IP Library › Granted Patent US 12,041,033
Granted Patent B2
US 12,041,033 · App. 17/748,205 · Granted Jul 16, 2024

Authorization and audit control in a multi-protocol IoT domain

Inventors: Jagadish Chundury (Chennai, IN); Venkat R (Bangalore, IN); Jaswanth D K (Mysore, IN)
Assignee: Cisco Technology, Inc.
H04L63/0236H04L41/0226
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,041,033
App. No.
17/748,205
Filed
May 19, 2022
Granted
Jul 16, 2024
Kind
B2
Art Unit
2496
USPC
726/12
Abstract

In one embodiment, an authorizing device (e.g., a gateway) receives a native protocol request packet from a requesting device destined to a serving device, and translates the native protocol request packet into an authorization protocol mapping. The authorizing device may then apply authorization protocol based authorization (e.g., OT protocol independent) to the native protocol request packet based on the authorization protocol mapping, and transmits the native protocol request packet toward the serving device in response to the authorization protocol mapping being authorized. In one embodiment, the techniques herein may also perform an audit in this manner.

Claims (39)

1. A method, comprising:

receiving, at an authorizing device, a native protocol request packet from a requesting device destined to a serving device;

translating, by the authorizing device, the native protocol request packet into an authorization protocol mapping;

applying, by the authorizing device, authorization protocol based authorization to the native protocol request packet based on the authorization protocol mapping; and

transmitting, by the authorizing device, the native protocol request packet toward the serving device in response to the authorization protocol mapping being authorized.

2. The method as in claim 1 , further comprising:

dropping the native protocol request packet in response to the authorization protocol mapping being unauthorized.

3. The method as in claim 1 , wherein the native protocol request packet comprises an operational technology packet from an operational technology device manager.

4. The method as in claim 1 , wherein the authorization protocol mapping is based on a simple network management protocol.

5. The method as in claim 1 , further comprising:

receiving updates to apply to the authorization protocol based authorization from a network manager.

6. The method as in claim 1 , wherein the authorization protocol mapping is based on one or more of: a function code; a data address; one or more audit attributes; and a service device identifier.

7. The method as in claim 1 , wherein the authorization protocol based authorization is based on native protocol management information being mapped into an authorization protocol management information base.

8. The method as in claim 7 , wherein there is a respective authorization protocol management information base for each native protocol of a plurality of native protocols.

9. The method as in claim 1 , wherein the authorization protocol based authorization corresponds to an audit.

10. The method as in claim 1 , wherein the native protocol request packet is selected from a group consisting of: a Modbus request packet; a distributed network protocol version 3 request packet; and a simple network management protocol packet.

11. The method as in claim 1 , wherein the authorizing device is an Internet of Things gateway.

12. The method as in claim 1 , further comprising:

performing native protocol authentication on the native protocol request packet prior to applying authorization protocol based authorization to the native protocol request packet.

13. A tangible, non-transitory, computer-readable medium having computer-executable instructions stored thereon that, when executed by a processor on a computer, cause the computer to perform a method comprising:

receiving a native protocol request packet from a requesting device destined to a serving device;

translating the native protocol request packet into an authorization protocol mapping;

applying authorization protocol based authorization to the native protocol request packet based on the authorization protocol mapping; and

transmitting the native protocol request packet toward the serving device in response to the authorization protocol mapping being authorized.

14. The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the method further comprises:

dropping the native protocol request packet in response to the authorization protocol mapping being unauthorized.

15. The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the native protocol request packet comprises an operational technology packet from an operational technology device manager.

16. The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the authorization protocol mapping is based on a simple network management protocol.

17. The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the method further comprises:

receiving updates to apply to the authorization protocol based authorization from a network manager.

18. The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the authorization protocol mapping is based on one or more of: a function code; a data address; one or more audit attributes; and a service device identifier.

19. The tangible, non-transitory, computer-readable medium as in claim 13 , wherein the authorization protocol based authorization is based on native protocol management information being mapped into an authorization protocol management information base.

20. An apparatus, comprising:

a processor configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process, when executed, configured to:

receive a native protocol request packet from a requesting device destined to a serving device;

translate the native protocol request packet into an authorization protocol mapping;

apply authorization protocol based authorization to the native protocol request packet based on the authorization protocol mapping; and

transmit the native protocol request packet toward the serving device in response to the authorization protocol mapping being authorized.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2022
From: CHUNDURY, JAGADISH; R, VENKAT; D K, JASWANTH
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059956/0528 →
Continuity (1)
Related Publication 20230379300A1 · Nov 23, 2023