Systems, methods, and storage media for detecting a security intrusion of a network device

US11228404B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11228404-B2
Application numberUS-201916582943-A
CountryUS
Kind codeB2
Filing dateSep 25, 2019
Priority dateSep 28, 2018
Publication dateJan 18, 2022
Grant dateJan 18, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems, methods, and storage media for detecting a security intrusion of a network device are disclosed. Exemplary implementations may include a method involving, in the network device including a processor, monitor a light signal associated with a security enabled port of the network device; and in response to detecting a change in the light signal, initiate a security alert.

First claim

Opening claim text (preview).

What is claimed is: 1. A network security device comprising: a plurality of bi-directional communication ports each comprising an output port and a corresponding input port; a loopback connector to redirect a light signal from an output port of at least one of the plurality of bi-directional communication ports to a corresponding input port of the at least one of the plurality of bi-directional communication ports; a controller configuring the at least one of the plurality of bi-directional communication ports as a security enabled port, the controller transmitting, to a security monitoring system, an alarm indication in response to detecting a loss of the redirected light signal on the security enabled ports; and a switch device associated with the at least one of the plurality of bi-directional communication ports and transmitting, to the controller, an insertion signal upon a change of state of the switch device in response to an insertion of a cable into the at least one of the plurality of bi-directional communication ports, wherein transmission of the alarm indication is further in response to receiving, at the controller, the insertion signal from the switch device associated with the security enabled port. 2. The network security device of claim 1 wherein the network device further comprises a photodetector associated with the at least one of the plurality of bi-directional communication ports and transmitting, to the controller, an indicator signal corresponding to a detection of the light signal on the input port. 3. The network security device of claim 2 wherein the photodetector detects a removal of the loopback connector and transmits, in response to the removal of the loopback connector, a loss of signal indicator to the controller. 4. The network security device of claim 1 wherein the network device is a reconfigurable optical add drop multiplexor (ROADM) and the photodetector is a photodiode. 5. The network security device of claim 4 wherein the plurality of bi-directional communication ports are operably associated with a wavelength selectable switch component of the ROADM. 6. The network security device of claim 2 , the network device further comprising: a common signal bi-directional port comprise a common signal port receiving a common light signal; and a demultiplexer replicating the common light signal to the output port of each of the plurality of bi-directional communication ports. 7. The network security device of claim 6 , the network device further comprising a light-detecting sensor associated with the common signal bi-directional port and transmitting, to the controller, a common signal indicator signal, wherein the controller further compares the indicator signal corresponding to the detection of the light signal on the input port and the common signal indicator signal. 8. The network security device of claim 1 wherein the at least one of the plurality of bi-directional communication ports is not providing communication with another networking device. 9. A method for detecting a security intrusion of a network device, the method comprising: redirecting, at a networking device, a light signal present on an output portion of at least one of a plurality of bi-directional communication ports of the networking device to a corresponding input portion of the at least one of the plurality of bi-directional communication ports; monitoring, via a controller, a presence of the light signal on the input portion of the at least one bi-directional communication port; configuring, at the controller, the at least one of the plurality of bi-directional communication ports as a security enabled port; transmitting, via the controller, a security alarm in response to detecting a loss of light signal on the input portion of the security enabled port; and transmitting, via a switch device associated with the at least one of the plurality of bi-directional communication ports, an insertion signal upon a change of state of the switch device in response to an insertion of a cable into the at least one of the plurality of bi-directional communication ports, wherein transmission of the security alarm is further in response to receiving, at the controller, the insertion signal from the switch device associated with the security enabled port. 10. The method of claim 9 wherein the networking device is a reconfigurable optical add drop multiplexor (ROADM) network device, the communication port associated with a wavelength selectable switch (WSS) of the ROADM network device. 11. The method of claim 9 wherein the networking device comprises a loopback connector between the output portion of the bi-directional communication port and the corresponding input portion of the communication port to redirect the light signal. 12. The method of claim 9 wherein monitoring the presence of the light signal comprises: receiving, from a photodetector sensor corresponding to the input portion of the communication port, a light detection signal indicating the presence of the light signal, wherein transmission of the security alarm corresponds to the light detection signal indicating a loss of the light signal on the input portion of communication port. 13. The method of claim 9 further comprising: configuring, via the controller, a first portion of a plurality of communication ports of the networking device as transmission ports for communication with other networking devices; and configuring, via the controller, a second portion of the plurality of communication ports of the networking device as security ports, the bi-directional communication ports included in the second portion of the plurality of communication ports, the security ports monitored for a loss of the light signal. 14. The method of claim 13 wherein an input light signal is replicated to each of the plurality of communication ports of the networking device. 15. A networking device comprising: a network communication port receiving a telecommunications signal; a wavelength selectable switch (WSS) replicating the telecommunications signal on a plurality of bi-directional communication ports each comprising an output port and a corresponding input port; a loopback connector to redirect a light signal from an output port of at least one port of the plurality of bi-directional communication ports to a corresponding input port of the at least one port; a photodetector associated with the at least one port to detect a light signal on the input port of the at least one port; the controller receiving a light detection signal from the photodetector and generating, based on the light detection signal, a security alarm for the security enabled port; and a switch device associated with the at least one of the plurality of bi-directional communication ports and transmitting, to the controller, an insertion signal upon a change of state of the switch device in response to an insertion of a cable into the at least one of the plurality of bi-directional communication ports, wherein generation of the security alarm is further in response to receiving, at the controller, the insertion signal from the switch device associated with the security enabled port. 16. The networking device of claim 15 further comprising: a switch associated with the at least one port and transmitting, to the controller, an insertion signal in response to an insertion of a device into the at least one port. 17. The networking device of claim 15 wherein the light detection signal indicates a loss of the light signal at the input port of th

Assignees

Inventors

Classifications

  • using loopbacks · CPC title

  • Monitoring arrangements {(for SDH/SONET rings H04J3/085)} · CPC title

  • H04L1/243Primary

    at the transmitter, using a loop-back · CPC title

  • Testing of input or output with loop-back · CPC title

  • H04B10/85Primary

    Protection from unauthorised access, e.g. eavesdrop protection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11228404B2 cover?
Systems, methods, and storage media for detecting a security intrusion of a network device are disclosed. Exemplary implementations may include a method involving, in the network device including a processor, monitor a light signal associated with a security enabled port of the network device; and in response to detecting a change in the light signal, initiate a security alert.
Who is the assignee on this patent?
Level 3 Communications Llc
What technology area does this patent fall under?
Primary CPC classification H04L1/243. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 18 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).