A method for implementing zero-trust role-based microsegmentation on a network switch, and a network controller and access switch using the same.

Zero-trust role-based microsegmentation on network switches addresses the limitations of perimeter security by using network switches to enforce granular access control without client agents, enhancing security and efficiency.

JP7850328B1Active Publication Date: 2026-04-22PIOLINK
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
PIOLINK
Filing Date
2025-09-22
Publication Date
2026-04-22

AI Technical Summary

Technical Problem

The perimeter security model is ineffective in detecting and blocking threats within the internal network, as it relies on trusting entities beyond the perimeter, leading to potential attacks using infected computers, and implementing zero-trust security models is complex and costly with traditional architectures.

Method used

Implement zero-trust role-based microsegmentation using network switches, where a network controller and access switch manage network devices and resources based on predefined segments and access control lists (VLAN and IACL) without requiring agents on client terminals.

Benefits of technology

Enables granular security policies and efficient segment-based resource access control, reducing complexity and cost while maintaining high security by continuously monitoring user and device behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007850328000001_ABST
    Figure 0007850328000001_ABST
Patent Text Reader

Abstract

This provides a method for efficiently implementing zero-trust network access, along with network controllers and access switches. [Solution] In a method for implementing zero-trust role-based microsegmentation, the network controller obtains network device information about the network device 10 from the access switch 100, registers the network device in the segment corresponding to the network device's asset information, transmits the segment ID corresponding to the segment in which the network device is registered to the access switch, and the access switch specifies the segment ID as metadata to the network device's MAC address and controls the network device's access to network resources based on resource access control rules corresponding to the segment ID.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for implementing zero-trust role-based microsegmentation based on a network switch, as well as a network controller and an access switch using the same.

Background Art

[0002] The perimeter security model is a powerful network security model for controlling access from an enterprise's external network to its internal network. However, the biggest problem with the perimeter security model lies in the perimeter itself. That is, since security control is concentrated at the perimeter, once beyond the perimeter, security control can no longer be applied.

[0003] Permitting access in the perimeter security model means trusting the entity accessing. Because it trusts the access entity, it permits access to internal resources. For example, since a computer connected to an internal business network uses an internal IP address, internal security devices basically operate on the principle of trust.

[0004] An attacker exploits such a trust relationship to launch an attack, occupying an already trusted internal terminal and using it for the attack. Since the perimeter security model applies security control only at the perimeter, which is the contact point between the external network and the internal network, it cannot detect or block threats existing inside beyond the perimeter.

[0005] In other words, attackers can use malware to infect computers connected to the internal network, and then use those infected computers as a base to attack information assets. As a result, the internal network of a company, which has previously been considered a source of trust, can no longer be trusted. Therefore, it is necessary to assume that attackers have already infiltrated the company's internal network, and procedures are needed to detect and respond to attacks even in such a worst-case scenario.

[0006] To address the shortcomings of this perimeter security model, the Zero Trust Security model was proposed.

[0007] Zero trust security essentially maintains data and resources in an inaccessible state, allowing users to access them only under appropriate circumstances and with limited access; this is known as least privilege access.

[0008] The zero-trust security model assumes that all users, devices, or applications on the network are potential threats and that an authentication process must be followed before granting access. In other words, access is granted based on identity, the device being used, and the content of the request, rather than on the user's location or network.

[0009] Therefore, the zero-trust security model offers the advantage of high security by enforcing device authentication for all access requests, and improved operational flexibility by allowing users to access securely from anywhere. Furthermore, security can be flexibly applied by continuously monitoring user and device behavior.

[0010] However, implementing a zero-trust security model in a system requires considerable time and investment, and the need for device authentication for every access request makes implementation complex and increases management costs. Furthermore, forcing authentication on users can degrade the user experience.

[0011] Furthermore, traditional zero-trust security architectures operate based on PDP (Policy Decision Point) or PEP (Policy Enforcement Point), installing agents on client terminals and controlling access to resources through gateways.

[0012] While this conventional method has the advantage of allowing for fine-grained control, it has limitations in installing agents on all terminals, and controlling resources at the gateway before the network has limitations in applying granular access restrictions across the entire network.

[0013] Therefore, the applicant seeks to propose a method for more efficiently implementing zero-trust network access. [Overview of the Initiative] [Problems that the invention aims to solve]

[0014] The purpose of this invention is to solve all of the problems of the prior art described above.

[0015] Another objective of the present invention is to enable control of zero-trust network access based on zero-trust security using a network switch as the underlying infrastructure.

[0016] Furthermore, another objective of the present invention is to enable the application of granular security policies by utilizing information such as MAC / IP / VLAN without installing an agent on the client terminal.

[0017] Furthermore, another objective of the present invention is to enable efficient segment-based resource access control by utilizing the ACLs of network switches. [Means for solving the problem]

[0018] According to one embodiment of the present invention, a method for implementing zero-trust role-based microsegmentation based on a network switch is provided, comprising the steps of: (a) when specific network device information relating to a specific network device connected to the network is obtained from at least one access switch that enables network devices and network resources to communicate with each other within the network, a network controller refers to asset information corresponding to the specific network device and registers the specific network device in a specific segment corresponding to the asset information from among pre-configured segments (the segments are microsegmentations of the network based on the roles performed by the network devices in accordance with a network security policy for zero-trust security); and (b) the network controller transmits a specific segment ID corresponding to the specific segment in which the specific network device is registered to the access switch, causing the access switch to use a VLAN Access Control List (VACL) to specify the specific segment ID as metadata to a specific MAC address of the specific network device, and to use an Ingress Access Control List (IACL) to control the specific network device's access to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID.

[0019] In one example, in step (a), the network controller refers to the category-specific attribute values ​​registered in the asset information corresponding to the specific network device, confirms at least one matching keyword that matches a pre-configured segment keyword, confirms the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

[0020] In one example, in step (a), the network controller, with the network administrator having set at least one segment keyword for each of the segments, identifies the at least one matching keyword, which is at least one specific attribute value that matches the segment keyword, from among the attribute values, identifies the specific segment to which the at least one matching keyword is set, and registers the specific network device to the specific segment.

[0021] In one example, prior to step (b), the network controller tags each of the network resources to which each of the network resources belongs, so that each of the segment IDs corresponding to each of the segments has at least one specific resource group from among the resource groups (the resource groups are grouped and classified based on the role of the network resources) to which it can access, thereby registering each of the access rights of each of the segment IDs to each of the network resources in the IACL.

[0022] In one example, in step (b), the network controller uses the access switch to verify a specific segment ID and a specific destination IP address of a specific packet sent from a specific network device, to verify the access rights of the specific segment ID to a specific network resource corresponding to the specific destination IP address via the IACL, and to filter the transmission of the specific packet to the specific network resource according to the verified access rights.

[0023] According to another embodiment of the present invention, in a method for implementing zero-trust role-based microsegmentation based on a network switch, (a) when at least one access switch that enables network devices and network resources to communicate with each other within a network detects a connection of a specific network device to the network, transmits specific network device information relating to the specific network device to a network controller, and the network controller, by referring to asset information corresponding to the specific network device, registers the specific network device in a specific segment corresponding to the specific asset information from among pre-configured segments (the segments are obtained by microsegmenting the network based on the roles performed by the network devices in accordance with a network security policy for zero-trust security), and transmits a specific segment ID corresponding to the specific segment in which the specific network device is registered to the access switch; and (b) when the specific network ID corresponding to the specific network device is obtained from the network controller, the access switch uses a VACL (Vlant Access Control List) to specify the specific segment ID as metadata to a specific MAC address of the specific network device, and uses an IACL (Ingress Access Control List). A method is provided that includes the step of controlling access to the network resources of a particular network device based on at least one specific resource access control rule corresponding to the specific segment ID using a List of ( ).

[0024] In one example, in the step (a), the access switch transmits the specific device information to the network controller, and the network controller refers to the category-specific attribute values registered in the asset information corresponding to the specific network device to confirm at least one matching keyword that matches the preset segment keyword, and confirms the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

[0025] In one example, in the step (a), the access switch uses the network controller to confirm at least one matching keyword that is at least one specific attribute value that matches the segment keyword from among the attribute values, with at least one segment keyword set for each of the segments by the network administrator, and confirms the specific segment in which the at least one matching keyword is set, and registers the specific network device in the specific segment.

[0026] In one example, before the step (b), the access switch uses the network controller to tag each of the network resources with the respective resource group to which each of the network resources belongs, with at least one specific resource group that can be accessed set from among resource groups (the resource groups are grouped and classified based on the role of the network resources), so as to register the access rights of each of the segment IDs for each of the network resources in the IACL.

[0027] In one example, in step (b), the access switch verifies a specific segment ID and a specific destination IP address of a specific packet sent from the specific network device, verifies the access rights of the specific segment ID to a specific network resource corresponding to the specific destination IP address through the IACL, and filters the transmission of the specific packet to the specific network resource according to the verified access rights.

[0028] According to one embodiment of the present invention, a network controller that implements zero-trust role-based microsegmentation based on a network switch includes: a memory storing instructions for implementing zero-trust role-based microsegmentation based on a network switch; and a processor that implements the zero-trust role-based microsegmentation based on the network switch according to the instructions stored in the memory; wherein the processor (i) when specific network device information relating to a specific network device connected to the network is obtained from at least one access switch that enables network devices and network resources to communicate with each other within the network, it refers to asset information corresponding to the specific network device and registers the specific network device in a specific segment corresponding to the asset information from among pre-configured segments (the segments are obtained by microsegmenting the network based on the roles performed by the network device in accordance with a network security policy for zero-trust security); and (ii) transmits a specific segment ID corresponding to the specific segment in which the specific network device is registered to the access switch, thereby enabling the access switch to perform VACL (Vlant Access Control) A network controller is provided that uses a List to specify a specific segment ID as metadata for a specific MAC address of a specific network device, and uses an IACL (Ingress Access Control List) to control the access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID.

[0029] In one example, in the (I) process, the processor refers to the category-specific attribute values registered in the asset information corresponding to the specific network device, checks at least one matching keyword that matches a preset segment keyword, checks the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

[0030] In one example, in the (I) process, the processor, in a state where at least one segment keyword is set for each of the segments by a network administrator, checks at least one matching keyword that is at least one specific attribute value that matches the segment keyword from among the attribute values, checks the specific segment in which the at least one matching keyword is set, and registers the specific network device in the specific segment.

[0031] In one example, before the (II) process, the processor tags each of the network resources with the respective resource group to which each of the network resources belongs, in a state where at least one specific resource group that is accessible is set from among resource groups (the resource groups are grouped and classified based on the roles of the network resources), so that the access rights of each of the segment IDs for each of the network resources are registered in the IACL.

[0032] In one example, the processor, in process (II), uses the access switch to verify a specific segment ID and a specific destination IP address of a specific packet sent from a specific network device, verifies the access rights of the specific segment ID to a specific network resource corresponding to the specific destination IP address via the IACL, and filters the transmission of the specific packet to the specific network resource according to the verified access rights.

[0033] According to another embodiment of the present invention, an access switch implementing zero-trust role-based microsegmentation based on a network switch includes: a memory storing instructions for implementing zero-trust role-based microsegmentation based on a network switch; and a processor that implements the zero-trust role-based microsegmentation based on the network switch according to the instructions stored in the memory; wherein the processor (I) when a connection of a specific network device to the network is detected, transmits specific network device information relating to the specific network device to a network controller, causing the network controller to refer to asset information corresponding to the specific network device and register the specific network device in a specific segment corresponding to the specific asset information from among pre-configured segments (the segments are obtained by microsegmenting the network based on the roles performed by the network device in accordance with a network security policy for zero-trust security); and transmits a specific segment ID corresponding to the specific segment in which the specific network device is registered to the access switch; and (II) when the specific segment ID corresponding to the specific network device is obtained from the network controller, VACL (Vlant Access Control) An access switch is provided that uses a List (VACL) to specify a specific segment ID as metadata to a specific MAC address of a specific network device, and uses an IACL (Ingress Access Control List) to perform a process of controlling the access of a specific network device to a network resource based on at least one specific resource access control rule corresponding to the specific segment ID.

[0034] In one example, the processor transmits the specific device information to the network controller in the (I) process, and the network controller uses the category-specific attribute values ​​registered in the asset information corresponding to the specific network device to confirm at least one matching keyword that matches a pre-set segment keyword, confirms the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

[0035] In one example, the processor, in process (I), uses the network controller to confirm at least one matching keyword, which is at least one specific attribute value that matches the segment keyword, from among the attribute values, with the network administrator having set at least one segment keyword for each of the segments; confirms the specific segment to which the at least one matching keyword is set; and registers the specific network device to the specific segment.

[0036] In one example, the processor registers the access rights of each segment ID to each network resource in the IACL before the (II) process by using the network controller to tag each resource group to which each network resource belongs, so that each segment ID corresponding to each segment has at least one specific resource group accessible from among the resource groups (the resource groups are grouped and classified based on the role of the network resource).

[0037] In one example, the processor, in process (II), checks a specific segment ID and a specific destination IP address of a specific packet sent from a specific network device, checks the access rights of the specific segment ID to a specific network resource corresponding to the specific destination IP address through the IACL, and filters the transmission of the specific packet to the specific network resource according to the checked access rights. [Effects of the Invention]

[0038] According to the present invention, zero-trust role-based microsegmentation based on zero-trust security can be implemented on a network switch.

[0039] According to the present invention, it is possible to apply granular security policies by utilizing information such as MAC / IP / VLAN without installing an agent on the client terminal.

[0040] According to the present invention, efficient segment-based resource access control becomes possible by utilizing the ACLs of network switches. [Brief explanation of the drawing]

[0041] The following drawings, attached for use in describing embodiments of the present invention, represent only a portion of the embodiments, and a person with ordinary skill in the art to which the present invention pertains (hereinafter referred to as "ordinary art") can obtain other drawings from these drawings without performing any inventive work.

[0042] [Figure 1] This figure schematically illustrates a system that implements zero-trust role-based microsegmentation based on a network switch according to one embodiment of the present invention. [Figure 2]This figure schematically illustrates a state in which zero-trust role-based microsegmentation is implemented on a network switch according to one embodiment of the present invention. [Figure 3] This diagram schematically illustrates a state in which access is controlled using VACL and IACL in a state where zero-trust role-based microsegmentation is implemented based on a network switch according to one embodiment of the present invention. [Modes for carrying out the invention]

[0043] The detailed description of the present invention, as described below, refers to the accompanying drawings illustrating specific embodiments in which the present invention may be carried out. These embodiments are described in sufficient detail so that a person of the ordinary skill can carry out the present invention. It should be understood that the various embodiments of the present invention are different from one another but do not need to be mutually exclusive. For example, certain shapes, structures and characteristics described herein can be realized by modifying one embodiment to another without departing from the spirit and scope of the present invention.

[0044] Furthermore, it should be understood that the position or arrangement of individual components within each embodiment may be modified without departing from the spirit and scope of the invention. Therefore, the detailed descriptions below should not be taken as restrictive, and the scope of the invention should be understood to encompass the scope claimed in the claims and all equivalent scopes. In the drawings, similar reference numerals indicate identical or similar components across various aspects.

[0045] In the following, several preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings, so that a person with ordinary skill in the art to which the present invention pertains can easily implement the present invention.

[0046] Figure 1 is a schematic diagram illustrating a system that implements zero-trust role-based microsegmentation based on a network switch according to one embodiment of the present invention, and the system 1000 may include at least one access switch 100 and a network controller 200. For reference, Figure 1 shows three access switches, six network devices, and four network resources, but the number of access switches 100, network devices, and network resources is not limited thereto, and the system 1000 may actually be configured in a more complex structure.

[0047] The access switch 100 enables network devices and network resources to communicate with each other within the network. The access switch 100 may include a memory containing instructions for implementing zero-trust role-based microsegmentation based on the network switch, and a processor that implements zero-trust role-based microsegmentation based on the network switch according to the instructions stored in the memory.

[0048] Specifically, the access switch 100 may, but is not limited to, achieve desired system performance using a combination of computing equipment (e.g., equipment that may include computer processors, memory, storage, input and output devices, and other conventional computing equipment components; electronic communication equipment such as routers and switches; and electronic information storage systems such as network-attached storage (NAS) and storage area networks (SANs)) and computer software (i.e., instructions that enable the computing equipment to function in a particular manner).

[0049] Furthermore, the processor of a computing device may include hardware components such as an MPU (Micro Processing Unit) or CPU (Central Processing Unit), cache memory, and a data bus. The computing device may also further include an operating system and software components for applications that perform specific purposes.

[0050] However, this does not exclude cases where the computing device includes an integrated processor, which is a form in which the medium, processor, and memory for carrying out the present invention are integrated.

[0051] On the other hand, the processor of the access switch 100, when it detects a connection of a specific network device 10 to the network according to instructions stored in memory, can execute a process in which it transmits specific network device information for the specific network device 10 to the network controller 200, and the network controller 200 refers to the asset information corresponding to the specific network device 10 and registers the specific network device 100 in a specific segment corresponding to the asset information from among the pre-configured segments, and transmits a specific segment ID corresponding to the specific segment in which the specific network device 100 is registered to the access switch 100.

[0052] In this case, the segments may be microsegmentations of the network based on the roles performed by network devices, in accordance with a network security policy for zero-trust security. The processor of the access switch 100, upon obtaining a specific segment ID corresponding to a specific network device 10 from the network controller 200 according to instructions stored in memory, can execute a process to control the access of the specific network device 10 to the network resource 20 based on at least one specific resource access control rule corresponding to the specific segment ID, using a VLAN Access Control List (VACL) to specify the specific segment ID as metadata to a specific MAC address of the specific network device 10, and using an Ingress Access Control List (IACL) to control the access of the specific network device 10 to the network resource 20.

[0053] The network controller 200 manages access switches 100 that enable network devices and network resources to communicate with each other within the network, microsegments the network based on the roles performed by network devices 10 in accordance with a network security policy for zero-trust security to generate segments, and sets a user security policy for each segment for zero-trust security. The network controller 200 may include a memory that stores instructions for implementing zero-trust role-based microsegmentation based on the network switches, and a processor that implements zero-trust role-based microsegmentation based on the network switches in accordance with the instructions stored in the memory.

[0054] Specifically, the network controller 200 may, but is not limited to, achieve desired system performance using a combination of computing devices (e.g., devices that may include computer processors, memory, storage, input and output devices, and other conventional computing device components; electronic communication devices such as routers and switches; and electronic information storage systems such as network-attached storage (NAS) and storage area networks (SANs)) and computer software (i.e., instructions that enable the computing devices to function in a particular manner).

[0055] Furthermore, the processor of a computing device may include hardware components such as an MPU (Micro Processing Unit) or CPU (Central Processing Unit), cache memory, and a data bus. The computing device may also further include an operating system and software components for applications that perform specific purposes.

[0056] However, this does not exclude cases where the computing device includes an integrated processor, which is a form in which the medium, processor, and memory for carrying out the present invention are integrated.

[0057] On the other hand, the processor of the network controller 200, following instructions stored in memory, can, when it obtains specific network device information for a specific network device 10 connected to the network from at least one access switch 100 that enables network devices and network resources to communicate with each other within the network, refer to asset information corresponding to the specific network device 10 and execute a process to register the specific network device in a specific segment corresponding to the asset information from among the pre-configured segments. Then, following instructions stored in memory, the processor of the network controller 200 can transmit a specific segment ID corresponding to the specific segment in which the specific network device 10 is registered to the access switch 100, and the access switch 100 can execute a process to specify the specific segment ID as metadata to a specific MAC address of the specific network device 10 using a VACL (Vlant Access Control List), and to control the access of the specific network device 10 to the network resource 20 based on at least one specific resource access control rule corresponding to the specific segment ID using an IACL (Ingress Access Control List).

[0058] A method for implementing zero-trust role-based microsegmentation on a network switch using a system according to one embodiment of the present invention configured as described above will be explained below with reference to Figure 2.

[0059] First, the access switch 100 collects MAC (Media Access Control) addresses, IP (Internet Protocol) addresses, VLAN (Virtual LAN), port information, etc., of network devices connected to the network, and monitors the access flow of network devices to network resources via sFlow (sampled Flow), etc. When a specific network device 10 connected to the network is detected (S10), the access switch 100 can transmit specific network device information, such as the MAC address, IP address, VLAN information, etc. of the specific network device 10, that is, specific network device information corresponding to the specific network device 10, to the network controller 200 (S20).

[0060] Then, the network controller 200 refers to the specific network device information of the specific network device 10 transmitted from the access switch 100, confirms the asset information corresponding to the specific network device 10, and, referring to the asset information corresponding to the specific network device 10, registers the specific network device 10 in a specific segment corresponding to the asset information from among the pre-configured segments. At this time, the segments may be microsegments of the network based on the roles performed by the network devices, in accordance with the network security policy for zero-trust security.

[0061] In other words, the network controller 200, having obtained specific network device information for a specific network device 10 from the access switch 100, can use the specific network device information, for example, at least one of the MAC address, IP address, and VLAN information corresponding to the specific network device 10, to check the asset information of the specific network device 10, refer to the category-specific attribute values ​​registered in the asset information corresponding to the specific network device 10 to check at least one matching keyword that matches the pre-configured segment keyword, check a specific segment corresponding to at least one matching keyword (S30), and register the specific network device 10 in the specific segment (S40).

[0062] At this time, the network controller 200 can, with the network administrator having set at least one segment keyword for each segment, identify at least one matching keyword from among the attribute values ​​that matches the segment keyword, identify a specific segment to which at least one matching keyword is set, and register a specific network device to that specific segment.

[0063] In other words, a segment configured to correspond to the entire set of confirmed matching keywords can be identified as a specific segment corresponding to a specific network device, and a specific network device can be registered to that specific segment.

[0064] As an example, as shown in Figure 2, a network administrator can generate segments such as "Confidential," "Sensitive-Dev," "Sensitive-Plan," "NPE," "Test-Device," and "Unauthenticated / Managed" through role-based microsegmentation, and then set the segment keyword "Client Name: Administrator" for the "Confidential" segment, the segment keywords "Terminal Type: Business PC, Business Equipment" and "Department: Development Team 1" for the "Sensitive-Dev" segment, the segment keywords "Terminal Type: Business PC, Business Equipment" and "Department: Planning Office" for the "Sensitive-Plan" segment, the segment keyword "Terminal Type: Office Equipment" for the "NPE" segment, and the segment keyword "IP Address: 192.168.100.101~192.168.100.120" for the "Test-Device" segment.

[0065] With segment keywords set for each segment in this way, the results of checking the specific network device information and asset information of a specific network device 10 that was detected to be connected to the network show that if the attribute value of the "Client Name" category in the asset information is "Administrator," which is the matching keyword, then the segment corresponding to the specific network device 10 is the "Confidential" segment. If the attribute value of the "Terminal Type" category in the asset information is "Business PC," which is the matching keyword, and the attribute value of the "Department" category is "Development Team 1," which is the matching keyword, then the segment corresponding to the specific network device 10 is the "Sensitive-Dev" segment. If the attribute value of the "IP Address" category in the specific network device information is "192.168.100.110," which is the matching keyword, then the segment corresponding to the specific network device 10 is the "Test-Device" segment. On the other hand, if, after checking the specific network device information and asset information of a specific network device 10, there is no attribute value that matches the segment keyword, i.e., there is no matching keyword, then the segment corresponding to the specific network device 10 is the "Unauthenticated / Managed" segment. This allows a specific network device 10 to be automatically registered to the corresponding specific segment through a matching keyword.

[0066] Furthermore, when checking a specific segment corresponding to a particular network device based on segment keywords, a priority can be set for each configured segment. By sequentially checking the segments corresponding to a particular network device, from the highest-priority segment to the lowest-priority segment according to the priority, the specific segment corresponding to a particular network device can be identified.

[0067] As an example, assuming that in Figure 2 "Confidential" is set as the first-priority segment, "Sensitive-Dev" as the second-priority segment, "Sensitive-Plan" as the third-priority segment, "NPE" as the fourth-priority segment, "Test-Device" as the fifth-priority segment, and "Unauthenticated / Managed" as the sixth-priority segment, if the overall matching keywords for a specific network device 10 are "Business PC" and "Planning Office," then we can first compare the matching keywords "Business PC" and "Planning Office" with the segment keyword "Administrator," which is set in the first-priority segment "Confidential." Since the matching keywords "Business PC" and "Planning Office" do not match the segment keyword "Administrator," we can determine that the specific network device does not belong to the "Confidential" segment. Next, the matching keywords "business PC" and "planning office" can be compared with the segment keywords "business PC" and "development team 1" set in the second-priority segment "Sensitive-Dev". The matching keyword "business PC" matches the segment keyword "business PC", but the other matching keyword "planning office" does not match the segment keyword "development team 1". Therefore, it can be determined that the specific network device does not belong to the "Sensitive-Dev" segment. Next, the matching keywords "business PC" and "planning office" can be compared with the segment keywords "business PC" and "planning office" set in the third-priority segment "Sensitive-Plan". The matching keyword "business PC" matches the segment keyword "business PC", and the matching keyword "planning office" also matches the segment keyword "planning office". Therefore, it can be determined that the specific network device belongs to the "Sensitive-Plan" segment.Therefore, if a particular network device is determined to belong to the third-priority segment, "Sensitive-Plan," then the fourth through sixth-priority segments are not checked, and the specific segment corresponding to that network device can be determined to be the "Sensitive-Plan" segment.

[0068] Next, the network controller 200 can transmit a specific segment ID corresponding to a specific segment in which a specific network device 10 is registered to the access switch 100 (S50).

[0069] Then, the access switch 100 can use a VACL (Vlan Access Control List) to specify a specific segment ID as metadata for a specific MAC address of a specific network device 10, and use an IACL (Ingress Access Control List) to control access to the network resource 20 of the specific network device 10 based on at least one specific resource access control rule corresponding to the specific segment ID (S60).

[0070] In this case, the network controller 200 can register the access rights of each segment ID to each network resource in the IACL by tagging the respective resource group to which each network resource belongs, with each segment ID corresponding to each segment configured to have at least one specific resource group accessible from among the resource groups. The resource groups may be grouped and classified based on the role of the network resources.

[0071] For example, as shown in Figure 2, if a network administrator creates resource groups such as "All Access Permissions," "Common_Server," and "Office Equipment," and each segment is configured to have access to a specific resource group, then tagging network resource 20 with the "Common_Server" resource group will be configured so that only the "Sensitive_Dev" segment is allowed access to the "Common_Server" resource group. Therefore, the access rights for network resource 20 in the IACL, i.e., the filter for network resource 20, can be configured to allow access for segment IDs corresponding to the "Sensitive_Dev" segment and block access for other segment IDs. In contrast, if the network resource 20 is tagged with the "Office Equipment" resource group, the "Office Equipment" resource group is configured so that only the "Sensitive_Dev" segment and the "Sensitive_Plan" segment are allowed access. Therefore, the access rights for network resource 20 in the IACL can be configured to allow access for segment IDs corresponding to the "Sensitive_Dev" segment and the "Sensitive_Plan" segment, and block access for other segment IDs. Furthermore, if the network resource 20 is tagged with the "Office Equipment" resource group, and the "All Access Permissions" resource group is also tagged, the "All Access Permissions" resource group is configured to only allow access to the "Confidential" segment. Therefore, the access rights for network resource 20 in the IACL can be configured to allow access to the segment ID corresponding to the "Sensitive_Dev" segment, the segment ID corresponding to the "Sensitive_Plan" segment, and the segment ID corresponding to the "Confidential" segment, while blocking access to other segment IDs.

[0072] On the other hand, referring to Figure 3, the process of generating resource access control rules for a single segment using VACL and IACL in the access switch 100 can be briefly explained as follows.

[0073] Assuming that N network devices are registered in segment #1 and M network resources are tagged in resource group #1, VACL can be used to specify segment #1 as metadata for N MAC addresses corresponding to N network devices, and IACL can be used to set up M filters to filter access to each of the M network resources for segment #1.

[0074] Therefore, the number of ACL filters in access switch 100 becomes N+1 × M. This significantly reduces the number of filters compared to conventional ACL implementations, where a filter is generated for each of the M network resources for each of the N network devices, resulting in N × M filters. Furthermore, it becomes possible to control access to a zero-trust network for a large number of network resources with a memory capacity of 1k to 2k for the access switch's filter hardware.

[0075] Furthermore, conventionally, the smallest unit of a segment was limited to a switch + port, making it impossible to assign multiple segments to a single switch port. However, by using VACL and IACL as in the present invention, it becomes possible to operate segments for network devices at any location without the physical constraints of conventional switches + ports.

[0076] In other words, the present invention enables continuous segment operation even when the connection location of a network device changes, by specifying the segment ID as metadata in the MAC address of the network device, regardless of the switch port.

[0077] Furthermore, conventionally, when multiple network devices are connected to a single switch port via a hub, all network devices connected to that switch port via the hub are managed on the same segment. Therefore, it was not possible to operate each network device using a single switch port via the hub on different segments. However, according to the present invention, it becomes possible to operate each network device using a single switch port via the hub on different segments.

[0078] On the other hand, a simplified explanation of the process by which the access location processes packets sent from a specific network device using VACL and IACL as described above is as follows:

[0079] When a packet containing the MAC address, source IP address, and destination IP address is sent from a specific network device, the access switch forwards the packet via the VACL, specifying the segment ID as metadata to the MAC address. After verifying the segment ID and destination IP address from the forwarded packet, and checking the filtering conditions for the segment ID against the destination IP address via the IACL, if it is confirmed that the segment ID allows access to the destination IP address, the access switch forwards the packet to the destination IP address, enabling the specific network device to access the network resource corresponding to the destination IP address. If it is confirmed that the segment ID denies access to the destination IP address, the access switch drops the packet, blocking the specific network device from accessing the network resource corresponding to the destination IP address.

[0080] The embodiments of the present invention described above are implemented in the form of program instructions that can be executed through various computer components and may be recorded on a computer-readable recording medium. The computer-readable recording medium may include program instructions, data files, data structures, etc., individually or in combination. The program instructions recorded on the computer-readable recording medium may be specially designed and configured for the present invention, or they may be known and available to those skilled in the art in the field of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program instructions, such as ROMs, RAMs, and flash memory. Examples of program instructions include not only machine code, such as that produced by a compiler, but also high-level language code that can be executed by a computer using an interpreter or the like. The hardware devices may be configured to operate as one or more software modules to perform the processing according to the present invention, and vice versa.

[0081] Although the present invention has been described above with specific details such as concrete components, and with limited embodiments and drawings, these are provided only to aid in a more overall understanding of the invention, and the invention is not limited to the above embodiments. A person with ordinary skill in the art to which the invention pertains can make various modifications and variations from this description.

[0082] Therefore, the concept of the present invention should not be limited to the embodiments described above, and all modifications equivalent to or equivalent to the claims described below shall also fall within the scope of the concept of the present invention. [Explanation of Symbols]

[0083] 1000 System 10 Network Devices 20 Network Resources 100 Access Switches 200 Network Controllers

Claims

1. In a method for implementing zero-trust role-based microsegmentation based on network switches, (a) When specific network device information relating to a specific network device connected to the network is obtained from at least one access switch that enables network devices and network resources to communicate with each other within the network, the network controller refers to the asset information corresponding to the specific network device and registers the specific network device in a specific segment corresponding to the asset information from among pre-configured segments (the segments are microsegmentations of the network based on the roles performed by the network devices in accordance with the network security policy for zero trust security), (b) The network controller transmits a specific segment ID corresponding to the specific segment in which the specific network device is registered to the access switch, and the access switch uses a VACL (Vlan Access Control List) to specify the specific segment ID as metadata to the specific MAC address of the specific network device, and uses an IACL (Ingress Access Control List) to control the access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID. A method that includes this.

2. In step (a) above, The method according to claim 1, wherein the network controller refers to category-specific attribute values ​​registered in the asset information corresponding to the specific network device, confirms at least one matching keyword that matches a pre-set segment keyword, confirms the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

3. In step (a) above, The method according to claim 2, wherein the network controller, with each of the segments set by the network administrator, confirms the at least one matching keyword, which is at least one specific attribute value that matches the segment keyword, from among the attribute values, confirms the specific segment to which the at least one matching keyword is set, and registers the specific network device in the specific segment.

4. Before step (b), The method according to claim 1, wherein the network controller tags each resource group to which each network resource belongs, so that each of the segment IDs corresponding to each of the segments is configured to have at least one specific resource group accessible from among resource groups (the resource groups are grouped and classified based on the role of the network resources), thereby registering each of the access rights of each segment ID to each of the network resources in the IACL.

5. In step (b) above, The method according to claim 1, wherein the network controller uses the access switch to verify a specific segment ID and a specific destination IP address of a specific packet transmitted from a specific network device, verifies the access rights of the specific segment ID to a specific network resource corresponding to the specific destination IP address via the IACL, and filters the transmission of the specific packet to the specific network resource according to the verified access rights.

6. In a method for implementing zero-trust role-based microsegmentation based on network switches, (a) When at least one access switch that enables network devices and network resources to communicate with each other within the network detects a connection of a particular network device to the network, it transmits specific network device information relating to the particular network device to a network controller, and the network controller, by referring to asset information corresponding to the particular network device, registers the particular network device in a specific segment corresponding to the asset information from among pre-configured segments (the segments are microsegmentations of the network based on the roles performed by the network devices in accordance with a network security policy for zero trust security), and transmits a specific segment ID corresponding to the specific segment in which the particular network device is registered to the access switch, (b) When the specific segment ID corresponding to the specific network device is obtained from the network controller, the access switch uses a VACL (Vlan Access Control List) to specify the specific segment ID as metadata to a specific MAC address of the specific network device, and uses an IACL (Ingress Access Control List) to control the access of the specific network device to the network resource based on at least one specific resource access control rule corresponding to the specific segment ID; A method that includes this.

7. In step (a) above, The method according to claim 6, wherein the access switch transmits the specific network device information to the network controller, and the network controller uses the network controller to refer to the category-specific attribute values ​​registered in the asset information corresponding to the specific network device to confirm at least one matching keyword that matches a preset segment keyword, confirms the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

8. In step (a) above, The method according to claim 7, wherein the access switch, with the network controller, checks for at least one matching keyword, which is at least one specific attribute value that matches the segment keyword, from among the attribute values, with the network administrator having set at least one segment keyword for each of the segments, checks for the specific segment to which the at least one matching keyword is set, and registers the specific network device to the specific segment.

9. Before step (b), The method according to claim 6, wherein the access switch, using the network controller, registers the respective access rights of each segment ID to each of the network resources in the IACL, such that each segment ID corresponding to each of the segments has at least one specific resource group accessible from among the resource groups (the resource groups are grouped and classified based on the role of the network resources) configured, and tags the respective resource group to which each of the network resources belongs.

10. In step (b) above, The method according to claim 6, wherein the access switch verifies a specific segment ID and a specific destination IP address of a specific packet transmitted from the specific network device, verifies the access rights of the specific segment ID to a specific network resource corresponding to the specific destination IP address via the IACL, and filters the transmission of the specific packet to the specific network resource according to the verified access rights.

11. In a network controller that implements zero-trust role-based microsegmentation based on a network switch, A memory containing instructions for implementing zero-trust role-based microsegmentation based on a network switch, A processor that implements the zero-trust role-based microsegmentation on the network switch in accordance with the instructions stored in the memory, Includes, The processor is a network controller that performs the following processes: (I) when specific network device information relating to a specific network device connected to the network is obtained from at least one access switch that enables network devices and network resources to communicate with each other within the network, it refers to asset information corresponding to the specific network device and registers the specific network device in a specific segment corresponding to the asset information from among pre-configured segments (the segments are microsegmentations of the network based on the roles performed by the network devices in accordance with a network security policy for zero-trust security); and (II) transmits a specific segment ID corresponding to the specific segment in which the specific network device is registered to the access switch, and causes the access switch to specify the specific segment ID as metadata to a specific MAC address of the specific network device using a VACL (Vlan Access Control List), and controls the access of the specific network device to the network resource based on at least one specific resource access control rule corresponding to the specific segment ID using an IACL (Ingress Access Control List).

12. The aforementioned processor, The network controller according to claim 11, wherein in the process of (I) above, the network controller refers to the category attribute values ​​registered in the asset information corresponding to the specific network device, confirms at least one matching keyword that matches a pre-set segment keyword, confirms the specific segment corresponding to the at least one matching keyword, and registers the specific network device in the specific segment.

13. The aforementioned processor, The network controller according to claim 12, wherein in the process described in (I) above, the network administrator identifies at least one matching keyword, which is at least one specific attribute value that matches the segment keyword, from among the attribute values, with at least one segment keyword set for each of the segments, identifies the specific segment to which the at least matching keyword is set, and registers the specific network device to the specific segment.

14. The aforementioned processor, The network controller according to claim 11, wherein, prior to the process of (II) above, each of the segment IDs corresponding to each of the segments is tagged with the respective resource group to which each of the network resources belongs, with at least one specific resource group accessible from among the resource groups (the resource groups are grouped and classified based on the role of the network resources), so that the respective access rights of each segment ID to each of the network resources are registered in the IACL.

15. The aforementioned processor, The network controller according to claim 11, wherein in the process of (II) above, the access switch is used to verify a specific segment ID and a specific destination IP address of a specific packet transmitted from a specific network device, to verify the access rights of the specific segment ID to a specific network resource corresponding to the specific destination IP address via the IACL, and to filter the transmission of the specific packet to the specific network resource according to the verified access rights.

16. In an access switch that implements zero-trust role-based microsegmentation based on a network switch, A memory containing instructions for implementing zero-trust role-based microsegmentation based on a network switch, A processor that implements the zero-trust role-based microsegmentation on the network switch in accordance with the instructions stored in the memory, Includes, The processor performs the following processes: (I) When a connection of a specific network device to the network is detected, it transmits specific network device information relating to the specific network device to the network controller, and the network controller uses the asset information corresponding to the specific network device to register the specific network device in a specific segment corresponding to the asset information from among pre-configured segments (the segments are obtained by micro-segmenting the network based on the role performed by the network device in accordance with a network security policy for zero-trust security), and transmits a specific segment ID corresponding to the specific segment in which the specific network device is registered to the access switch; and (II) When the specific segment ID corresponding to the specific network device is obtained from the network controller, the access switch performs the following processes: it uses a VACL (Vlan Access Control List (VACL)) to specify the specific segment ID as metadata to a specific MAC address of the specific network device, and uses an IACL (Ingress Access Control List) to control the access of the specific network device to network resources based on at least one specific resource access control rule corresponding to the specific segment ID.

17. The aforementioned processor, The access switch according to claim 16, wherein in the process of (I) above, the specific network device information is transmitted to the network controller, and the network controller refers to the category attribute values ​​registered in the asset information corresponding to the specific network device to confirm at least one matching keyword that matches a preset segment keyword, confirms the specific segment corresponding to the at least one matching keyword, and registers the specific network device to the specific segment.

18. The aforementioned processor, The access switch according to claim 17, wherein in the process of (I) above, the network controller checks for at least one matching keyword, which is at least one specific attribute value that matches the segment keyword, from among the attribute values, with the network administrator having set at least one segment keyword for each of the segments, checks for the specific segment on which the at least one matching keyword is set, and registers the specific network device to the specific segment.

19. The aforementioned processor, Prior to the process of (II) described above, the access switch according to claim 16, wherein the network controller registers the respective access rights of each segment ID to each of the network resources in the IACL, by tagging each resource group to which each of the network resources belongs, such that each segment ID corresponding to each of the segments has at least one specific resource group from among the resource groups (the resource groups are grouped and classified based on the role of the network resources) that it can access.

20. The aforementioned processor, The access switch according to claim 16, wherein in the process of (II) above, a specific segment ID and a specific destination IP address of a specific packet transmitted from the specific network device are verified, access rights of the specific segment ID to a specific network resource corresponding to the specific destination IP address are verified through the IACL, and transmission of the specific packet to the specific network resource is filtered according to the verified access rights.

Citation Information

Patent Citations

  • Network controller, network control method and program

    JP2016054419A

  • Master device, communication control method, communication control program, and communication control system

    JP2023047977A

  • Method for managing network using microsegmentation for zero trust security and access switch using the same

    JP2025067750A

  • System for providing zero trust model based seruity management service

    KR102655993B1