IP Library › Granted Patent US 12,603,919
Granted Patent B2
US 12,603,919 · App. 18/748,596 · Granted Apr 14, 2026

Adding policy coding to packet headers to use to access resources in a secure network

Inventors: Lee Simon Cooper (Portsmouth, GB); Ralph Bateman (Southampton, GB); Scott Moonen (Fuquay Varina, NC)
Assignee: International Business Machines Corporation
H04L63/20H04L63/0227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,919
App. No.
18/748,596
Granted
Apr 14, 2026
Kind
B2
Abstract

Provided are a computer program product, system, and method for adding policy coding to packet headers to use to access resources in a secure network. A determination is made of policy information for a user defining user privileges to access resources in the secure network. The policy information is inserted into packet headers in packets to transmit to an enforcement point associated with a destination resource in the secure network indicated in the packet headers. The packets with the packet headers including the policy information are transmitted to the enforcement point. The enforcement point applies policy rules to the policy information to determine whether to forward the packets to the destination resource.

Claims (57)

1 . A computer program product for generating packets at a client device to access resources in a secure network, the computer program product comprising a computer readable storage medium having computer readable program code embodied therein that when executed performs operations, the operations comprising:

determining, at the client device, policy information for a user defining user privileges to access resources in the secure network;

inserting, at the client device, the policy information into each of a plurality of packet headers in each of a plurality of packets to transmit the packets with the inserted policy information to an enforcement point associated with a destination resource in the secure network indicated in the packet headers; and

transmitting, by the client device, the packets with the packet headers including the policy information to the enforcement point, wherein the enforcement point applies policy rules to the policy information to determine whether to forward the packets to the destination resource.

2 . The computer program product of claim 1 , wherein the determining the policy information comprises:

determining a policy coding as a function of a user type of the user, device type of the client device, and user permissions within the secure network, wherein the policy information inserted into the packet headers comprises the policy coding.

3 . The computer program product of claim 2 , wherein the policy coding comprises an encoded value indicating the user type of the user, the device type, and the user permissions, wherein the enforcement point applies the policy rules to the user permissions, the device type, and the user type indicated in the policy coding to determine whether to forward the packets to the destination resource indicated in the packets.

4 . The computer program product of claim 1 , wherein the operations further comprise:

using at least one of encryption and signing of the policy information to insert at least one of encrypted and signed policy information into the packet headers, wherein the enforcement point performs at least one of decrypting and authenticating the signed policy information and then apply the policy rules to the policy information.

5 . The computer program product of claim 1 , wherein the determining the policy information comprises:

transmitting a request to authenticate the user of the client device to an access control system of the secure network and obtain the policy information; and

receiving the policy information from the access control system to include in the packet headers of the packets transmitted to the secure network in response to the access control system authenticating the user and returning the policy information for the authenticated user.

6 . The computer program product of claim 1 , wherein the determining the policy information for the user comprises:

authenticating the user at the client device; and

accessing the policy information from local storage in the client device to include in the packet headers of the packets in response to the authenticating the user.

7 . The computer program product of claim 1 , wherein the operations further comprise:

running a packet encapsulation manager in a kernel of an operating system of the client device to perform the determining of the policy information and the inserting the policy information in the packet headers, and further performs:

intercepting packets directed to the secure network, wherein the policy information is inserted in the packet headers of the intercepted packets; and

forwarding the packets with the packet headers having the policy information to the secure network.

8 . The computer program product of claim 1 , wherein the policy information is inserted in an extended header of an Internet Protocol (IP) packet available for user determined information.

9 . A system for generating packets at a client device to access resources in a secure network, comprising:

a processor; and

a computer readable storage medium having computer readable program code embodied therein that when executed by the processor performs operations, the operations comprising:

determining, at the client device, policy information for a user defining user privileges to access resources in the secure network;

inserting, at the client device, the policy information into each of a plurality of packet headers in each of a plurality of packets to transmit the packets with the inserted policy information to an enforcement point associated with a destination resource in the secure network indicated in the packet headers; and

transmitting, by the client device, the packets with the packet headers including the policy information to the enforcement point, wherein the enforcement point applies policy rules to the policy information to determine whether to forward the packets to the destination resource.

10 . The system of claim 9 , wherein the determining the policy information comprises:

determining a policy coding as a function of a user type of the user, device type of the client device, and user permissions within the secure network, wherein the policy information inserted into the packet headers comprises the policy coding.

11 . The system of claim 10 , wherein the policy coding comprises an encoded value indicating the user type of the user, the device type, and the user permissions, wherein the enforcement point applies the policy rules to the user permissions, the device type, and the user type indicated in the policy coding to determine whether to forward the packets to the destination resource indicated in the packets.

12 . The system of claim 9 , wherein the determining the policy information comprises:

transmitting a request to authenticate the user of the client device to an access control system of the secure network and obtain the policy information; and

receiving the policy information from the access control system to include in the packet headers of the packets transmitted to the secure network in response to the access control system authenticating the user and returning the policy information for the authenticated user.

13 . The system of claim 9 , wherein the determining the policy information for the user comprises:

authenticating the user at the client device; and

accessing the policy information from local storage in the client device to include in the packet headers of the packets in response to the authenticating the user.

14 . The system of claim 9 , wherein the computer readable storage medium includes:

an operating system; and

a packet encapsulation manager running in a kernel of the operating system, wherein the packet encapsulation manager performs the determining of the policy information and the inserting the policy information in the packet headers, and further performs:

intercepting packets directed to the secure network, wherein the policy information is inserted in the packet headers of the intercepted packets; and

forwarding the packets with the packet headers having the policy information to the secure network.

15 . A computer implemented method for generating packets at a client device to access resources in a secure network, comprising:

determining, at the client device, policy information for a user defining user privileges to access resources in the secure network;

inserting, at the client device, the policy information into each of a plurality of packet headers in each of a plurality of packets to transmit the packets with the inserted policy information to an enforcement point associated with a destination resource in the secure network indicated in the packet headers; and

transmitting, by the client device, the packets with the packet headers including the policy information to the enforcement point, wherein the enforcement point applies policy rules to the policy information to determine whether to forward the packets to the destination resource.

16 . The computer implemented method of claim 15 , wherein the determining the policy information comprises:

determining a policy coding as a function of a user type of the user, device type of the client device, and user permissions within the secure network, wherein the policy information inserted into the packet headers comprises the policy coding.

17 . The computer implemented method of claim 16 , wherein the policy coding comprises an encoded value indicating the user type of the user, the device type, and the user permissions, wherein the enforcement point applies the policy rules to the user permissions, the device type, and the user type indicated in the policy coding to determine whether to forward the packets to the destination resource indicated in the packets.

18 . The computer implemented method of claim 15 , wherein the determining the policy information comprises:

transmitting a request to authenticate the user of the client device to an access control system of the secure network and obtain the policy information; and

receiving the policy information from the access control system to include in the packet headers of the packets transmitted to the secure network in response to the access control system authenticating the user and returning the policy information for the authenticated user.

19 . The computer implemented method of claim 15 , wherein the determining the policy information for the user comprises:

authenticating the user at the client device; and

accessing the policy information from local storage in the client device to include in the packet headers of the packets in response to the authenticating the user.

20 . The computer implemented method of claim 15 , further comprising:

running a packet encapsulation manager running in a kernel of an operating system of the client device, wherein the packet encapsulation manager performs the determining of the policy information and the inserting the policy information in the packet headers, and further performs:

intercepting packets directed to the secure network, wherein the policy information is inserted in the packet headers of the intercepted packets; and

forwarding the packets with the packet headers having the policy information to the secure network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: COOPER, LEE SIMON; BATEMAN, RALPH; MOONEN, SCOTT
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 067799/0883 →
Continuity (1)
Related Publication 20250392622A1 · Dec 25, 2025
References Cited (28)
US 11470100B1 · Christian · 2022 [cited by applicant]
US 11533307B2 · Mahajan · 2022 [cited by applicant]
US 11962572B2 · Sapp · 2024 [cited by applicant]
US 20040083295A1 · Amara et al. · 2004 [cited by applicant]
US 20070107061A1 · Engle · 2007 [cited by examiner]
US 20070147378A1 · Elgebaly et al. · 2007 [cited by applicant]
US 20090307751A1 · Lin et al. · 2009 [cited by applicant]
US 20130139241A1 · Leeder · 2013 [cited by examiner]
US 20150117217A1 · Stallard · 2015 [cited by examiner]
US 20160294703A1 · Langton · 2016 [cited by examiner]
US 20200059459A1 · Abraham · 2020 [cited by examiner]
US 20210160237A1 · Rozner · 2021 [cited by applicant]
US 20210227056A1 · Aluvala et al. · 2021 [cited by applicant]
US 20220210067A1 · Gross, IV · 2022 [cited by applicant]
US 20230043721A1 · Liu · 2023 [cited by applicant]
US 20230254318A1 · Hu · 2023 [cited by applicant]
US 20230353362A1 · Dyer · 2023 [cited by examiner]
US 20230362067A1 · Natal · 2023 [cited by applicant]
US 20230421538A1 · Ponaka · 2023 [cited by examiner]
“About eBPF | Calico Documentation”. [Online][Retrieved Jun. 5, 2024], 8pp. https://docs.tigera.io/calico/latest/about/kubernetes-training/about-ebpf#types-of-ebpf-program. [cited by applicant]
Cisco Systems, Inc., “IPv6 Extension Headers Review and Considerations”, Oct. 2006, 12 pp., [Online] [Retrieved Jun. 5, 2024]. https://www.cisco.com/en/US/technologies/tk648/tk872/technologies_white_paper0900aecd8054d37… [cited by applicant]
IBM Corporation, U.S. Appl. No. 18/748,666, filed Jun. 20, 2024, 37pp. [cited by applicant]
National Cyber Security Centre, “Zero Trust Architecture Design Principles”, Jul. 23, 2021. [Online] [Retrieved Apr. 22, 2024], 5pp. https://www.ncsc.gov.uk/collection/zero-trust-architecture. [cited by applicant]
Rose, S., et al., “Zero Trust Architecture”, National Institute of Standards and Technology, U.S. Department of Commerce, Aug. 10, 2020. [Online][Retrieved Jun. 18, 2024], 59pp. https://www.nist.gov/publications/zero-tr… [cited by applicant]
S. Deering, et al., “Internet Protocol, Version 6 (IPv6) Specification”, Internet Engineering Task Force (IETF), Jul. 2017, [Online][Retrieved Jun. 18, 2024], 42 pp. https://www.rfc-editor.org/rfc/rfc8200.html#page-23. [cited by applicant]
“List of IBM Patents or Patent Applications Treated as Related”, Jun. 20, 2024, 2pp. [cited by applicant]
International Searching Authority, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or Declaration,” Patent Cooperation Treaty Aug. 14, 20… [cited by applicant]
United States Notice of Allowance dated Jan. 21, 2026, 08 pages, in U.S. Appl. No. 18/748,666. [cited by applicant]