IP Library › Granted Patent US 12,206,584
Granted Patent B1
US 12,206,584 · App. 17/534,966 · Granted Jan 21, 2025

Method and system for filtering data packets to prevent crosstalk

Inventors: Neale Ranns (Hure, FR); IJsbrand Wijnands (Leuven, BE); Stefan Olofsson (Dubai, AE)
Assignee: GRAPHIANT, INC.
H04L47/17H04L47/11H04L47/825H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,584
App. No.
17/534,966
Granted
Jan 21, 2025
Kind
B1
Abstract

Embodiments of a secure communication network are disclosed. To implement the embodiments, an ingress core node that includes a processor and a memory storing computer-executable instructions, is presented. The instructions, when executed, cause the processor to receive a data packet. The instructions further cause the processor to compare a slice identifier (ID) associated with the received data packet with one or more slice IDs in an access control list (ACL). The instructions further cause the processor to filter the received data packet based on the comparison indicating an occurrence of a match between the slice ID associated with the data packet and one of the one or more slice IDs in the ACL. The instructions further cause the processor to transmit the filtered data packet to an egress core node of the core network via one or more intermediate core nodes of the core network.

Claims (40)

1. An ingress core node of a core network, the ingress core node comprising:

a processor; and

a memory storing computer-executable instructions that when executed, cause the processor to:

compare a slice identifier (ID) associated with a data packet with one or more slice IDs in an access control list (ACL), wherein the ACL includes an indication that one or more of the one or more slice IDs in the ACL are compromised; and

filter the data packet based on the comparison indicating an occurrence of a match between the slice ID associated with the data packet and one of the one or more slice IDs in the ACL.

2. The ingress core node of claim 1 , wherein the computer-executable instructions further cause the processor to transmit the filtered data packet to an egress core node of the core network.

3. The ingress core node of claim 1 , wherein the computer-executable instructions further cause the processor to receive the data packet from an ingress customer premises equipment (CPE).

4. The ingress core node of claim 2 , wherein the data packet is receivable by the egress core node and further wherein, the egress core node is configured to:

compare another slice ID associated with the received data packet with the one or more slice IDs in the ACL;

filter the received data packet based on the comparison indicating an occurrence of a match between the another slice ID associated with the received data packet and one of the one or more slice IDs in the ACL; and

transmit the filtered data packet to an egress customer premises equipment (CPE).

5. The ingress core node of claim 4 , wherein the egress core node is further configured to discard the received data packet based on the comparison indicating a mismatch between the another slice ID and the one or more slice IDs in the ACL.

6. The ingress core node of claim 2 , wherein the computer-executable instructions further cause the processor to receive another data packet from the egress core node, wherein the egress core node is configured to:

receive the another data packet from another ingress customer premises equipment (CPE);

compare another slice ID associated with the received another data packet to one or more other slice IDs in another ACL; and

filter the received another data packet based on the comparison indicating an occurrence of a match between the another slice ID and one of the one or more other slice IDs.

7. The ingress core node of claim 6 , wherein the computer-executable instructions further cause the processor to transmit the received another data packet to another egress CPE.

8. The ingress core node of claim 6 , wherein the egress core node is further configured to discard the received another data packet based on the comparison indicating a mismatch between the another slice ID and the one or more other slice IDs in the another ACL.

9. A method for secure communication of data packets, the method comprising:

comparing, by an ingress core node of a core network, a slice identifier (ID) associated with a data packet of the data packets with one or more slice IDs in an access control list (ACL), wherein the ACL includes an indication that one or more of the one or more slice IDs in the ACL are compromised; and

filtering, by the ingress core node, the data packet based on the comparison indicating an occurrence of a match between the slice ID associated with the data packet and one of the one or more slice IDs in the ACL.

10. The method of claim 9 , further comprising:

transmitting, by the ingress core node, the filtered data packet to an egress core node of the core network.

11. The method of claim 9 , further comprising:

receiving, by the ingress core node, the data packet from an ingress customer premises equipment (CPE).

12. The method of claim 10 , further comprising:

receiving, by the egress core node, the data packet;

comparing, by the egress core node, another slice ID associated with the received data packet with the one or more slice IDs in the ACL;

filtering, by the egress core node, the received data packet based on the comparison indicating an occurrence of a match between the another slice ID associated with the received data packet and one of the one or more slice IDs in the ACL; and

transmitting, by the egress core node, the filtered data packet to an egress customer premises equipment (CPE).

13. The method of claim 12 , further comprising discarding, by the egress core node, the received data packet based on the comparison indicating a mismatch between the another slice ID and the one or more slice IDs in the ACL.

14. The method of claim 11 , further comprising:

receiving, by the egress core node, another data packet of the data packets from another ingress CPE;

comparing, by the egress core node, another slice ID associated with the received another data packet to one or more other slice IDs in another ACL; and

filtering, by the egress core node, the received another data packet based on the comparison indicating an occurrence of match between the another slice ID and one of the one or more other slice IDs.

15. The method of claim 14 , further comprising:

receiving, by the ingress core node, the another data packet from the egress core node; and

transmitting, by the ingress core node, the received another data packet to another egress CPE.

16. The method of claim 14 , further comprising:

discarding, by the egress core node, the received another data packet based on the comparison indicating a mismatch between the another slice ID and the one or more other slice IDs in the another ACL.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2021
From: RANNS, NEALE; WIJNANDS, IJSBRAND; OLOFSSON, STEFAN
To: GRAPHIANT, INC.
Reel/Frame 058232/0084 →
References Cited (8)
US 20060117058A1 · Smith · 2006 [cited by examiner]
US 20100325701A1 · Sun · 2010 [cited by examiner]
US 20170237656A1 · Gage · 2017 [cited by examiner]
US 20170366616A1 · Rodrigues Nascimento · 2017 [cited by examiner]
US 20180102970A1 · Pan · 2018 [cited by examiner]
US 20200213154A1 · Han · 2020 [cited by examiner]
US 20220107802A1 · Rao · 2022 [cited by examiner]
Uriarte et al., “Expressive Policy-Based Access Control for Resource-Constrained Devices”, Mar. 2, 2018, IEEE, IEEE Access (vol. 6, 2018, pp. 15-46) (Year: 2018). [cited by examiner]