IP Library Patent Application 18902257
Patent Application
App. No. 18/902,257

METHOD FOR APPLICATION CLASS OF SERVICE IN ZERO TRUST CAMPUS NETWORK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/902,257
Abstract

Disclosed herein are system, method, and computer program product aspects for providing packets from an agent-based zero trust network access (ZTNA) user device class of service in a campus network. Some aspects of this disclosure relate to a user equipment (UE) including a memory and a processor. The processor is configured to generate a packet that include a payload and an inner header and generate an encrypted packet by encrypting the packet. The processor is further configured to generate a combined packet based on the encrypted packet and an outer header. The outer header indicates a class of service corresponding to the packet. The processor is further configured to transmit the combined packet to a campus network via a secured tunnel.

Claims (46)

1 . A user equipment (UE), comprising:

a memory;

at least one processor coupled to the memory and configured to:

generate a packet that includes a payload and an inner header;

generate an encrypted packet by encrypting the packet;

generate a combined packet based on the encrypted packet and an outer header, wherein the outer header indicates a class of service corresponding to the packet; and

transmit the combined packet to a campus network via a secured tunnel.

2 . The UE of claim 1 , wherein the outer header further indicates a permission to access the campus network.

3 . The UE of claim 1 , wherein the campus network is a zero trust network access (ZTNA) network.

4 . The UE of claim 1 , wherein to generate the combined packet, the at least one processor is further configured to:

determine the class of service based on the packet; and

generate the outer header based on the class of service.

5 . The UE of claim 1 , wherein the secured tunnel is an Internet protocol security (IPSEC) tunnel or a wireguard tunnel.

6 . The UE of claim 1 , wherein the outer header is an Internet protocol differentiated services code point (IP DSCP) header.

7 . The UE of claim 1 , wherein the inner header is a transmission control protocol/Internet protocol (TCP/IP) header.

8 . The UE of claim 1 , wherein the at least one processor is further configured to:

connect to the campus network; and

in response to connecting to the campus network, generate the combined packet.

9 . A method of a user equipment (UE), comprising:

generating a packet that includes a payload and an inner header;

generating an encrypted packet by encrypting the packet;

generating a combined packet based on the encrypted packet and an outer header, wherein the outer header indicates a class of service corresponding to the packet; and

transmitting the combined packet to a campus network via a secured tunnel.

10 . The method of claim 9 , wherein the outer header further indicates a permission to access the campus network.

11 . The method of claim 9 , wherein the campus network is a zero trust network access (ZTNA) network.

12 . The method of claim 9 , wherein the generating the combined packet further comprises:

determining the class of service based on the packet; and

generating the outer header based on the class of service.

13 . The method of claim 9 , wherein the secured tunnel is an Internet protocol security (IPSEC) tunnel or a wireguard tunnel.

14 . The method of claim 9 , wherein the outer header is an Internet protocol differentiated services code point (IP DSCP) header.

15 . The method of claim 9 , wherein the inner header is a transmission control protocol/Internet protocol (TCP/IP) header.

16 . The method of claim 9 , further comprising:

connecting to the campus network; and

in response to connecting to the campus network, generating the combined packet.

17 . A non-transitory computer-readable medium (CRM) comprising instructions to, upon execution of the instructions by one or more processors of a user equipment (UE), cause the UE to perform operations, the operations comprising:

generating a packet that includes a payload and an inner header;

generating an encrypted packet by encrypting the packet;

generating a combined packet based on the encrypted packet and an outer header, wherein the outer header indicates a class of service corresponding to the packet; and

transmitting the combined packet to a campus network via a secured tunnel.

18 . The non-transitory CRM of claim 17 , wherein the outer header further indicates a permission to access the campus network.

19 . The non-transitory CRM of claim 17 , wherein the generating the combined packet further comprises:

determining the class of service based on the packet; and

generating the outer header based on the class of service.

20 . The non-transitory CRM of claim 17 , wherein the operations further comprise:

connecting to the campus network; and

in response to connecting to the campus network, generating the combined packet.

Assignments (2)
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2024
From: GROSSER, DONALD B.; SAMARYA, MAHENDRA; BICKFORD, CHARLES; YOHE, KEVIN, II; JAMES, SUVEENA; BRADY, MICHAEL
To: EXTREME NETWORKS, INC.
Reel/Frame 069507/0543 →