Method and apparatus for selectively enforcing network security policies using group identifiers
Abstract
In selectively enforcing network security policy using group identifiers, access controls are stored in a policy enforcement point (PEP) that controls access to a network. Each access control specifies that a named group is allowed access to a resource. A binding of a network address to an authenticated user, for which the PEP controls access to the network, is stored. The group is updated to include the network address of the authenticated user at the PEP. Packet flows originating from the address can pass from the PEP into the network only if the network address is in the named group identified in one of the access controls that specifies that the named group is allowed access to the network. Thus, network security can be implemented using abstract groups that include specific network addresses; user network access is controlled by updating the groups to modify network addresses of users.
Claims
exact text as granted — not AI-modified1 . An apparatus, comprising:
a network interface that is coupled to the data network for receiving one or more packet flows therefrom; at least one processor; a computer-readable medium encoded with one or more stored sequences of instructions which, when executed by the processor, cause the processor to perform:
creating and storing one or more access controls in a policy enforcement point in a telecommunications network, wherein the policy enforcement point is configured to control access of a plurality of clients to the network, wherein each of the access controls specifies that a named group is allowed access to a particular resource in the network;
receiving a binding of a network address to an authenticated user of one of the clients;
updating the named group at the policy enforcement point to include the network address of the authenticated user from the binding; and
permitting a packet flow originating from the network address to pass from the policy enforcement point into the network only if the network address is in the named group identified in one of the access controls that specifies that the named group is allowed access to the network.
2 . The apparatus of claim 1 , further comprising instructions which when executed by the processor cause storing one or more definitions of groups in a data store; storing one or more definitions of resources within a data store; storing one or more access controls at the policy enforcement point, wherein each of the access controls specifies that a named group is allowed access to a particular resource, and wherein one of the access controls specifies that all other traffic is denied access to the network.
3 . The apparatus of claim 1 , further comprising instructions which when executed by the processor cause distributing the network address of the authenticated user and information identifying one or more groups of which the authenticated user is a member to all policy enforcement points of a protected network that the user seeks to access.
4 . The apparatus of claim 1 , further comprising instructions which when executed by the processor cause distributing the network address of the authenticated user and information identifying one or more groups of which the authenticated user is a member to all policy enforcement points that define a security zone that encompasses the user.
5 . The apparatus of claim 1 , further comprising instructions which when executed by the processor cause receiving an Internet Protocol (IP) address for the user from a network address binding resolution (NABR) process.
6 . The apparatus of claim 1 , further comprising instructions which when executed by the processor cause determining that the user has discontinued use of the client, and in response to the determining, deleting the network address to which the user is bound from each named group of each policy enforcement point of the network.
7 . The apparatus of claim 1 , further comprising instructions which when executed by the processor cause receiving an Internet Protocol (IP) address for the user from an ASAP protocol process.
8 . The apparatus of claim 1 , further comprising instructions which when executed by the processor cause receiving an Internet Protocol (IP) address for the user from a DNS process.
9 . A computer-readable medium carrying one or more sequences of instructions for selectively enforcing a security policy in a network, which instructions, when executed by one or more processors, cause the one or more processors to carry out the steps of:
creating and storing one or more access controls in a policy enforcement point in a telecommunications network, wherein the policy enforcement point is configured to control access of a plurality of clients to the network, wherein each of the access controls specifies that a named group is allowed access to a particular resource in the network; receiving a binding of a network address to an authenticated user of one of the clients; updating the named group at the policy enforcement point to include the network address of the authenticated user from the binding; and permitting a packet flow originating from the network address to pass from the policy enforcement point into the network only if the network address is in the named group identified in one of the access controls that specifies that the named group is allowed access to the network.
10 . An apparatus, comprising:
means for creating and storing one or more access controls in a policy enforcement point in a telecommunications network, wherein the policy enforcement point is configured to control access of a plurality of clients to the network, wherein each of the access controls specifies that a named group is allowed access to a particular resource in the network; means for receiving a binding of a network address to an authenticated user of one of the clients; means for updating the named group at the policy enforcement point to include the network address of the authenticated user from the binding; and means for permitting a packet flow originating from the network address to pass from the policy enforcement point into the network only if the network address is in the named group identified in one of the access controls that specifies that the named group is allowed access to the network.
11 . The apparatus of claim 10 , further comprising means for storing one or more definitions of groups in a data store; storing one or more definitions of resources within a data store; storing one or more access controls at the policy enforcement point, wherein each of the access controls specifies that a named group is allowed access to a particular resource, and wherein one of the access controls specifies that all other traffic is denied access to the network.
12 . The apparatus of claim 1 , further comprising means for distributing the network address of the authenticated user and information identifying one or more groups of which the authenticated user is a member to all policy enforcement points of a protected network that the user seeks to access.
13 . The apparatus of claim 1 , further comprising means for distributing the network address of the authenticated user and information identifying one or more groups of which the authenticated user is a member to all policy enforcement points that define a security zone that encompasses the user.
14 . The apparatus of claim 1 , further comprising means for receiving an Internet Protocol (IP) address for the user from a network address binding resolution (NABR) process.
15 . The apparatus of claim 1 , further comprising means for determining that the user has discontinued use of the client, and in response to the determining, deleting the network address to which the user is bound from each named group of each policy enforcement point of the network.
16 . The apparatus of claim 1 , further comprising means for receiving an Internet Protocol (IP) address for the user from an ASAP protocol process.
17 . The apparatus of claim 1 , further comprising means for receiving an Internet Protocol (IP) address for the user from a DNS process.
18 . A data processing system, comprising:
a first data packet router comprising a dynamic host control protocol (DHCP) server configured to generate network addresses and a network address binding resolution (NABR) protocol server configured to bind network users to the network addresses; a second data packet router coupled in the network and configured as a policy enforcement point to control access of a plurality of client computers to the network; a third data packet router coupled in the network to the first data packet router and comprising a group membership management agent comprising one or more stored sequences of instructions which, when executed, cause the second data packet router to perform:
storing a group list and a resource definition in a data store;
storing information defining one of the network users as a member of a group defined in the group list;
storing one or more access controls in the second data packet router, wherein each of the access controls specifies that the group is allowed access to a particular resource of the resource definition;
receiving a binding of a network address to an authenticated user of one of the client computers;
updating the named group at the second data packet router to include the network address of the authenticated user from the binding; and
permitting a packet flow originating from the network address to pass from the second data packet router into the network only if the network address is in the named group identified in one of the access controls that specifies that the named group is allowed access to the network.
19 . The system of claim 18 , further comprising instructions which when executed by the processor cause determining that the user has discontinued use of one of the client computers, and in response to the determining, deleting the network address to which the user is bound from each named group at the second data packet router.
20 . The system of claim 18 , further comprising instructions which when executed by the processor cause receiving the network address from the DHCP server in response to the one of the network users initiating operation of one of the client computers.
21 . The system of claim 18 , further comprising instructions which when executed by the processor cause receiving the binding in response to the NABR server performing a network address binding resolution for a particular network user, prior to storing the information defining one of the network users as a member of the group.Join the waitlist — get patent alerts
Track US2007204333A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.