US 12,407,738 B2
Applying overlay network policy based on users
Nicholas Anthony Marrone, Seattle, WA (US); and Bryan David Skene, Seattle, WA (US)
Assigned to TYCO FIRE & SECURITY GMBH, Neuhausen am Rheinfall (CH)
Filed by Tyco Fire & Security GmbH, Neuhausen am Rheinfall (CH)
Filed on Nov. 20, 2023, as Appl. No. 18/515,221.
Application 18/515,221 is a continuation of application No. 17/378,535, filed on Jul. 16, 2021, granted, now 11,824,901.
Application 17/378,535 is a continuation of application No. 17/084,557, filed on Oct. 29, 2020, granted, now 11,070,594, issued on Jul. 20, 2021.
Claims priority of provisional application 63/093,041, filed on Oct. 16, 2020.
Prior Publication US 2024/0089300 A1, Mar. 14, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01); H04L 12/66 (2006.01)
CPC H04L 63/205 (2013.01) [H04L 12/66 (2013.01); H04L 63/102 (2013.01); H04L 63/104 (2013.01); H04L 63/108 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method, comprising:
providing credentials of users to an authorization service for an underlay network, wherein the authorization service authenticates the users as members of one or more authorization groups for the underlay network;
providing one or more user groups associated with an overlay network, each user being associated with a respective user group of the one or more user groups, the user group for a respective user identified based on a match of the user group to an authorization group in which the respective user is authenticated as a member;
providing one or more resource groups associated with one or more resources in the overlay network; and
configuring policy information for gateways of the overlay network according to an access time window, wherein the policy information is configured according to one or more disqualified access tags and one or more disqualified resource groups,
the one or more disqualified access tags being determined according to at least some of the one or more user groups associated with the access time window, and
the one or more disqualified resource groups determined based on resources corresponding to the one or more disqualified access tags.