Systems and methods for secure network communication

US10476910B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10476910-B2
Application numberUS-201715629396-A
CountryUS
Kind codeB2
Filing dateJun 21, 2017
Priority dateJun 21, 2017
Publication dateNov 12, 2019
Grant dateNov 12, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system for secure network communications is provided. The system includes an enforcement switch in communication with a third-party device and an external device and a plurality of core devices in communication with the third-party device and a plurality of access devices. The enforcement switch is configured to receive a secure frame from the external device. The secure frame includes one or more security features. The secure frame is destined for one or more of the plurality of access devices. The enforcement switch is also configured to generate a regular frame based on the secure frame by removing the one or more security features and transmit the regular frame to the third-party device for routing to the one or more of the plurality of access devices through at least one of the plurality of core devices.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for secure and efficient network communications within a wide area network (WAN) comprising: an enforcement switch in communication with a third-party device and a WAN router, the WAN router in communication with an external device, wherein the external device is located remotely from the enforcement switch and is external to the WAN and wherein the third-party device is a WAN optimizer and is unable to process secure frames; and a plurality of core devices in communication with the third-party device and a plurality of access devices, wherein each access device of the plurality of access devices is configured to receive the secure frames and deliver the secure frames to end users using the plurality of access devices, wherein the enforcement switch is configured to: receive a secure frame from the external device via the WAN router, wherein the secure frame includes one or more security features and wherein the secure frame is destined for one or more of the plurality of access devices; generate a regular frame based on the secure frame in response to determining that the secure frame complies with a security policy, wherein the regular frame is generated by removing the one or more security features; and transmit the regular frame to the third-party device, wherein the third-party device is configured to: (i) determine optimal routing of the regular frame to the one or more of the plurality of access devices by identifying one or more core devices of the at least one of the plurality of core devices and (ii) transmit the regular frame to the identified one or more core devices of the at least one of the plurality of core devices. 2. A system in accordance with claim 1 , wherein each core device of the plurality of core devices is configured to: receive the regular frame from the third-party device; generate a re-secured frame based on the regular frame, wherein the re-secured frame is generated by adding the one or more security features; and transmit the re-secured frame to the one or more of the plurality of access devices. 3. A system in accordance with claim 2 , wherein each core device stores a security policy, and wherein the core device is configured to: determine the one or more security features for the re-secured frame based on the security policy; and generate the re-secured frame based on the regular frame and the one or more security features. 4. A system in accordance with claim 2 , wherein the core device is further configured to route the re-secured frame to the one or more of the plurality of access devices through one or more distribution devices. 5. A system in accordance with claim 1 , wherein the enforcement switch stores the security policy, and wherein the enforcement switch is programmed to: if the determination is that the secure frame complies with the security policy, decode and transmit the secure frame; and if the determination is that the secure frame does not comply with the security policy, drop the secure frame and prevent further transmission of the secure frame. 6. A system in accordance with claim 1 , wherein the plurality of core devices and the plurality of access devices form a wide area network (WAN) network. 7. An enforcement switch in communication with a third-party device and a wide area network (WAN) router for assuring secure and efficient network communications within a wide area network, wherein the WAN router in communication with an external device that is located in a remote location from the enforcement switch and is external to the WAN and wherein the third-party device is a WAN optimizer and is unable to process secure frames, and wherein the enforcement switch is configured to: receive a secure frame from the external device via the WAN router, wherein the secure frame includes one or more security features and wherein the secure frame is destined for one or more of a plurality of access devices; determine whether the secure frame complies with a security policy; if the determination is that the secure frame complies, decode and transmit the secure frame; and if the determination is that the secure frame does not comply, drop the secure frame and prevent further transmission of the secure frame; if the determination is that the secure frame complies, enforcement switch is configured to: generate a regular frame based on the secure frame, wherein the regular frame is generated by removing the one or more security features; and transmit the regular frame to the third-party device, wherein the third-party device is configured to determine optimal routing of the regular frame to the one or more of the plurality of access devices by identifying one or more core devices and transmitting the regular frame to the identified one or more core devices. 8. A computer implemented method for secure and efficient network communications within a wide area network (WAN), said method implemented on an enforcement switch in communication with a third-party device and a WAN router, the WAN router in communication with an external device, wherein the external device is located remotely from the enforcement switch and is external to the WAN and wherein the third-party device is a WAN optimizer and is unable to process secure frames, said method comprising: receiving a secure frame from the external device via the WAN router, wherein the secure frame includes one or more security features and wherein the secure frame is destined for one or more of a plurality of access devices, wherein each access device of the plurality of access devices is configured to receive the secure frames and deliver the secure frames to end users of the plurality of access devices; generating, by the enforcement switch, a regular frame based on the secure frame in response to determining that the secure frame complies with a security policy, wherein the regular frame is generated by removing the one or more security features; and transmitting, by the enforcement switch, the regular frame to the third-party device, wherein the third- party device is configured to: (i) determine optimal routing of the regular frame to the one or more of the plurality of access devices by identifying one or more core devices of at least one of a plurality of core devices and (ii) transmit the regular frame to the identified one or more core devices of the at least one of a plurality of core devices. 9. A method in accordance with claim 8 further comprising: receiving the regular frame from the third-party device; generating a re-secured frame based on the regular frame, wherein the re-secured frame is generated by adding the one or more security features; and transmitting the re-secured frame to the one or more of the plurality of access devices. 10. A method in accordance with claim 9 further comprising: determining the one or more security features for the re-secured frame based on a security policy; and generating the re-secured frame based on the regular frame and the one or more security features. 11. A method in accordance with claim 8 , wherein the enforcement switch stores the security policy, and wherein determining that the secure frame complies with the security policy further comprises: if the determination is that the secure frame complies with the security policy, decoding and transmitting the secure frame; and if the determination is that the secure frame does not comply with the security policy, dropping the secure frame and prevent further transmission of the secure frame, and the method further comprising routing the secure frame to the one or more of the plurality of access devices through the one or more core devices of

Assignees

Inventors

Classifications

  • Interconnection of networks using encapsulation techniques, e.g. tunneling · CPC title

  • Applying verification of the received information (cryptographic mechanisms or cryptographic arrangements for data integrity or data verification H04L9/32) · CPC title

  • Grouping of entities · CPC title

  • for separating internal from external traffic, e.g. firewalls · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10476910B2 cover?
A system for secure network communications is provided. The system includes an enforcement switch in communication with a third-party device and an external device and a plurality of core devices in communication with the third-party device and a plurality of access devices. The enforcement switch is configured to receive a secure frame from the external device. The secure frame includes one or…
Who is the assignee on this patent?
Mastercard International Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 12 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).