IP Library Granted Patent US 11,588,821
Granted Patent B1
US 11,588,821 · App. 16/818,431 · Granted Feb 21, 2023

Systems and methods for access control list (ACL) filtering

Inventors: Thomas Frederick Detwiler (Huntsville, AL); Cory Z. Zywno (Huntsville, AL); Darrin L. Gieger (Pell City, AL); Spencer R. Gass (Madison, AL); Miriam Angela Nunnally (Madison, AL)
Assignee: ADTRAN, Inc.
H04L63/101G06F16/2282
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,588,821
App. No.
16/818,431
Granted
Feb 21, 2023
Kind
B1
Abstract

A filter for performing access control list (ACL) filtering may be used in place of highly-complex and resource-intensive TCAMs for access control. In this regard, the filter may be configured to compare packet header information to action-priority pairs stored in ACL tables. Each action-priority pair indicates at least one action to be performed for implementing a desired rule and a priority for that action. An access control action from an action-priority pair matching the header information may be performed in order to implement a desired access control rule for the received packet. If multiple action-priority pairs from the same table match the header information, then the priorities of the matching action-priority pairs may be compared to resolve the conflict. The circuitry of the filter is arranged such that exact-match searching can be performed on the ACL tables to reduce the complexity and cost of the filter.

Claims (40)

1. A system for controlling access to a network using access control list (ACL) filtering, comprising:

a memory system for storing ACL tables, each of the ACL tables storing a plurality of action-priority pairs, each of the action-priority pairs indicative of an access control action and a priority associated with the access control action, wherein each of the ACL tables is correlated with a respective bit mask; and

a filter configured to receive and filter a flow of data packets, the flow including a data packet having a plurality of header fields,

the filter configured to determine a filter group identifier based on at least one field of the plurality of header fields,

the filter configured to select a plurality of the ACL tables associated with the filter group identifier for use in processing the data packet,

the filter configured to compress the plurality of header fields into a set of range identifiers and to apply a plurality of bit masks respectively correlated with the selected plurality of ACL tables to the range identifiers thereby generating a plurality of search strings, wherein each search string is for searching a respective one of the selected plurality of ACL tables,

the filter configured to perform exact-match searches on the selected plurality of ACL tables with the plurality of search strings,

the filter further configured to select an action-priority pair from the selected plurality of ACL tables matching a respective one of the plurality of search strings and perform the access control action indicated by the selected action-priority pair, wherein the access control action controls whether the data packet is dropped by the filter or whether header information in the data packet is changed by the filter.

2. The system for controlling access to the network of claim 1 , wherein the filter is further configured to perform comparisons of priorities indicated by action-priority pairs from the selected plurality of ACL tables matching the plurality of search strings.

3. The system for controlling access to the network of claim 2 , further comprising a ternary content-addressable memory (TCAM) configured to receive the plurality of header fields and to provide at least one action-priority pair in response to the plurality of header fields, wherein the filter is configured to compare at least one priority indicated by the at least one action-priority pair to the priorities indicated by the action-priority pairs from the selected plurality of ACL tables matching the plurality of search strings.

4. The system of claim 1 , wherein the access control action is to drop the data packet from the flow.

5. A system for controlling access to a resource using access control list (ACL) filtering, comprising:

a memory system for storing access control list (ACL) tables for a plurality of filter groups, each of the ACL tables having a plurality of action-priority pairs, wherein each of the action-priority pairs indicates a priority and an access control action for processing data packets; and

a filter configured to receive and filter a flow of data packets, the flow including a data packet having a plurality of header fields,

the filter configured to use at least one of the plurality of header fields to determine a filter group identifier,

the filter configured to compress the plurality of header fields into a set of range identifiers,

the filter configured to select a subset of the ACL tables based upon the group identifier,

the filter configured to convert the set of range identifiers into a plurality of search strings for searching the subset of the ACL tables,

the filter configured to search the subset of the ACL tables using the plurality of search strings,

the filter configured to select an action-priority pair from the subset of the ACL tables matching a respective one of the plurality of search strings,

the filter configured to perform an access control action indicated by the selected action-priority pair, wherein the access control action controls whether the data packet is dropped by the filter or whether header information in the data packet is changed by the filter.

6. The system for controlling access to the resource of claim 5 , wherein the filter is further configured to perform comparisons of priorities indicated by action-priority pairs from the subset of the ACL tables matching the plurality of search strings.

7. The system of claim 5 , wherein the access control action is to drop the data packet from the flow.

8. A method for controlling access to a network using access control list (ACL) filtering, comprising:

storing ACL tables in a memory system, each of the ACL tables storing a plurality of action-priority pairs, each of the action-priority pairs indicative of an access control action and a priority associated with the access control action;

correlating each of the ACL tables with a respective bit mask;

receiving, with a filter, a flow of data packets, the flow including a data packet having a plurality of header fields;

filtering, with the filter based on information in header fields of the data packets, the flow of the data packets;

determining, with the filter, a filter group identifier based on at least one of the plurality of header fields;

selecting, with the filter, a subset of the ACL tables associated with the filter group identifier for use in processing the data packet;

compressing, with the filter, the plurality of header fields into a set of range identifiers;

applying, with the filter, a plurality of bit masks respectively correlated with the subset of ACL tables to the range identifiers, thereby generating a plurality of search strings;

performing, with the filter, exact-match searches on the subset of ACL tables with the plurality of search strings;

selecting, with the filter, an action-priority pair from the subset of ACL tables matching a respective one of the plurality of search strings; and

performing the access control action indicated by the selected action-priority pair, wherein the access control action controls whether the data packet is dropped by the filter or whether header information in the data packet is changed by the filter.

9. The method of claim 8 , further comprising performing, with the filter, comparisons of priorities indicated by action-priority pairs from the subset of ACL tables matching the plurality of search strings.

10. The method of claim 9 , further comprising:

receiving the plurality of header fields at a ternary content-addressable memory (TCAM); providing at least one action-priority pair with the TCAM in response to the plurality of header fields; and

comparing, with the filter, at least one priority indicated by the at least one action-priority pair to the priorities indicated by the action-priority pairs from the subset of ACL tables matching the plurality of search strings.

11. The method of claim 8 , wherein the access control action is to drop the data packet from the flow.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2020
From: DETWILER, THOMAS FREDERICK; GASS, SPENCER R.; ZYWNO, CORY Z.; NUNNALLY, MIRIAM ANGELA; GIEGER, DARRIN L.
To: ADTRAN, INC.
Reel/Frame 052110/0603 →
Cited By (2)
US 12,294,636 US 12,432,208