Labeling gateway for compartmented multi-operator network elements over a heterogeneous network
Abstract
The present invention provides adequate service virtualization and compartmentalization in Network Management Systems for heterogeneous Network Elements to provide interoperability. It introduces a generic mediation layer that can be added to each Network Element that does not provide a network compartmentalization model that is compatible with the one used by the Network Management System. The mediation layer acts as a reverse proxy for the Network Management System to provide an operator with transparent access to an appropriate Management Service. The present invention is also instrumental in providing a high level of security in such hybrid networks.

Term
Term ended
Projected expiry passed 14 April 2024, 2.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
14 claims: 2 independent, 12 dependent
- 1A method for providing, through compartmentalization, an operator with management access to a network element in a hybrid network, comprising the steps of:(a) mapping an incoming management connec tion, to said network element, to a management service according to a policy;and (b) relaying, subsequently to step (a), said incoming management connection to said management service.
- 8A system for providing an operator with management access to a network element in a hybrid network, comprising:(a) means to map an incoming management connection, to said network element, to a management service according to a policy;and (b) means to relay, subsequently to step (a), said incoming management connection to said management service.
Independent claims2
30 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
0001The invention relates to the field of network management and more particularly to providing a highly secure Network Management S ystem for a network of heterogeneous Network Elements through compartmentalization and virtualization techniques.
BACKGROUND OF THE INVENTION
0002Earlier systems and methods introduce the use of mandatory access control to enforce strong compartmental ization between operators of a Network Management System. They also propose mechanisms to carry information about compartmentalization through the network, thereby allowing extension of the compartmentalization to a set of hosts.
0003Such mechanisms a re highly relevant to Network Management Systems, as they can be used to transparently extend to the whole network, compartments defined for operators in the Network Management System. This extension enables implementation of a strong information flow con trol between operators, each operator being provided, through service virtualization, with a specific view of the network.
0004The invention disclosed in the co -pending US Application 10/045,048 filed on January 15, 2002, describes the use of a compart mentalized Operating System to increase the security of a Network Management Infrastructure, especially when it addresses a Multi -operator environment.
0005Several standards exist to carry information related to compartmentalization with the traffic. T he CIPSO (Commercial Internet Protocol Security Option), for example, communicates security information within and between different security domains. It provides for multiple security domains utilizing a single software environment. Another example of t hese standards would be the FIPS188 which also supports a large number of compartments. Furthermore, there exists several operating systems that claim compliance with these standards (e.g., SELinux and Trusted Solaris).
0006Despite the existence of standards, interoperability between different systems that claim to have an implementation of those standards is not guaranteed. As a result, compartmentalization through the network often requires usage of similar Operating Systems.
0007This constraint is not acceptable in the scope of a Network Management System. Networks are often made of a large variety of heterogeneous Network Elements (e.g., different vendors). It is not reasonable to expect that these Network Elements be built on top of a set of Operating Systems that implement compatible network compartmentalization mechanisms. For example, some Network Elements might be built on top of operating systems that provide non - interoperable network compartmentalization mechanisms: compartmentalization techniques could be different from one system to another. Other Network Elements might be built on top of standard operating systems that do not provide compartmentalization features. Furthermore, even systems that implement compartmentalization do not always support services virtualization needed to provide each operator with a specific view of the network according to the operator's compartment.
0008The lack of compartmentalization on one of the two hosts involved in a communication, the implement ation of different network compartmentalization techniques on these two hosts, and the implementation of similar network compartmentalization techniques configured with inconsistent compartment definitions, are the main foundations for incompatibility. Co nsequently, service virtualization and compartmentalization through a managed network becomes difficult to achieve because of the heterogeneous nature of such a network, which leads to interoperability problems.
0009These limitations necessitate the ne ed for a network scheme that allows the integration of different network compartmentalization techniques within a network while providing interoperability between the miscellaneous elements of that network.
SUMMARY OF THE INVENTION
0010To overcome the limitations of the prior art described above, and to overcome other limitations that will become apparent upon reading and understanding the present specification, the present invention accordingly implements compartmentalization and virtualization techni ques.
0011The present invention provides the advantage of allowing the integration of different network compartmentalization techniques within a network while providing interoperability between the miscellaneous elements of that network.
0012The present invention enables service virtualization on a system that does not natively implement this concept. It does so by introducing a generic mediation layer that can be added to each Network Element that does not provide a network compartmentalization mo del that is compatible with the one used by the Network Management System. The mediation layer acts as a reverse proxy to provide an operator with transparent access to an appropriate Management Service.
0013The present invention allows, through compa rtmentalization, the providing of a high level of security that is required for a hybrid network: ample security is needed for a network composed of heterogeneous Network Elements and supporting different network compartmentalization techniques.
BRIEF DESCRIPTION OF THE DRAWINGS
0014In order that the invention may be more clearly understood, a prior art device and devices according to the present invention will now be described with reference to the accompanying drawings in which:
0015Figure 1 show an example illustrating the prior art system;
0016Figure 2 is a block diagram outlining the functionality of the disclosed invention; and
0017Figure 3 echos figure 1 to accentuate the main difference between the prior art and the disclosed invent ion.
DETAILED DESCRIPTION OF THE INVENTION
0018The following description is presented to enable a person skilled in the art to make use of the invention and is provided in the context of a particular application and its requirements. Various modifica tions to the disclosed embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of the present invention. T hus, the present invention is not intended to be limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.
0019As exemplified in figure 1, existing systems require homogeneous compartmentalization techniques. Only two compartments, compartment A <b>101</b> and compartment B <b>102</b>, are employed to illustrate the purpose of this example. A network <b>100</b> comprises of a Network Management System <b>103</b>, a Network Element <b>104</b>, and channels of communication <b>105</b> between the two. For a network <b>100</b> to be managed effectively, it is usually compartmentalized, with each compartment comprising of elements similar to the ones mentioned above: compartment A <b>101</b> has its own compartment management system <b>106</b>, its own compartment element <b>107</b>, and its own channels of communication <b>108</b>. The same applies to compartment B <b>102.</b>
0020The management system <b>106</b> of compartment A <b>101</b> can only manage the element <b>107</b> of that compartment. A management connection fro m the management system <b>106</b> of compartment A <b>101</b> traverses the channels <b>108</b> of that compartment to administer the element <b>107</b> of the same compartment. For a management connection from compartment A <b>101</b> to administer the element <b>110</b> of compartment B <b>102</b>, calls for the element <b>107</b> of compartment A <b>101</b> and the element <b>110</b> of compartment B <b>102</b> to be built on top of a set of operating systems that implement compatible network compartmentalization mechanisms.
0021The invention of this application provides a solution to the aforementioned interoperability problem based on a Labeling Conversion Gateway (hereinafter, referred to as LCG). The LCG addresses the compatibility issues that contemporary Network Management Systems fail to sufficiently deal with by offering adequate service virtualization and compartmentalization, in Network Management Systems for heterogeneous Network Elements, to provide interoperability. It is also instrumental in providing a high level of security in such hybrid networks.
0022The LCG is a generic mediation layer that can be added to each Network Element that does not provide a network compartmentalization model that is compatible with the one used by the Network Management System. The LCG acts as a reverse proxy for the Network Management System to provide an operator with transparent access to an appropriate Management Service.
0023As shown in figure 2, in a network <b>200</b>, the LCG <b>203</b> is integrated into the Network Element <b>201</b>, and it deflects all of the incoming management connections from the Network Management System <b>202</b> to that Network Element <b>201.</b> After receiving the management connection, the LCG <b>203</b> maps it to the appropriate Management Service <b>206.</b> The LCG <b>203</b> then relays the management connection to the Management S ervice <b>206,</b> thereby providing the operator <b>207</b> with management access to the Network Element <b>201</b>.
0024For an efficient implementation of the invention, it is required that the Management Services <b>206</b> be accessible only through the LCG <b>203</b>. One way to achieve this would be to bind a management service to a loop -back interface that cannot be accessed directly from a remote system. The loop -back interface and its alternatives are considered to be well known to a person skilled in the art.
0025Networks are inherently susceptible to attack by exploitation of security weaknesses in network protocols and infrastructure components. By constraining all of the incoming management connections to access their Management Services <b>206</b> through the LCG <b>203</b>, the present invention provides a level of network security: the LCG <b>203</b> monitors and authorizes (by using labeling information, for example), all management connections before rendering access to the Management Services <b>206</b>.
0026The mapping between the inco ming connection and the appropriate Management Service <b>206</b> is defined by a Labeling Conversion Policy <b>204</b> (hereinafter, referred to as LCP), which is stored in a database <b>205</b> on the Network Element <b>201</b>. Incoming connections are mapped according to any of the following: the IP source address, the IP destination address, the transport protocol used (TCP, UDP or both), the TCP or UDP destination port, or the labeling information contained in IP options.
0027A connection that matches an entry of the LCP <b>204</b> is relayed to the appropriate Management Service <b>206</b> by the LCG <b>203</b> according to the LCP <b>204.</b> The LCP <b>204</b> can specify changes to the following information in the incoming connection: the IP destination address, the TCP or UDP destination port, and the labeling information contained in IP options. A connection that does not match an entry of the Labeling Conversion Policy is left unchanged.
0028To further clarify the present invention, figure 3 is presented to - in combination with figure 1 - depict the main difference between the prior art and the disclosed invention. To reflect the illustration of figure 1, as well, only two compartments are employed in this example: compartment A <b>301</b> and compartment B <b>302.</b>
0029A management connection from the management system <b>303</b> of compartment A <b>301</b> traverses the channels <b>304</b> of that compartment to reach the LCG <b>203</b>, which is integrated into the Network Element <b>201</b>. Subsequently to mapping the incoming management connection in accordance to the LCP <b>204</b>, which is also stored on the Network Element <b>201</b>, the management connection can be relayed to any Management Service <b>206</b>.
0030The scheme described above can be built into Network Elements during production or added on to existing Network Elements that do no t natively implement this concept.
Contents5
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO0108354A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| EP1327934A1 | Cites | European Patent Office (EPO) | Search report |
| US6499059B1 | Cites | United States of America | Applicant |
7 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 417117 | United States of America | – | |
| 41711703 | United States of America | A |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| CN1538669A | China | A | |
| US2004210768A1 | United States of America | A1 | |
| EP1487151A2This record | European Patent Office (EPO) | A2 | |
| EP1487151A3 | European Patent Office (EPO) | A3 | |
| US7536716B2 | United States of America | B2 | |
| EP1487151B1 | European Patent Office (EPO) | B1 | |
| DE602004021747D1 | Germany | D1 |
34 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Change of addressCA | CA | FR | |
| Change of addressCA | CA | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Lien (pledge) constitutedGC | GC | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designation fees paidAKX | AKX | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1487151
- Application
- 43002062
Titles3
- German
- Markierungsgateway für unterteilte Mehr-Betreiber-Netzelemente in einem heterogenen Netz
- English
- Labeling gateway for compartmented multi-operator network elements over a heterogeneous network
- French
- Passerelle d'étiquettage pour des eléments de réseau compartementés multi-opérateurs dans un réseau hétérogène
Classification
- CPC, 4
- H04L41/0226
- H04L41/022
- H04L63/102
- H04L41/40
- IPC, 2
- H04L12 24
- H04L29 06
Designated states33
- Contracting states, 28
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Poland
- Portugal
- Romania
and 4 moreShow fewer
- Sweden
- Slovenia
- Slovakia
- Türkiye
- Extension states, 5
- Albania
- Croatia
- Lithuania
- Latvia
- North Macedonia