×

Applying a packet routing policy to an application session

  • US 9,253,152 B1
  • Filed: 07/03/2014
  • Issued: 02/02/2016
  • Est. Priority Date: 10/17/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method for routing data packets of an application session, the method comprising:

  • recognizing the application session between a network and an application via a security gateway;

    determining by the security gateway a user identity from an application session record for the application session, the application session record comprising a user identity used for accessing a network through a host, a host identity for the host, and an application session time;

    querying, by the security gateway, an identity server by sending the host identity and the application session time in the application session record, the identity server comprising an access session record for an access session between a second host and the network, the access session record comprising a second user identity used for accessing the network through the second host, a second host identity for the second host, and an access session time;

    comparing, by the identity server, the host identity in the application session record with the second host identity in the access session record, and comparing the access session time with the application session time;

    returning, by the identity server, the second user identity in the access session record if the host identity in the application session record matches the second host identity in the access session record, and if the access session time matches the application session time;

    storing at the identity server the second user identity as a network user identity used for accessing the network in the application session record;

    determining by the security gateway at least one packet routing policy applicable to the application session based on the user identity;

    receiving, at the security gateway, a data packet for the application session, the data packet comprising a source network address and a destination network address;

    comparing, by the security gateway, information from the data packet with the at least one packet routing policy; and

    in response to finding a match between the data packet and the at least one packet routing policy, processing the data packet using a forwarding interface of the at least one packet routing policy by the security gateway.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×