Systems and methods for segmenting networks using user defined networks
Systems and methods for creating user defined network in a network environment is provided. Users are able to create user defined networks which as private logical groups that extend across different wired and wireless networking constructs. A user may use an endpoint (e.g., mobile phone) to create a user defined network, to associate one or more endpoints with the user defined network, and to invite other users to add their endpoints to the user defined network. The user may create a policy for endpoints in the user defined network such as only allowing endpoints associated with the user defined network or restricting types of traffic that can be communicated to endpoints in the user defined network. The user defined network, and associated policies, may be enforced by the infrastructure devices in the network environment.
1 . A method comprising:
receiving a request to create a user defined network by a computing device from an endpoint associated with a first user;
in response to the request, assigning a user defined network identifier to the user defined network by the computing device;
adding the endpoint as a member of the user defined network by the computing device by storing a unique device identifier of the endpoint with the user defined network identifier;
providing the user defined network to an authentication server, comprising providing, to the authentication server, a first owner flag indicating that the endpoint is associated with the first user and that the first user controls the user defined network;
in response to receiving an authentication request from the endpoint including the unique device identifier:
determining that the endpoint belongs to the user defined network based on the unique device identifier; and
causing a policy of the user defined network to be applied to the endpoint;
receiving, from the endpoint, a request to add a second user to the user defined network, wherein the request specifies an account of the second user;
transmitting, to the account of the second user, an invitation to join the user defined network, wherein the invitation indicates the policy of the user defined network;
receiving, from the second user, a second unique device identifier of a second endpoint associated with the second user; and
in response to receiving a second authentication request from the second endpoint including the second unique device identifier:
determining that the second endpoint belongs to the user defined network based on the second unique device identifier, comprising receiving, from the authentication server, a second owner flag indicating that the second endpoint is not associated with the first user that controls the user defined network; and
causing the policy of the user defined network to be applied to the second endpoint, wherein the policy comprises disallowing the second endpoint from exchanging unicast traffic with other endpoints in the user defined network.
2 . The method of claim 1 , further comprising selecting the policy for the user defined network by the computing device.
3 . The method of claim 2 , wherein the policy comprises only allowing network traffic between members of the user defined network.
4 . The method of claim 3 , wherein the network traffic comprises multicast and broadcast traffic.
5 . The method of claim 1 , where the authentication server is a RADIUS server.
6 . The method of claim 1 , wherein the user defined network identifier is not transferred between the endpoint and one or more network infrastructure devices.
7 . The method of claim 1 , wherein providing the user defined network to the authentication server comprises providing the user defined network identifier and a user defined network name.
8 . The method of claim 1 , wherein providing the authentication server comprises providing the user defined network identifier as part of an authorization profile.
9 . The method of claim 1 , further comprising:
determining that the invitation was accepted; and
in response to the determination, generating and sending a change of authorization for the authentication server, wherein the change of authorization identifies the one or more endpoints associated with the second user.
10 . A method comprising:
creating a user defined network for a first user by a computing device;
adding an endpoint associated with the first user as a member of the user defined network by the computing device by storing a unique device identifier of the endpoint with a user defined network identifier for the user defined network;
providing the user defined network to an authentication server, comprising providing, to the authentication server, a first owner flag indicating that the endpoint is associated with the first user and that the first user controls the user defined network;
receiving a request to add a second user to the user defined network from the first user by the computing device;
in response to the request, generating and sending an invitation to the second user by the computing device;
determining that the invitation was accepted by the computing device;
in response to the determination, generating and sending a change of authorization for the user defined network to the authentication server by the computing device, wherein the change of authorization identifies one or more endpoints associated with the second user;
in response to receiving an authentication request from the endpoint including the unique device identifier:
determining that the endpoint belongs to the user defined network based on the unique device identifier; and
causing a policy of the user defined network to be applied to the endpoint;
receiving, from the endpoint, a request to add a second user to the user defined network, wherein the request specifies an account of the second user;
transmitting, to the account of the second user, an invitation to join the user defined network, wherein the invitation indicates the policy of the user defined network;
receiving, from the second user, a second unique device identifier of a second endpoint associated with the second user; and
in response to receiving a second authentication request from the second endpoint including the second unique device identifier:
determining that the second endpoint belongs to the user defined network based on the second unique device identifier, comprising receiving, from the authentication server, a second owner flag indicating that the second endpoint is not associated with the first user that controls the user defined network; and
causing the policy of the user defined network to be applied to the second endpoint, wherein the policy comprises disallowing the second endpoint from exchanging unicast traffic with other endpoints in the user defined network.
11 . The method of claim 10 , where the authentication server is a RADIUS server.
12 . The method of claim 10 , wherein the user defined network identifier is not transferred between the endpoint and one or more network infrastructure devices.
13 . The method of claim 10 , further comprising only allowing network traffic between the first user and the second user in the user defined network.
14 . The method of claim 13 , wherein the network traffic comprises multicast and broadcast traffic.
15 . The method of claim 10 , wherein providing the user defined network to the authentication server comprises providing the user defined network identifier and a user defined network name.
16 . The method of claim 10 , wherein providing the user defined network to the authentication server comprises providing the user defined network identifier as part of an authorization profile.
17 . A system comprising:
an endpoint associated with a first user;
a plurality of network infrastructure devices associated with a network; and
an authentication server, wherein the authentication server is adapted to:
receive a request to authenticate the endpoint;
in response to the request, authenticate the endpoint;
determine that the endpoint is associated with a user defined network based on determining that a unique device identifier of the endpoint is associated with a user defined network identifier of the user defined network;
in response to the determination, provide a user defined network identifier to one or more of the plurality of network infrastructure devices for enforcement by the one or more of the plurality of network infrastructure devices, comprising providing a first owner flag indicating that the endpoint is associated with the first user and that the first user controls the user defined network, wherein the one or more of the plurality of network infrastructure devices cause a policy of the user defined network to be applied to the endpoint;
receive, from the endpoint, a request to add a new user to the user defined network, wherein the request specifies an account of the new user;
transmit, to the account of the new user, an invitation to join the user defined network, wherein the invitation indicates the policy of the user defined network;
receive, from the new user, a second unique device identifier of a second endpoint associated with the new user; and
in response to receiving a second authentication request from the second endpoint including the second unique device identifier:
determine that the second endpoint belongs to the user defined network based on the second unique device identifier; and
provide the user defined network identifier to one or more of the plurality of network infrastructure devices for enforcement by the one or more of the plurality of network infrastructure devices, comprising providing a second owner flag indicating that the second endpoint is not associated with the first user that controls the user defined network, wherein the one or more of the plurality of network infrastructure devices cause the policy of the user defined network to be applied to the second endpoint, wherein the policy comprises disallowing the second endpoint from exchanging unicast traffic with other endpoints in the user defined network.
18 . The system of claim 17 , where the authentication server is a RADIUS server.
19 . The system of claim 17 , wherein the authentication server adapted to provide the user defined network identifier to one or more of the plurality of network infrastructure devices comprises wherein the authentication server adapted to provide the user defined network identifier as part of an authorization profile for the first user.
20 . The system of claim 18 , wherein the plurality of network infrastructure devices are adapted to only allow the endpoint to communicate with other endpoints that are also associated with the user defined network.