first node device is non-compliant with the network policy, disrupting, by a processing device, a communication path of the first subset of the plurality of node devices and the first node device within the network, wherein disrupting the communication path of the first subset of the plurality of node devices and the first node device comprises altering a second cryptographic state of the second subset of the plurality of node devices to be incompatible with a first cryptographic state of the first subset of the plurality of node devices and the first node device, and

wherein disrupting the communication path of the first subset of the plurality of node devices and the first node device is performed without directly accessing the first subset of the plurality of node devices.

2. The method of claim 1 , wherein altering the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device comprises altering a cryptographic key utilized by the communication path.

3. The method of claim 1 , wherein altering the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device comprises altering a seed used to generate a cryptographic key utilized by the communication path.

4. The method of claim 1 , wherein the first subset of the plurality of node devices that are associated with the first node device each share a common feature with the first node device.

5. The method of claim 1 , wherein the first subset of the plurality of node devices that are associated with the first node device provide a same service to the network as the first node device.

6. The method of claim 1 , wherein the first subset of the plurality of node devices comprises node devices of the plurality of node devices within a threshold number of connections from the first node device.

7. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

determine that a first node device of a plurality of node devices in a network is non-compliant with a network policy;

identify a first subset of the plurality of node devices that are associated with the first node device and a second subset of the plurality of node devices that are not associated with the first node device; and

in response to determining that the first node device is non-compliant with the network policy, disrupt, by the processing device, a communication path of the first subset of the plurality of node devices and the first node device within the network, wherein, to disrupt the communication path of the first subset of the plurality of node devices and the first node device, the processing device is to alter a second cryptographic state of the second subset of the plurality of node devices to be incompatible with a first cryptographic state of the first subset of the plurality of node devices and the first node device, and

wherein disrupting the communication path of the first subset of the plurality of node devices and the first node device is performed by the processing device without directly accessing the first subset of the plurality of node devices.

8. The system of claim 7 , wherein, to alter the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device, the processing device is to alter a cryptographic key utilized by the communication path.

9. The system of claim 7 , wherein, to alter the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device, the processing device is to alter a seed used to generate a cryptographic key utilized by the communication path.

10. The system of claim 7 , wherein the first subset of the plurality of node devices that are associated with the first node device each share a common feature with the first node device.

11. The system of claim 7 , wherein the first subset of the plurality of node devices that are associated with the first node device provide a same service to the network as the first node device.

12. The system of claim 7 , wherein the first subset of the plurality of node devices comprises node devices of the plurality of node devices within a threshold number of connections from the first node device.

13. A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

determine that a first node device of a plurality of node devices in a network is non-compliant with a network policy;

identify a first subset of the plurality of node devices that are associated with the first node device and a second subset of the plurality of node devices that are not associated with the first node device; and

in response to determining that the first node device is non-compliant with the network policy, disrupt, by the processing device, a communication path of the first subset of the plurality of node devices and the first node device within the network, wherein, to disrupt the communication path of the first subset of the plurality of node devices and the first node device, the processing device is to alter a second cryptographic state of the second subset of the plurality of node devices to be incompatible with a first cryptographic state of the first subset of the plurality of node devices and the first node device, and

wherein disrupting the communication path of the first subset of the plurality of node devices and the first node device is performed by the processing device without directly accessing the first subset of the plurality of node devices.

14. The non-transitory computer-readable storage medium of claim 13 , wherein, to alter the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device, the processing device is to alter a cryptographic key utilized by the communication path.

15. The non-transitory computer-readable storage medium of claim 13 , wherein, to alter the second cryptographic state of the second subset of the plurality of node devices to be incompatible with the first cryptographic state of the first subset of the plurality of node devices and the first node device, the processing device is to alter a seed used to generate a cryptographic key utilized by the communication path.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the first subset of the plurality of node devices that are associated with the first node device each share a common feature with the first node device.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the first subset of the plurality of node devices that are associated with the first node device provide a same service to the network as the first node device.

18. The non-transitory computer-readable storage medium of claim 13 , wherein the first subset of the plurality of node devices comprises node devices of the plurality of node devices within a threshold number of connections from the first node device.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2022
From: CHIBON, PIERRE-YVES; GRIFFIN, LEIGH
To: RED HAT, INC.
Reel/Frame 059390/0316 →