IP Library Granted Patent US 12,407,738
Granted Patent B2
US 12,407,738 · App. 18/515,221 · Granted Sep 2, 2025

Applying overlay network policy based on users

Inventors: Nicholas Anthony Marrone (Seattle, WA); Bryan David Skene (Seattle, WA)
Assignee: TYCO FIRE & SECURITY GMBH
H04L63/205H04L12/66H04L63/102H04L63/104H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,738
App. No.
18/515,221
Granted
Sep 2, 2025
Kind
B2
Abstract

Embodiments are directed to managing communication. Credentials of a user may be provided to an authorization service such that the authorization service authenticates the user as a member of authorization groups and such that the user may be associated with a gateway on an overlay network. The authorization groups may be compared with user groups to associate the user with one or more user group. The gateway may be associated with one or more resource group based on the user groups. Policy information may be generated for the gateway based on each resource group. The policy information may be provided to the gateway to define policies associated with resources in the overlay network. The policy information may be enforced against source nodes providing overlay traffic directed to target nodes in the overlay network.

Claims (45)

1. A method, comprising:

providing credentials of users to an authorization service for an underlay network, wherein the authorization service authenticates the users as members of one or more authorization groups for the underlay network;

providing one or more user groups associated with an overlay network, each user being associated with a respective user group of the one or more user groups, the user group for a respective user identified based on a match of the user group to an authorization group in which the respective user is authenticated as a member;

providing one or more resource groups associated with one or more resources in the overlay network; and

configuring policy information for gateways of the overlay network according to an access time window, wherein the policy information is configured according to one or more disqualified access tags and one or more disqualified resource groups,

the one or more disqualified access tags being determined according to at least some of the one or more user groups associated with the access time window, and

the one or more disqualified resource groups determined based on resources corresponding to the one or more disqualified access tags.

2. The method of claim 1 , further comprising providing the policy information to the gateway over the underlay network.

3. The method of claim 2 , wherein the policy information is configured and provided to the gateway, responsive to a current time being outside of the access time window.

4. The method of claim 1 , wherein each user group is associated with one or more access tags, and each resource group is associated with one or more resource tags, and wherein the one or more disqualified access tags are determined based on the one or more access tags of respective user groups associated with the access time window.

5. The method of claim 4 , wherein the one or more access tags of the respective user groups associated with the access time window are identified, based on the respective user groups having disqualified access to the resources corresponding to the disqualified access tags within the access time window.

6. The method of claim 1 , further comprising:

providing the policy information to the gateway to define one or more policies associated with the one or more resources in the overlay network, the gateway enforcing the one or more policies in response to a source node associated with the gateway providing overlay traffic directed to a target node in the overlay network.

7. The method of claim 1 , wherein the policy information is configured for respective gateways based on which resource groups are associated with the respective gateway.

8. The method of claim 1 , further comprising:

providing one or more credentials of a user to one or more other authorization services, wherein the one or more other authorization services authenticate the user as a member of one or more other authorization groups; and

updating the one or more resource groups associated with the gateway according to the one or more other authorization groups.

9. The method of claim 1 , wherein the gateway enforces one or more policies for the overlay network according to the policy information, the gateway enforcing the one or more policies by terminating one or more of connections or traffic tunnels associated with activity that violates at least one policy of the one or more policies.

10. A system, comprising:

one or more network computers comprising memory storing instructions and one or more processors configured to execute the instructions to cause the one or more network computers to:

provide credentials of users to an authorization service for an underlay network, wherein the authorization service authenticates the users as members of one or more authorization groups for the underlay network;

provide one or more user groups associated with an overlay network, each user being associated with a respective user group of the one or more user groups, the user group for a respective user identified based on a match of the user group to an authorization group in which the respective user is authenticated as a member;

provide one or more resource groups associated with one or more resources in the overlay network; and

configure policy information for gateways of the overlay network according to an access time window, wherein the policy information is configured according to one or more disqualified access tags and one or more disqualified resource groups,

the one or more disqualified access tags being determined according to at least some of the one or more user groups associated with the access time window, and

the one or more disqualified resource groups determined based on resources corresponding to the one or more disqualified access tags.

11. The system of claim 10 , wherein the one or more processors are further configured to execute the instruction to cause the one or more network computers to provide the policy information to the gateway over the underlay network.

12. The system of claim 11 , wherein the policy information is configured and provided to the gateway, responsive to a current time being outside of the access time window.

13. The system of claim 10 , wherein each user group is associated with one or more access tags, and each resource group is associated with one or more resource tags, and wherein the one or more disqualified access tags are determined based on the one or more access tags of respective user groups associated with the access time window.

14. The system of claim 13 , wherein the one or more access tags of the respective user groups associated with the access time window are identified, based on the respective user groups having disqualified access to the resources corresponding to the disqualified access tags within the access time window.

15. The system of claim 10 , wherein the one or more processors are further configured to execute the instruction to cause the one or more network computers to:

provide the policy information to the gateway to define one or more policies associated with the one or more resources in the overlay network, the gateway enforcing the one or more policies in response to a source node associated with the gateway providing overlay traffic directed to a target node in the overlay network.

16. The system of claim 10 , wherein the policy information is configured for respective gateways based on which resource groups are associated with the respective gateway.

17. The system of claim 10 , wherein the one or more processors are further configured to execute the instruction to cause the one or more network computers to:

provide one or more credentials of a user to one or more other authorization services, wherein the one or more other authorization services authenticate the user as a member of one or more other authorization groups; and

update the one or more resource groups associated with the gateway according to the one or more other authorization groups.

18. The system of claim 10 , further comprising the gateways.

19. The system of claim 18 , wherein the gateway enforces one or more policies for the overlay network according to the policy information, the gateway enforcing the one or more policies by terminating one or more of connections or traffic tunnels associated with activity that violates at least one policy of the one or more policies.

20. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

provide credentials of users to an authorization service for an underlay network, wherein the authorization service authenticates the users as members of one or more authorization groups for the underlay network;

provide one or more user groups associated with an overlay network, each user being associated with a respective user group of the one or more user groups, the user group for a respective user identified based on a match of the user group to an authorization group in which the respective user is authenticated as a member;

provide one or more resource groups associated with one or more resources in the overlay network; and

configure policy information for gateways of the overlay network according to an access time window, wherein the policy information is configured according to one or more disqualified access tags and one or more disqualified resource groups,

the one or more disqualified access tags being determined according to at least some of the one or more user groups associated with the access time window, and

the one or more disqualified resource groups determined based on resources corresponding to the one or more disqualified access tags.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2024
From: JOHNSON CONTROLS TYCO IP HOLDINGS LLP
To: TYCO FIRE & SECURITY GMBH
Reel/Frame 067056/0552 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: MARRONE, NICHOLAS ANTHONY; SKENE, BRYAN DAVID
To: TEMPERED NETWORKS, INC.
Reel/Frame 065685/0148 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: TEMPERED NETWORKS, INC.
To: JOHNSON CONTROLS TYCO IP HOLDINGS LLP
Reel/Frame 065685/0207 →
Continuity (4)
Continuation 17378535 · Jul 16, 2021
Continuation 17084557 · Oct 29, 2020
Provisional Application 63093041 · Oct 16, 2020
Related Publication 20240089300A1 · Mar 14, 2024
References Cited (147)
US 5835727A · Wong et al. · 1998 [cited by applicant]
US 6158010A · Moriconi et al. · 2000 [cited by applicant]
US 6981156B1 · Stern et al. · 2005 [cited by applicant]
US 7209956B2 · Mache · 2007 [cited by applicant]
US 7324533B1 · Deliberato et al. · 2008 [cited by applicant]
US 7373660B1 · Guichard et al. · 2008 [cited by applicant]
US 7395349B1 · Szabo et al. · 2008 [cited by applicant]
US 7796593B1 · Ghosh et al. · 2010 [cited by applicant]
US 7881199B2 · Krstulich · 2011 [cited by applicant]
US 7996894B1 · Chen et al. · 2011 [cited by applicant]
US 8224971B1 · Miller et al. · 2012 [cited by applicant]
US 8429400B2 · Khalid et al. · 2013 [cited by applicant]
US 8489701B2 · Manion et al. · 2013 [cited by applicant]
US 8607301B2 · Carrasco · 2013 [cited by applicant]
US 8630183B2 · Miyata · 2014 [cited by applicant]
US 8832211B1 · Lebedev et al. · 2014 [cited by applicant]
US 8886827B2 · Goel et al. · 2014 [cited by applicant]
US 8959513B1 · Swaminathan · 2015 [cited by applicant]
US 9210170B1 · Kim · 2015 [cited by examiner]
US 9264522B1 · Reeves et al. · 2016 [cited by applicant]
US 9313193B1 · Mehta · 2016 [cited by examiner]
US 9432379B1 · Roche · 2016 [cited by examiner]
US 9774586B1 · Roche et al. · 2017 [cited by applicant]
US 10158545B1 · Marrone et al. · 2018 [cited by applicant]
US 10911418B1 · Fuchs et al. · 2021 [cited by applicant]
US 10999154B1 · Ahrenholz et al. · 2021 [cited by applicant]
US 11477183B1 · Brandwine · 2022 [cited by examiner]
US 11509658B1 · Kulkarni · 2022 [cited by examiner]
US 20020026532A1 · Maeda et al. · 2002 [cited by applicant]
US 20020073182A1 · Zakurdaev et al. · 2002 [cited by applicant]
US 20020143855A1 · Traversat et al. · 2002 [cited by applicant]
US 20030061479A1 · Kimura · 2003 [cited by applicant]
US 20030081620A1 · Danner et al. · 2003 [cited by applicant]
US 20030123436A1 · Joseph et al. · 2003 [cited by applicant]
US 20030177387A1 · Osterwalder · 2003 [cited by examiner]
US 20040024905A1 · Liao et al. · 2004 [cited by applicant]
US 20040143628A1 · Bradford et al. · 2004 [cited by applicant]
US 20040268121A1 · Shelest et al. · 2004 [cited by applicant]
US 20050014500A1 · Muhonen et al. · 2005 [cited by applicant]
US 20050052999A1 · Oliver et al. · 2005 [cited by applicant]
US 20050265355A1 · Havala et al. · 2005 [cited by applicant]
US 20060190458A1 · Mishina et al. · 2006 [cited by applicant]
US 20060233166A1 · Bou-Diab et al. · 2006 [cited by applicant]
US 20070019641A1 · Pai et al. · 2007 [cited by applicant]
US 20070081530A1 · Nomura et al. · 2007 [cited by applicant]
US 20070226781A1 · Chen et al. · 2007 [cited by applicant]
US 20070230352A1 · Kokku et al. · 2007 [cited by applicant]
US 20070258440A1 · Watanabe · 2007 [cited by applicant]
US 20080072282A1 · Willis et al. · 2008 [cited by applicant]
US 20080082823A1 · Starrett et al. · 2008 [cited by applicant]
US 20080151916A1 · Jetcheva et al. · 2008 [cited by applicant]
US 20080232360A1 · Mihaly et al. · 2008 [cited by applicant]
US 20080288614A1 · Gil et al. · 2008 [cited by applicant]
US 20080307519A1 · Curcio et al. · 2008 [cited by applicant]
US 20090010168A1 · Yurchenko et al. · 2009 [cited by applicant]
US 20090034738A1 · Starrett · 2009 [cited by applicant]
US 20090059906A1 · Cullen · 2009 [cited by applicant]
US 20090129374A1 · Yurchenko et al. · 2009 [cited by applicant]
US 20090210518A1 · Verma et al. · 2009 [cited by applicant]
US 20090210541A1 · Chandolu et al. · 2009 [cited by applicant]
US 20090310518A1 · Jayaram et al. · 2009 [cited by applicant]
US 20100014533A1 · Hirano et al. · 2010 [cited by applicant]
US 20100024026A1 · Ylonen et al. · 2010 [cited by applicant]
US 20100027442A1 · Chockler et al. · 2010 [cited by applicant]
US 20100042747A1 · Hascalovici et al. · 2010 [cited by applicant]
US 20100214959A1 · Kuehnel et al. · 2010 [cited by applicant]
US 20100218235A1 · Ganot · 2010 [cited by applicant]
US 20100254395A1 · Smith et al. · 2010 [cited by applicant]
US 20110016509A1 · Huang et al. · 2011 [cited by applicant]
US 20110035466A1 · Panigrahi · 2011 [cited by applicant]
US 20110090892A1 · Cooke · 2011 [cited by applicant]
US 20110103393A1 · Meier et al. · 2011 [cited by applicant]
US 20110141881A1 · Joshi et al. · 2011 [cited by applicant]
US 20110159842A1 · Vander Veen et al. · 2011 [cited by applicant]
US 20120110203A1 · Ozawa · 2012 [cited by applicant]
US 20120163196A1 · Jansen et al. · 2012 [cited by applicant]
US 20120304243A1 · Li et al. · 2012 [cited by applicant]
US 20130010621A1 · Yoshiuchi et al. · 2013 [cited by applicant]
US 20130018993A1 · Hui et al. · 2013 [cited by applicant]
US 20130046414A1 · Ree · 2013 [cited by applicant]
US 20130083725A1 · Mallya et al. · 2013 [cited by applicant]
US 20130198830A1 · Nemoto et al. · 2013 [cited by applicant]
US 20130254264A1 · Hankinson et al. · 2013 [cited by applicant]
US 20130283364A1 · Chang et al. · 2013 [cited by applicant]
US 20140026207A1 · Wang et al. · 2014 [cited by applicant]
US 20140133354A1 · Scharf et al. · 2014 [cited by applicant]
US 20140150070A1 · Peterson · 2014 [cited by applicant]
US 20140223507A1 · Xu · 2014 [cited by applicant]
US 20140282817A1 · Singer et al. · 2014 [cited by applicant]
US 20140282850A1 · Mattes et al. · 2014 [cited by applicant]
US 20140307744A1 · Dunbar et al. · 2014 [cited by applicant]
US 20140348131A1 · Duan et al. · 2014 [cited by applicant]
US 20150024677A1 · Gopal et al. · 2015 [cited by applicant]
US 20150046997A1 · Gupta et al. · 2015 [cited by applicant]
US 20150057766A1 · Ejiri et al. · 2015 [cited by applicant]
US 20150067033A1 · Martinsen et al. · 2015 [cited by applicant]
US 20150124823A1 · Pani et al. · 2015 [cited by applicant]
US 20150135259A1 · Ilyadis et al. · 2015 [cited by applicant]
US 20150281074A1 · Kubota · 2015 [cited by applicant]
US 20150365316A1 · Liao et al. · 2015 [cited by applicant]
US 20150372828A1 · Hao et al. · 2015 [cited by applicant]
US 20160028624A1 · Song et al. · 2016 [cited by applicant]
US 20160036861A1 · Mattes et al. · 2016 [cited by applicant]
US 20160149804A1 · Mirza · 2016 [cited by applicant]
US 20160255542A1 · Hughes et al. · 2016 [cited by applicant]
US 20160261641A1 · Mattes et al. · 2016 [cited by applicant]
US 20160352705A1 · Lockhart · 2016 [cited by examiner]
US 20170019430A1 · Cohn · 2017 [cited by applicant]
US 20170142208A1 · Hammer et al. · 2017 [cited by applicant]
US 20170238215A1 · Jin · 2017 [cited by applicant]
US 20170373935A1 · Subramanian et al. · 2017 [cited by applicant]
US 20170373936A1 · Hooda et al. · 2017 [cited by applicant]
US 20180083968A1 · Xu et al. · 2018 [cited by applicant]
US 20180084060A1 · Xie et al. · 2018 [cited by applicant]
US 20180124183A1 · Kozat et al. · 2018 [cited by applicant]
US 20180234459A1 · Kung et al. · 2018 [cited by applicant]
US 20190068592A1 · Mattela et al. · 2019 [cited by applicant]
US 20190132152A1 · Wang et al. · 2019 [cited by applicant]
US 20190149401A1 · Ramachandran et al. · 2019 [cited by applicant]
US 20190158397A1 · Liu · 2019 [cited by applicant]
US 20190246331A1 · Nakajima · 2019 [cited by applicant]
US 20190372876A1 · Marrone et al. · 2019 [cited by applicant]
US 20190394107A1 · Marrone et al. · 2019 [cited by applicant]
US 20200067341A1 · Glover et al. · 2020 [cited by applicant]
US 20200106780A1 · Malliah · 2020 [cited by examiner]
US 20200128018A1 · Kumaraswamy · 2020 [cited by examiner]
US 20200177503A1 · Hooda et al. · 2020 [cited by applicant]
US 20200358777A1 · Threlkeld · 2020 [cited by examiner]
US 20210075794A1 · Gazit · 2021 [cited by examiner]
US 20210084048A1 · Kannan et al. · 2021 [cited by applicant]
US 20210377272A1 · Dasari · 2021 [cited by examiner]
WO WO2007038872A1 · 2007 [cited by applicant]
WO WO2008039506A2 · 2008 [cited by applicant]
WO WO2011159842A2 · 2011 [cited by applicant]
WO WO2019246331A1 · 2019 [cited by applicant]
Aoyagi, S. et al., “ELA: A Fully Distributed VPN System Over Peer-to-Peer Network,” IEEE Computer Society, Proceedings of the 2005 Symposium on Applications and the Internet (SAINT'05), Feb. 4, 2005 (4 pages). [cited by applicant]
Asguard Networks, Inc., “Gray Matter Systems Announces Asguard Networks Partnership at 2012 Gray Matter Systems Training and User Group Meeting,” URL: http://www.asguardnetworks.com/news/, Aug. 9, 2012, retrieved from i… [cited by applicant]
Asguard Networks, Inc., “SimpleConnectTM Product Information,” URL: http://www.asguardnetworks.com/product/, retrieved from internet on Nov. 9, 2012 (1 Page). [cited by applicant]
Asguard Networks, Inc., “SimpleConnectTM Quick Start Documentation Guide,” Revision 1, Dec. 13, 2012 (18 pages). [cited by applicant]
Asguard Networks, Inc., “Welcome to Asguard Networks,” URL: http://www.asguardnetworks.com/, retrieved from internet on Oct. 23, 2012 (1 page). [cited by applicant]
Benyamina, D. et al., “Wireless Mesh Networks Design—A Survey,” IEEE Communications Survey & Tutorials, vol. 14, No. 2, Second Quarter 2012 (pp. 299-310). [cited by applicant]
Henderson, T. et al., “HIP-based Virtual Private LAN Service (HIPLS),” Network Working Group, Internet-Draft, The Boeing Company, Nov. 6, 2012 (pp. 1-16). [cited by applicant]
International Search Report and Written Opinion on PCT Appl. No. PCT/US2014/023632 dated Jun. 23, 2014 (15 pages). [cited by applicant]
International Search Report and Written Opinion on PCT Appl. No. PCT/US2015/042993 dated Nov. 11, 2015 (11 pages). [cited by applicant]
Lawton, G., “Machine-to-Machine Technology gears up for growth,” IEEE Computer Society, Sep. 2004 (pp. 12-15). [cited by applicant]
Trusted Computing Group, “Architect's Guide: ICS Security Using TNC Technology,” Oct. 2013 (pp. 1-6). [cited by applicant]
Trusted Computing Group, Incorporated, “TCG Trusted Network Connect: IF-MAP Metadata for ICS Security,” Specification Version 1.0, Revision 44, May 8, 2014 (pp. 1-64). [cited by applicant]