IP Library Granted Patent US 7,647,410
Granted Patent B2
US 7,647,410 · App. 10/650,456 · Granted Jan 12, 2010

Network rights management

Assignee: Procera Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,647,410
App. No.
10/650,456
Granted
Jan 12, 2010
Kind
B2
Abstract

Methods and apparatus, including computer program products, implement techniques of processing data packets in a computer network. The computer network includes a multiport network device and a computer executing a software application. The multiport network device is configured to receive data packets to be transmitted using the computer network and the network device stores one or more authorized network descriptors. The software application generates data packets to be transmitted to the computer network through the network device. The software application registers the network rights descriptor with the network device and inserts the network rights descriptor in each generated data packet. The network device is configured to discard the data packet if the network rights descriptor in the data packet does not match an authorized network rights descriptor and to process the data packet if the network rights descriptor in the data packet matches an authorized network rights descriptor.

Claims (43)

1. A computer network comprising:

a multiport network device to receive data packets to be transmitted using the computer network, the network device storing one or more authorized network descriptors; and

a computer executing a software application, the software application generating data packets to be transmitted to the computer network through the network device, the software application registering a network rights descriptor with the network device, the software application inserting the network rights descriptor in each generated data packet;

wherein the network device is configured to discard the data packet if the local network rights descriptor in the data packet does not match an authorized local network rights descriptor, to determine whether the local network rights descriptor should be stripped from the data packet if the local network rights descriptor in the data packet matches an authorized network rights descriptor, and to process the data packet after the determination, wherein the network rights descriptor comprises an application rights descriptor, a content rights descriptor, and an enterprise rights descriptor, wherein the application rights descriptor is used to include information regarding a software application, device, or network appliance generating the data packet.

2. The computer network of claim 1 , wherein:

the one or more authorized network descriptors are stored persistently in the network device.

3. The computer network of claim 1 , wherein:

the one or more authorized network descriptors are stored in a device connected to the computer network, and the network device is configured to retrieve the authorized network descriptors from the device.

4. The computer network of claim 1 , wherein: the network device is configured to retrieve the authorized network descriptors from an authentication server.

5. The computer network of claim 1 , wherein:

the network device stores one or more user defined packet policies, and is configured to perform an action from a user defined packet policy that matches the network rights descriptor.

6. The computer network of claim 1 , wherein:

the network device is configured to route the data packet using a layer 2-3 switch.

7. The computer network of claim 1 , wherein: the network rights descriptor is encrypted.

8. The computer network of claim 1 , wherein: the network device is configured to process the data packet at wire-speed.

9. The computer network of claim 1 , wherein:

the network device is configured to block discarded data packets from utilizing the computer network, redirect discarded data packets, and log discarded data packets.

10. A computer network comprising:

a first multiport network device to receive data packets to be transmitted using the computer network, the first network device inserting a local network descriptor in each data packet transmitted by the first network device;

a second network device to receive data packets from the computer network, the second network device storing one or more authorized local network descriptors;

wherein the second network device is configured to discard the data packet if the local network descriptor in the data packet does not match an authorized local network descriptor, and to determine whether the local network descriptor should be stripped from the data packet if the local network descriptor in the data packet matches an authorized local network descriptor, and to process the data packet after the determination, wherein the network rights descriptor comprises an application rights descriptor, a content rights descriptor, and an enterprise rights descriptor, wherein the application rights descriptor is used to include information regarding a software application, device, or network appliance generating the data packet.

11. The computer network of claim 10 , wherein: the one or more authorized network descriptors are stored persistently in the second network device.

12. The computer network of claim 10 , wherein:

the one or more authorized network descriptors are stored in a device connected to the computer network, and the second network device is configured to retrieve the authorized network descriptors from the device.

13. The computer network of claim 10 , wherein: the second network device is configured to retrieve the authorized network descriptors from an authentication server.

14. The computer network of claim 10 , wherein the second network device stores one or more user defined packet policies, and is configured to perform an action from a user defined packet policy that matches the network rights descriptor.

15. The computer network of claim 10 , wherein:

the second network device is configured to route the data packet using a layer 2-3 switch.

16. The computer network of claim 10 , wherein: the network rights descriptor is encrypted.

17. The computer network of claim 10 , wherein: the first network device is configured to process the data packet at wire-speed.

18. The computer network of claim 10 , wherein:

the second network device is configured to process the data packet at wire-speed.

19. The computer network of claim 10 , wherein:

the second network device is configured to block discarded data packets from utilizing the computer network, redirect discarded data packets, and log discarded data packets.

20. The computer network of claim 10 , wherein the second network device is configured to strip the local network descriptor before processing the data packet, if the data packet has a destination external to the computer network.

21. A method for processing data packets in a computer network, comprising:

storing one or more authorized network descriptors at a multiport network device;

generating data packets at a software application, the data packets to be transmitted to the computer network through the network device;

inserting a network rights descriptor in each generated data packet with the software application;

receiving input at the network device identifying the network rights descriptor as an authorized network rights descriptor;

receiving a data packet at the network device, the data packet including information from one or more of Layers 2 through 7 of the OSI model;

if the network rights descriptor in the data packet matches an authorized network rights descriptor, processing the data packet at the network device; and

if the network rights descriptor in the data packet does not match an authorized network rights descriptor, discarding the data packet, wherein the network rights descriptor comprises an application rights descriptor, a content rights descriptor, and an enterprise rights descriptor, wherein the application rights descriptor is used to include information regarding a software application, device, or network appliance generating the data packet.

Assignments (15)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 25, 2025
From: BARINGS FINANCE LLC, AS THE COLLATERAL AGENT FOR THE SECURED PARTIES
To: PROCERA NETWORKS, INC.
Reel/Frame 070316/0447 →
SECURITY INTEREST Recorded Sep 3, 2024
From: JEFFERIES FINANCE LLC
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 068473/0448 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Nov 5, 2018
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: PROCERA NETWORKS, INC.
Reel/Frame 047417/0370 →
SECURITY INTEREST Recorded Nov 5, 2018
From: PROCERA NETWORKS, INC.
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 047408/0122 →
SECURITY INTEREST Recorded Nov 5, 2018
From: PROCERA NETWORKS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 047408/0091 →
SECURITY INTEREST Recorded Sep 22, 2017
From: PROCERA NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 043668/0169 →
RELEASE OF SECURITY INTEREST Recorded Sep 22, 2017
From: ANTARES CAPITAL LP
To: PROCERA NETWORKS, INC.
Reel/Frame 043668/0150 →
TERMINATION AND RELEASE OF SECURITY INTERESTS IN A PATENT Recorded Jun 1, 2017
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: PROCERA NETWORKS, INC.
Reel/Frame 042649/0229 →
TERMINATION AND RELEASE OF SECURITY INTERESTS IN PATENTS Recorded Jun 1, 2017
From: SILICON VALLEY BANK
To: PROCERA NETWORKS, INC.
Reel/Frame 042648/0769 →
NOTICE OF SECURITY INTEREST IN PATENTS Recorded May 31, 2017
From: PROCERA NETWORKS, INC.
To: ANTARES CAPITAL LP, AS ADMINISTRATIVE AGENT
Reel/Frame 042644/0247 →
SECURITY AGREEMENT Recorded Jun 5, 2015
From: PROCERA NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 035832/0247 →
SECURITY AGREEMENT Recorded Dec 23, 2009
From: PROCERA NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 023698/0570 →
RELEASE OF SECURITY INTEREST Recorded Dec 3, 2009
From: PENINSULA BANK BUSINESS FUNDING
To: PROCERA NETWORKS, INC.
Reel/Frame 023602/0854 →
SECURITY AGREEMENT Recorded Apr 10, 2009
From: PROCERA NETWORKS, INC.
To: PENINSULA BANK BUSINESS FUNDING, A DIVISION OF THE PRIVATE BANK OF THE PENINSULA
Reel/Frame 022535/0108 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2003
From: CLAUDATOS, CHRISTOPHER H.; HANSEN, MAGNUS B.
To: PROCERA NETWORKS
Reel/Frame 014052/0037 →
Continuity (2)
Provisional Application 6040671300 · Aug 28, 2002
Related Publication 20040139206A1 · Jul 15, 2004