Systems and methods for providing software defined network based dynamic access control in a cloud

US10425419B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10425419-B2
Application numberUS-201615215860-A
CountryUS
Kind codeB2
Filing dateJul 21, 2016
Priority dateJul 21, 2016
Publication dateSep 24, 2019
Grant dateSep 24, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system for providing access control in a cloud includes a software defined network including a software defined network controller. The system is configured to authenticate user access using multi-factor authentication. If the user is authorized to access a cloud resource the software defined network controller sends instructions to insert layer 3 and 4 user-specific flows to a software defined network device connected to the cloud resource. The user-specific flows cause the software defined network device to grant access to the cloud resource to the user.

First claim

Opening claim text (preview).

What is claimed: 1. A method comprising: receiving in an authentication, authorization, and accounting server a request from a user to access a cloud resource; receiving user authentication information in the authentication, authorization, and accounting server; comparing the user authentication information to a profile stored in a policy server to determine if the user is authorized to access the cloud resource; when the user is authorized to access the cloud resource, initiating a user session using a software defined network flow injection; assigning a source layer 3 IP address to the user from a preconfigured IP address pool; assigning an allowed layer 4 protocol or port; inserting a user specific flow with an IP address flow rule with the source layer 3 IP address and destination IP address of the cloud resource and a layer 4 flow rule that restricts access to only the allowed layer 4 protocol or port; granting the user access to the cloud resource; when the user session is terminated, sending an indication to the software defined network controller that the user session has been terminated; and removing the user specific flow with the software defined network controller to deny the user further access to the cloud resource. 2. The method of claim 1 wherein the software defined network device comprises a virtual router. 3. The method of claim 1 wherein the request from the user is provided by a front end access device. 4. The method of claim 2 wherein the virtual router is SDN enabled. 5. The method of claim 1 wherein the software defined network device is configured to deny access to the cloud resource unless there is a user-specific flow granting access to the user. 6. The method of claim 1 wherein the software defined network device is a ToR switch. 7. A system for controlling access to a cloud resource comprising: an authentication, authorization, and accounting server disposed in a software defined network; at least one subsystem that: receives a request in an authentication, authorization, and accounting server for access to the cloud resources from a user; receives user authentication information in the authentication, authorization, and accounting server; compares the user authentication information to a profile stored in a policy server to determine if the user is authorized to access the cloud resource; when the user is is authorized to access the cloud resource, initiates a user session using a software defined network flow injection; assigns a source layer 3 IP address to the user from a preconfigured IP address pool; assigns an allowed layer 4 protocol or port; inserts a user specific flow with an IP address flow rule with the source layer 3 IP address and destination IP address of the cloud resource and a layer 4 flow rule that restricts access to only the allowed layer 4 protocol or port; grants the user access to the cloud resource; when the user session is terminated, sends an indication to the software defined network controller that the user session has been terminated; and removes the user specific flow with the software defined network controller to deny the user further access to the cloud resource. 8. The system of claim 7 wherein the software defined network device comprises a virtual router. 9. The system of claim 7 wherein the at least one subsystem that receives a request for access comprises a subsystem that receives a request for access form a front end access device. 10. The system of claim 8 wherein the virtual router is SDN enabled. 11. The system of claim 7 wherein the software defined network device is configured to deny access to the cloud resources unless there is a user-specific flow granting access to the user. 12. The system of claim 7 wherein the software defined network device is a ToR switch.

Assignees

Inventors

Classifications

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • applying multi-factor authentication · CPC title

  • by using authentication-authorization-accounting [AAA] servers or protocols · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10425419B2 cover?
A system for providing access control in a cloud includes a software defined network including a software defined network controller. The system is configured to authenticate user access using multi-factor authentication. If the user is authorized to access a cloud resource the software defined network controller sends instructions to insert layer 3 and 4 user-specific flows to a software defin…
Who is the assignee on this patent?
At & T Ip I Lp
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 24 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 11 related publications on this page (citations in our corpus or others sharing the same primary CPC).