IP Library › Granted Patent US 12,652,318
Granted Patent B1
US 12,652,318 · App. 19/375,827 · Granted Jun 9, 2026

Method for implementing zero trust role-based microsegmentation based on network switch and network controller and access switch using the same

Inventors: Junnyung Choi (Incheon, KR); Nam Pyo Kim (Gwangmyeong-si, KR); Jae Young Park (Anyang-si, KR)
Assignee: PIOLINK, INC.
H04L63/20H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,318
App. No.
19/375,827
Granted
Jun 9, 2026
Kind
B1
Abstract

There is provided a method for implementing a zero trust role-based microsegmentation based on a network switch. The method includes steps of: (a) registering, by a network controller, the specific network device in a specific segment among preset segments by referring to asset information corresponding to the specific network device; and (b) transmitting, by the network controller, a specific segment ID corresponding to the specific segment to the access switch, to thereby instruct the access switch to assign the specific segment ID as metadata to a specific MAC address of the specific network device by using VACL, and control an access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID by using IACL.

Claims (28)

1 . A method for implementing a zero trust role-based microsegmentation, comprising steps of:

(a) in response to acquiring specific network device information for a specific network device from at least one access switch that enables network devices and network resources to communicate with one another within a network, wherein the specific network device accesses the network, registering, by a network controller, the specific network device in a specific segment among preset segments by referring to asset information corresponding to the specific network device, wherein the specific segment corresponds to the asset information, wherein the preset segments are acquired by microsegmenting the network based on a role which the network devices perform according to a network security policy for a zero trust security; and

(b) transmitting, by the network controller, a specific segment identifier (ID) corresponding to the specific segment to the access switch, to thereby instruct the access switch to assign the specific segment ID as metadata to a specific Medium Access Controller (MAC) address of the specific network device by using VACL (Vlan Access Control List), and control an access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID by using IACL (Ingress Access Control list), wherein the specific network device is registered in the specific segment.

2 . The method of claim 1 , wherein, at the step of (a), the network controller identifies at least one matching keyword corresponding to preset segment keywords by referring to attribute values for each of categories registered in the asset information corresponding to the specific network device, identifies the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

3 . The method of claim 2 , wherein, at the step of (a), in a state where at least one segment keyword is set for each of the preset segments by a network manager, the network controller identifies at least one matching keyword which is at least one specific attribute value corresponding to the segment keywords among the attribute values, identifies the specific segment for which the at least one matching keyword is set, and registers the specific network device in the specific segment.

4 . The method of claim 1 , wherein, before the step of (b), in a state where each of segment IDs corresponding to each of the preset segments is set to have at least one specific resource group accessible among resource groups, wherein the resource groups are classified by grouping based on roles of the network resources, the network controller registers an access right of each of the segment IDs for each of the network resources in the IACL by tagging each resource group to which each of the network resources belongs.

5 . The method of claim 1 , wherein, at the step of (b), the network controller instructs the access switch to identify the specific segment ID and a specific destination IP address of the specific packet transmitted from the specific network device, identify an access right of the specific segment ID for a specific network resource corresponding to the specific destination IP address through the IACL, and filter a transmission of the specific packet to the specific network resource according to the identified access right.

6 . A method for implementing a zero trust role-based microsegmentation, comprising steps of:

(a) in response to detecting a connection of a specific network device to a network, transmitting, by at least one access switch that enables network devices and network resources to communicate with one another within the network, specific network device information for the specific network device to the network controller, to thereby instruct the network controller to register the specific network device in a specific segment among preset segments by referring to asset information corresponding to the specific network device and transmit a specific segment identifier (ID) corresponding to the specific segment to the access switch, wherein the specific network device is registered in the specific segment, wherein the specific segment corresponds to specific asset information, wherein the preset segments are acquired by microsegmenting the network based on roles performed by the network devices according to a network security policy for a zero trust security; and

(b) in response to acquiring the specific segment ID corresponding to the specific network device from the network controller, assigning, by the access switch, the specific segment ID as metadata to a specific Medium Access Controller (MAC) address of the specific network device by using VACL (Vlan Access Control List), and controlling an access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID by using IACL (Ingress Access Control list).

7 . The method of claim 6 , wherein, at the step of (a), the access switch transmits the specific device information to the network controller, to thereby instruct the network controller to identify at least one matching keyword corresponding to preset segment keywords by referring to attribute values for each of categories registered in the asset information corresponding to the specific network device, identify the specific segment corresponding to the at least one matching keyword, and register the specific network device in the specific segment.

8 . The method of claim 7 , wherein, at the step of (a), in a state where at least one segment keyword is set for each of the preset segments by a network manager, the access switch instructs the network controller to identify at least one matching keyword which is at least one specific attribute value corresponding to the segment keywords among the attribute values, identify the specific segment in which the at least one matching keyword is set, and register the specific network device in the specific segment.

9 . The method of claim 6 , wherein, before the step of (b), in a state where each of segment IDs corresponding to each of the preset segments is set to have at least one specific resource group accessible among resource groups, wherein the resource groups are classified by grouping based on roles of the network resources, the access switch instructs the network controller to register an access right of each of the segment IDs for each of the network resources in the IACL by tagging each resource group to which each of the network resources belongs.

10 . The method of claim 6 , wherein, at the step of (b), the access switch identifies the specific segment ID and a specific destination IP address of a specific packet transmitted from the specific network device, identifies an access right of the specific segment ID for a specific network resource corresponding to the specific destination IP address through the IACL, and filters a transmission of the specific packet to the specific network resource according the identified access right.

11 . A network controller for implementing a zero trust role-based microsegmentation, comprising:

at least one memory which saves instructions for implementing the zero trust role-based microsegmentation; and

at least one processor configured to implement the zero trust role-based microsegmentation according to the instructions saved in the memory to perform processes of: (I) in response to acquiring specific network device information for a specific network device from at least one access switch that enables network devices and network resources to communicate with one another within a network, wherein the specific network device accesses the network, registering the specific network device in a specific segment among preset segments by referring to asset information corresponding to the specific network device, wherein the specific segment corresponds to the asset information, wherein the preset segments are acquired by microsegmenting the network based on a role which the network devices perform according to a network security policy for a zero trust security; and (II) transmitting a specific segment identifier (ID) corresponding to the specific segment to the access switch, to thereby instruct the access switch to assign the specific segment ID as metadata to a specific Medium Access Controller (MAC) address of the specific network device by using VACL (Vlan Access Control List), and control an access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID by using IACL (Ingress Access Control list), wherein the specific network device is registered in the specific segment.

12 . The network controller of claim 11 , wherein, at the process of (I), the processor identifies at least one matching keyword corresponding to preset segment keywords by referring to attribute values for each of categories registered in the asset information corresponding to the specific network device, identifies the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

13 . The network controller of claim 12 , wherein, at the process of (I), in a state where at least one segment keyword is set for each of the preset segments by a network manager, the processor identifies at least one matching keyword which is at least one specific attribute value corresponding to the segment keywords among the attribute values, identifies the specific segment for which the at least one matching keyword is set, and registers the specific network device in the specific segment.

14 . The network controller of claim 11 , wherein, before the process of (II), in a state where each of segment IDs corresponding to each of the preset segments is set to have at least one specific resource group accessible among resource groups, wherein the resource groups are classified by grouping based on roles of the network resources, the processor registers an access right of each of the segment IDs for each of the network resources in the IACL by tagging each resource group to which each of the network resources belongs.

15 . The network controller of claim 11 , wherein, at the process of (II), the processor instructs the access switch to identify the specific segment ID and a specific destination IP address of the specific packet transmitted from the specific network device, identify an access right of the specific segment ID for a specific network resource corresponding to the specific destination IP address through the IACL, and filter a transmission of the specific packet to the specific network resource according to the identified access right.

16 . An access switch for implementing a zero trust role-based microsegmentation, comprising:

at least one memory which saves instructions for implementing the zero trust role-based microsegmentation; and

at least one processor configured to implement the zero trust role-based microsegmentation according to the instructions saved in the memory to perform processes of: (I) in response to detecting a connection of a specific network device to a network, transmitting specific network device information for the specific network device to the network controller, to thereby instruct the network controller to register the specific network device in a specific segment among preset segments by referring to asset information corresponding to the specific network device and transmit a specific segment identifier (ID) corresponding to the specific segment to the access switch, wherein the specific network device is registered in the specific segment, wherein the specific segment corresponds to specific asset information, wherein the preset segments are acquired by microsegmenting the network based on roles performed by network devices according to a network security policy for a zero trust security; and (II) in response to acquiring the specific segment ID corresponding to the specific network device from the network controller, assigning the specific segment ID as metadata to a specific Medium Access Controller (MAC) address of the specific network device by using VACL (Vlan Access Control List), and controlling an access of the specific network device to network resources based on at least one specific resource access control rule corresponding to the specific segment ID by using IACL (Ingress Access Control list).

17 . The access switch of claim 16 , wherein, at the process of (I), the processor transmits the specific device information to the network controller, to thereby instruct the network controller to identify at least one matching keyword corresponding to preset segment keywords by referring to attribute values for each of categories registered in the asset information corresponding to the specific network device, identify the specific segment corresponding to the at least one matching keyword, and register the specific network device in the specific segment.

18 . The access switch of claim 17 , wherein, at the process of (I), in a state where at least one segment keyword is set for each of the preset segments by a network manager, the processor instructs the network controller to identify at least one matching keyword which is at least one specific attribute value corresponding to the segment keywords among the attribute values, identify the specific segment in which the at least one matching keyword is set, and register the specific network device in the specific segment.

19 . The access switch of claim 16 , wherein, before the process of (II), in a state where each of segment IDs corresponding to each of the preset segments is set to have at least one specific resource group accessible among resource groups, wherein the resource groups are classified by grouping based on roles of the network resources, the processor instructs the network controller to register an access right of each of the segment IDs for each of the network resources in the IACL by tagging each resource group to which each of the network resources belongs.

20 . The access switch of claim 16 , wherein, at the process of (II), the processor identifies the specific segment ID and a specific destination IP address of a specific packet transmitted from the specific network device, identifies an access right of the specific segment ID for a specific network resource corresponding to the specific destination IP address through the IACL, and filters a transmission of the specific packet to the specific network resource according the identified access right.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2025
From: CHOI, JUNNYUNG; KIM, NAM PYO; PARK, JAE YOUNG
To: PIOLINK, INC.
Reel/Frame 072752/0583 →
Priority Claims (1)
KR 10-2025-0118654 · Aug 25, 2025 · national
References Cited (16)
US 12155768B2 · Panicker et al. · 2024 [cited by applicant]
US 12177260B2 · Akali et al. · 2024 [cited by applicant]
US 20120233657A1 · Guevin · 2012 [cited by examiner]
US 20150295826A1 · Sitharaman · 2015 [cited by examiner]
US 20190132322A1 · Song · 2019 [cited by examiner]
US 20220029988A1 · Levin et al. · 2022 [cited by applicant]
US 20230025586A1 · Rolando · 2023 [cited by examiner]
US 20230026330A1 · Rolando · 2023 [cited by examiner]
US 20230026865A1 · Rolando · 2023 [cited by examiner]
US 20230188505A1 · Jensen · 2023 [cited by applicant]
US 20240283826A1 · Ganguli · 2024 [cited by examiner]
US 20240356983A1 · Akali · 2024 [cited by examiner]
JP 7645350B1 · 2025 [cited by applicant]
KR 102540094B1 · 2023 [cited by applicant]
KR 102576357B1 · 2023 [cited by applicant]
KR 102655993B1 · 2024 [cited by applicant]