IP Library › Granted Patent US 12,659,351
Granted Patent B2
US 12,659,351 · App. 18/427,660 · Granted Jun 16, 2026

Secure network communication system and method

Inventors: Milan Ramachandran (Bangalore, IN); Piotr Kupisiewicz (Cracow, PL); Sarath Chandra Bysani (Bangalore, IN); Rajesh M (Bangalore, IN); Shailendra Hullur (Bangalore, IN)
Assignee: ELISITY, INC.
H04L63/20H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,351
App. No.
18/427,660
Granted
Jun 16, 2026
Kind
B2
Abstract

A method for securing a network is described. The method includes receiving, by a virtual-edge (VE) docker of the network, a flow-tuple including data associated with at least a source device of the network, from an Internet Protocol (IP) flow cache. The method further includes performing, by the VE docker, a policy lookup for the flow-tuple in policy for the source device. The method furthermore includes pushing, by the VE docker, a transformed network access control (NAC) including NAC constructs based on the policy lookup, to an enforcement point (EP) in proximity to the source device.

Claims (48)

1 . A method for securing a network, the method comprising:

receiving, by a virtual-edge (VE) docker of the network, a flow-tuple including data associated with at least a source device of the network, from an Internet Protocol (IP) flow cache;

performing, by the VE docker, a policy lookup for the flow-tuple in one or more policy databases for the source device; and

pushing, by the VE docker, a transformed network access control (NAC) including NAC constructs based on the policy lookup, to an enforcement point (EP) in proximity to the source device.

2 . The method of claim 1 , further comprising receiving, by the VE docker, a policy from a software-defined perimeter controller (SDP-C).

3 . The method of claim 2 , further comprising storing, by the VE docker, the policy in the one or more policy databases included in the VE docker.

4 . The method of claim 3 , wherein performing the policy lookup for the flow-tuple in the policy comprises determining whether a policy for the flow-tuple exists in the one or more policy databases.

5 . The method of claim 4 , wherein pushing the transformed NAC to the EP in priority to the source device comprises pushing the transformed NAC to the EP in proximity to the source device in response to determining that the policy for the flow-tuple exists in the one or more policy databases.

6 . The method of claim 1 , further comprising:

configuring, by the VE docker, netflows for one or more EPs, including the EP in proximity to the source device and controlled by the VE docker in the network, such that the one or more EPs are enabled to stream netflow records associated with IP flows detected by the one or more EPs, to the VE docker.

7 . The method of claim 6 , further comprising:

receiving, by the VE docker, the netflow records associated with the IP flows streamed by the EP in proximity to the source device, wherein the netflow records include the flow-tuple.

8 . The method of claim 7 , further comprising:

updating, by the VE docker, the netflow records in the IP flow cache.

9 . The method of claim 8 , further comprising:

awaiting, by the VE docker, for one or more of additions, deletions, and modifications of the policy from a software-defined perimeter controller (SDP-C).

10 . The method of claim 9 , further comprising:

receiving, by the VE docker, an IP flow timeout from the IP flow cache; and

in response to receiving the IP flow timeout, withdrawing, by the VE docker, the transformed NAC applicable for the EP in proximity to the source device.

11 . The method of claim 6 , further comprising:

receiving, by the VE docker, the netflow records associated with the IP flows streamed by an EP in proximity to a destination device of the network, wherein the netflow records include a flow-tuple including data associated with at least the destination device.

12 . The method of claim 11 , further comprising:

updating, by the VE docker, the netflow records associated with the IP flows streamed by the EP in proximity to the destination device, in the IP flow cache.

13 . The method of claim 12 , further comprising:

receiving, by the VE docker, the flow-tuple including the data associated with at least the destination device, from the IP flow cache;

performing, by the VE docker, a policy lookup for the flow-tuple including the data associated with at least the destination device in the one or more policy databases; and

pushing, by the VE docker, a transformed NAC based on the policy lookup for the flow-tuple including the data associated with at least the destination device, to the EP in proximity to the destination device.

14 . The method of claim 13 , further comprising:

awaiting, by the VE docker, for one or more of additions, deletions, and modifications of a policy from a software-defined perimeter controller (SDP-C).

15 . The method of claim 14 , further comprising:

receiving, by the VE docker, an IP flow timeout for the destination device from the IP flow cache; and

in response to receiving the IP flow timeout for the destination device, withdrawing, by the VE docker, the transformed NAC applicable for the EP in proximity to the destination device.

16 . A virtual-edge (VE) docker for securing a network, the VE docker comprising:

a processor; and

a memory storing computer-executable instructions that when executed, cause the processor to:

receive, a flow-tuple including data associated with at least a source device of the network, from an Internet Protocol (IP) flow cache;

perform a policy lookup for the flow-tuple in one or more policy databases for the source device; and

push a transformed network access control (NAC) including NAC constructs based on the policy lookup, to an enforcement point (EP) in proximity to the source device.

17 . The VE docker of claim 16 , wherein the processor is further configured to:

configure netflows for one or more EPs, including the EP in proximity to the source device and controlled by the VE docker in the network, such that the one or more EPs are enabled to stream netflow records associated with IP flows detected by the one or more EPs, to the VE docker; and

receive the netflow records associated with the IP flows streamed by the EP in proximity to the source device, wherein the netflow records include the flow-tuple.

18 . The VE docker of claim 17 , wherein the processor is further configured to:

update the netflow records in the IP flow cache.

19 . The VE docker of claim 18 , wherein the processor is further configured to:

await for one or more of additions, deletions, and modifications of a policy from a software-defined perimeter controller (SDP-C).

20 . The VE docker of claim 19 , wherein the processor is further configured to:

receive an IP flow timeout from the IP flow cache; and

in response to the reception of the IP flow timeout, withdraw the transformed NAC applicable for the EP in proximity to the source device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2024
From: RAMACHANDRAN, MILAN; BYSANI, SARATH CHANDRA; M, RAJESH; HULLUR, SHAILENDRA
To: ELISITY, INC.
Reel/Frame 066672/0266 →
Continuity (2)
Provisional Application 63539971 · Sep 22, 2023
Related Publication 20250106258A1 · Mar 27, 2025
References Cited (5)
US 9935885B1 · Shen · 2018 [cited by examiner]
US 12413626B2 · Balmakhtar · 2025 [cited by examiner]
US 20240179070A1 · Zhou · 2024 [cited by examiner]
US 20240283825A1 · Balmakhtar · 2024 [cited by examiner]
CN 119232643A · 2024 [cited by examiner]