IP Library Granted Patent US 12,483,440
Granted Patent B2
US 12,483,440 · App. 18/689,010 · Granted Nov 25, 2025

Methods and systems for network segmentation

Inventors: Suresh Katukam (Milpitas, CA); Promode Nedungadi (San Jose, CA); Shiv Mehra (Saratoga, CA); Steve Alexander (Woodside, CA)
Assignee: NILE GLOBAL, INC.
H04L12/4641H04L12/4633H04L63/029H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,440
App. No.
18/689,010
Granted
Nov 25, 2025
Kind
B2
Abstract

Embodiments of a device and method are disclosed. In an embodiment, a method for network segmentation of a network deployed at a customer site involves establishing a tunnel between a network device of the network deployed at the customer site and a network port of a switch of the network deployed at the customer site, when a wired device is plugged into the network port of the switch, transmitting network traffic between the wired device and the network device through the tunnel, facilitating a security operation regarding the wired device, and based on a result of the security operation, performing a network segmentation operation regarding the wired device.

Claims (28)

1 . A method for network segmentation of a network deployed at a customer site, the method comprising:

establishing a tunnel between a network device of the network deployed at the customer site and a network port of a switch of the network deployed at the customer site when a wired device is plugged into the network port of the switch;

transmitting network traffic between the wired device and the network device through the tunnel to verify the wired device; and

performing a network segmentation operation regarding the wired device once the wired device is verified,

wherein the network device is a head end (HE) device and the switch is an access switch (AS), and the method further comprising implementing an authentication operation regarding the wired device through the tunnel that is established between the HE and the network port of the AS.

2 . The method of claim 1 , wherein the tunnel comprises a Generic Routing Encapsulation (GRE) tunnel.

3 . The method of claim 1 , wherein the tunnel comprises a Virtual Extensible Local Area Network (VXLAN) tunnel.

4 . The method of claim 1 , wherein the tunnel comprises a Network Virtualization using Generic Routing Encapsulation (GRE) tunnel.

5 . The method of claim 1 , wherein the tunnel comprises an IP Security (IP-Sec) tunnel.

6 . The method of claim 1 , wherein the wired device can be plugged into any available port of the switch.

7 . The method of claim 1 , wherein establishing the tunnel between the network device of the network deployed at the customer site and the network port of the switch of the network deployed at the customer site comprises establishing a plurality of port-specific tunnels between the network device and a plurality of network ports of the switch, wherein the port-specific tunnels are separate from each other.

8 . The method of claim 1 , wherein establishing the tunnel between the network device of the network deployed at the customer site and the network port of the switch of the network deployed at the customer site comprises establishing a plurality of tunnels between the network device and a plurality of network ports of the switch, wherein the tunnels are separate from each other.

9 . The method of claim 8 , wherein no tunnel is shared by multiple ports of the switch.

10 . The method of claim 1 , further comprising implementing an authentication operation regarding the wired device through the tunnel that is established between the network device and the network port of the switch.

11 . The method of claim 1 , wherein implementing the authentication operation regarding the wired device comprises accessing authentication server through the tunnel that is established between the HE and the network port of the AS.

12 . A system for network segmentation of a network deployed at a customer site, the system comprising:

memory; and

one or more processors configured to:

establish a tunnel between a network device of the network deployed at the customer site and a network port of a switch of the network deployed at the customer site when a wired device is plugged into the network port of the switch;

transmit network traffic between the wired device and the network device through the tunnel to verify the wired device; and

perform a network segmentation operation regarding the wired device once the wired device is verified,

wherein the network device is a head end (HE) device and the switch is an access switch (AS), and the one or more processors are further configured to implement an authentication operation regarding the wired device through the tunnel that is established between the HE and the network port of the AS.

13 . A method for network segmentation of a network deployed at a customer site, the method comprising:

establishing a plurality of Generic Routing Encapsulation (GRE) tunnels between a gateway device of the network deployed at the customer site and a plurality of network ports of a switch of the network deployed at the customer site;

when a plurality of wired devices are plugged into the network ports of the switch, transmitting network traffic between the wired devices and the gateway device through the GRE tunnels;

facilitating a security operation regarding the wired devices through the gateway device; and

based on a result of the security operation, performing a network segmentation operation regarding the wired devices using the gateway device,

wherein the gateway device is a head end (HE) device and the switch is an access switch (AS), and the method further comprising implementing an authentication operation regarding the wired devices through the tunnels that are established between the HE and the network port of the AS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2024
From: KATUKAM, SURESH; NEDUNGADI, PROMODE; MEHRA, SHIV; ALEXANDER, STEVE
To: NILE GLOBAL, INC.
Reel/Frame 066650/0788 →
Continuity (1)
Related Publication 20250132953A1 · Apr 24, 2025
References Cited (27)
US 8428087B1 · Vincent · 2013 [cited by examiner]
US 10382401B1 · Lee · 2019 [cited by examiner]
US 10609016B2 · Goeringer et al. · 2020 [cited by applicant]
US 11095610B2 · Gilbert et al. · 2021 [cited by applicant]
US 11343226B2 · Goeringer · 2022 [cited by examiner]
US 20090122990A1 · Gundavelli et al. · 2009 [cited by applicant]
US 20160028626A1 · Koganti · 2016 [cited by applicant]
US 20160255456A1 · Lee et al. · 2016 [cited by applicant]
US 20160351043A1 · Tabe · 2016 [cited by applicant]
US 20170034051A1 · Chanda et al. · 2017 [cited by applicant]
US 20170230281A1 · Newell · 2017 [cited by examiner]
US 20200092254A1 · Goeringer · 2020 [cited by examiner]
US 20200162589A1 · Vijayadharan · 2020 [cited by examiner]
US 20200177503A1 · Hooda · 2020 [cited by examiner]
US 20200322274A1 · Copley · 2020 [cited by applicant]
US 20200389469A1 · Litichever et al. · 2020 [cited by applicant]
US 20210176158A1 · Soh et al. · 2021 [cited by applicant]
US 20210367920A1 · Devarajan · 2021 [cited by examiner]
US 20220131898A1 · Hooda · 2022 [cited by examiner]
US 20220182317A1 · Thoria · 2022 [cited by examiner]
US 20220182359A1 · Devaraj · 2022 [cited by examiner]
US 20230421478A1 · Chhabra · 2023 [cited by examiner]
EP 3888307B1 · 2024 [cited by examiner]
PCT/US2022/042235, International Search Report, Jan. 10, 2023, 14 pgs. [cited by applicant]
Non-Final Office Action (U.S. Appl. No. 17/465,767) dated Mar. 9, 2023, 27 pgs. [cited by applicant]
Final Office Action (U.S. Appl. No. 17/465,767) dated Jun. 15, 2023, 17 pgs. [cited by applicant]
Notice of Allowance (U.S. Appl. No. 17/465,767) dated Aug. 28, 2023, 8 pgs. [cited by applicant]