IP Library Granted Patent US 11,252,196
Granted Patent B2
US 11,252,196 · App. 17/082,045 · Granted Feb 15, 2022

Method for managing data traffic within a network

Inventors: Ghassan Karame (Heidelberg, DE); Felix Klaedtke (Heidelberg, DE); Takayuki Sasaki (Tokyo, JP)
Assignee: NEC CORPORATION
H04L63/20H04L41/0816H04L41/0893H04L63/0263H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,252,196
App. No.
17/082,045
Granted
Feb 15, 2022
Kind
B2
Abstract

A reference monitor (RM) operates within a network having controllers that each control a corresponding network part having a forwarding element (FE) for forwarding data within the network. The RM enforces the security policy for a first network part managed by a first controller. The method includes: receiving a first rule request from the first controller, checking the first rule request for policy compliance, authorizing a part of the first rule request that is policy compliant, receiving a second rule request, the second rule request being from a second controller configured to control a second part of the network, the second rule request comprising an outside modification impacting the first network part, which is not managed by the second controller, checking the outside modification part for policy compliance, and based on determining that the outside modification part is policy compliant, authorizing the outside modification part of the second rule request.

Claims (38)

1. A method for operating a reference monitor (RM) within a network, the network comprising a plurality of controllers, each of the controllers being configured to control a corresponding part of the network comprising at least one forwarding element (FE) for forwarding data within the network, and wherein each of the controllers is connected to at least one of a plurality of reference monitors for enforcing a security policy for the network part managed by the corresponding one of the controllers, the reference monitors comprising the RM, the RM configured to enforce the security policy for a first network part managed by a first controller, the method comprising:

a) receiving a first rule request from the first controller,

b) checking the first rule request for policy compliance,

c) authorizing a part of the first rule request that is policy compliant,

d) receiving a second rule request, the second rule request being from a second controller of the controllers, the second controller being configured to control a second part of the network, the second rule request comprising an outside modification, the outside modification impacting at least the first network part, which is not managed by the second controller,

e) checking the outside modification part of the second rule request for policy compliance, and

f) based on determining that the outside modification part is policy compliant, authorizing the outside modification part of the second rule request.

2. The method according to claim 1 , wherein the RM is running isolated from the controllers.

3. The method according to claim 1 , wherein the network parts are network slices, the first network part being a first network slice, and the second network part being a second network slice.

4. The method according to claim 1 , the operation of checking the first rule request for policy compliance comprises:

determining whether the rule request comprises modifications impacting parts of the network outside of the first network part; and

based upon determining the rule request comprises modifications impacting parts of the network outside of the first network part, sending a notification that the RM cannot decide compliance of the modifications impacting parts of the network outside of the first network.

5. The method according to claim 1 , the method further comprising:

receiving a general binary contract tree for the first controller to contact the one or more controllers; and

checking the general binary tree for correctness.

6. The method according to claim 1 , wherein the authorization of the part of the first rule request is provided using a Boneh-Lynn-Shacham (BLS) signature.

7. The method according to claim 1 , wherein the authorization of the outside modification part of the second rule request is provided using a Boneh-Lynn-Shacham (BLS) signature.

8. The method according to claim 7 , wherein the compliant outside modification part of the second rule request is denoted by M, and wherein authorizing the compliant outside modification part of the second rule request comprises sending a BLS signature comprising M, a time stamp, and RM's private BLS key.

9. The method according to claim 1 , wherein the authorization is only valid for a predefined period of time.

10. The method of claim 1 ,

wherein the FE operates in a data plane of the network,

wherein the RM and the controller operate in a control plane of the network,

wherein a rule request comprises at least one of a request for installing, modifying, or deleting a data flow rule in the FE.

11. The method of claim 10 , wherein the network is a software defined network, and the FE is a software defined network switch.

12. A non-transitory computer-readable medium storing a program causing a computer to execute a method for operating a reference monitor (RM) within a network, the network comprising a plurality of controllers, each of the controllers being configured to control a corresponding part of the network comprising at least one forwarding element (FE) for forwarding data within the network, and wherein each of the controllers is connected to at least one of a plurality of reference monitors for enforcing a security policy for the network part managed by the corresponding one of the controllers, the reference monitors comprising the RM, the RM configured to enforce the security policy for a first network part managed by a first controller, the method comprising:

a) receiving a first rule request from the first controller,

b) checking the first rule request for policy compliance,

c) authorizing a part of the first rule request that is policy compliant,

d) receiving a second rule request, the second rule request being from a second controller of the controllers, the second controller being configured to control a second part of the network, the second rule request comprising an outside modification, the outside modification impacting at least the first network part, which is not managed by the second controller,

e) checking the outside modification part of the second rule request for policy compliance, and

f) based on determining that the outside modification part is policy compliant, authorizing the outside modification part of the second rule request.

13. A reference monitor (RM) for operating within a network, the network comprising a plurality of controllers, each of the controllers being configured to control a corresponding part of the network comprising at least one forwarding element (FE) for forwarding data within the network, and wherein each of the controllers is connected to at least one of a plurality of reference monitors for enforcing a security policy for the network part managed by the corresponding one of the controllers, the reference monitors comprising the RM, the RM configured to enforce the security policy for a first network part managed by a first controller, the reference monitor being configured to perform a method comprising:

a) receiving a first rule request from the first controller,

b) checking the first rule request for policy compliance,

c) authorizing a part of the first rule request that is policy compliant,

d) receiving a second rule request, the second rule request being from a second controller of the controllers, the second controller being configured to control a second part of the network, the second rule request comprising an outside modification, the outside modification impacting at least the first network part, which is not managed by the second controller,

e) checking the outside modification part of the second rule request for policy compliance, and

f) based on determining that the outside modification part is policy compliant, authorizing the outside modification part of the second rule request.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2026
From: NEC CORPORATION
To: NEC ASIA PACIFIC PTE LTD.
Reel/Frame 074916/0414 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2026
From: NEC ASIA PACIFIC PTE LTD.
To: CBS INTERACTIVE INC.
Reel/Frame 074916/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2026
From: NEC CORPORATION
To: NEC ASIA PACIFIC PTE LTD.
Reel/Frame 074814/0461 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2021
From: NEC LABORATORIES EUROPE GMBH
To: NEC CORPORATION
Reel/Frame 057665/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2020
From: KARAME, GHASSAN; KLAEDTKE, FELIX; SASAKI, TAKAYUKI
To: NEC LABORATORIES EUROPE GMBH
Reel/Frame 054188/0216 →
Continuity (2)
Continuation 16343006
Related Publication 20210058432A1 · Feb 25, 2021