US 12,438,887 B2
Network security enforcement using flexible client grouping at the control plane and data plane
Santhana Krishnan Narayanan, Bangalore (IN); and Raghunandan Prabhakar, Bangalore (IN)
Assigned to Hewlett Packard Enterprise Development LP, Spring, TX (US)
Filed by HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP, Spring, TX (US)
Filed on Dec. 14, 2023, as Appl. No. 18/539,735.
Claims priority of application No. 202341067539 (IN), filed on Oct. 9, 2023.
Prior Publication US 2025/0119436 A1, Apr. 10, 2025
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/107 (2013.01) [H04L 63/08 (2013.01); H04L 63/104 (2013.01); H04L 63/105 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A Network Access Device comprising:
a memory; and
a processor that is configured to execute machine readable instructions stored in the memory for operating the processor to:
authenticate, using a control plane component of the Network Access Device, a credential of a user or location associated with a first end user device and a second end user device, the credential being received via a network that communicatively connects the Network Access Device with the first end user device and the second end user device;
allocate, using the control plane component, a first Group Identifier Tag (GIT) to first network traffic originating from the first end user device;
when the credential of the user or location is received for the second end user device, automatically add, using a data plane component of the Network Access Device, the first GIT to second network traffic originating from the second end user device; and
when third network traffic is received by the data plane component of the Network Access Device that comprises a second GIT to the first end user device and the second end user device, drop, using the data plane component of the Network Access Device, the third network traffic, the second GIT being different than the first GIT, and
the second GIT being allocated to the third network traffic originating from a third end user device, the third end user device being absent from an association to the first network traffic and the second network traffic.