EP0335555A2

User to network interface protocol for packet communications networks.

Abstract

A high capacity metropolitan area network (MAN) is described. Data traffic from users is connected to data concentrators at the edge of the network, and is transmitted over fiber optic data links to a hub where the data is switched. The hub includes a plurality of data switching modules, each having a control means, and each connected to a distributed control space division switch. Advantageously, the data switching modules, whose inputs are connected to the concentrators, perform all checking and routing functions, while the 1024x1024 maximum size space division switch, whose outputs are connected to the concentrators, provides a large fan-out distribution network for reaching many concentrators from each data switching module. Distributed control of the space division switch permits several million connection and disconnection actions to be performed each second, while the pipelined and parallel operation within the control means permits each of the 256 switching modules to process at least 50,000 transactions per second. The data switching modules chain groups of incoming packets destined for a common outlet of the space division switch so that only one connection in that switch is required for transmitting each group of chained packets from a data switching module to a concentrator. MAN provides security features including a port identification supplied by the data concentrators, and a check that each packet is from an authorized source user, transmitting on a port associated with that user, to an authorized destination user that is in the same group (virtual network) as the source user.

EP0335555A2, drawing sheet 1
Sheet 1 of 28

Term

Term ended

Projected expiry passed 21 March 2009, 17.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

21 claims: 11 independent, 10 dependent

  1. 1
    A method of obtaining security in packet transmission from an input port to an output port, comprising the steps of:including in each data packet an identity of said input port and an identity of a user of said input port transmitting said each data packet;and checking for said each data packet whether a pair comprising said user identity and said port identity has been previously authorized.
  2. 3
    A data network for transmitting data packets, comprising:means for inserting in a packet an identity of a port transmitting said packet, said means being comprised in said network and out of control of a user at said port;and means for authenticating from said port identification and addressing data in said packet whether said port is authorized to transmit said packet to said network.
  3. 5
    In a data network, a method of achieving secure transmission from a source user to a destination user comprising the steps of:said destination user logging into said system with a login data packet comprising a destination user password, destination user identification, a destination group identification, and a destination port identification supplied by said network;said data network authenticating said destination user password, destination user identification, destination user group number, and destination user port number as being authorized to receive packets for said destination group and user;said source user logging into said system with a login packet comprising an identification of said source user, a source user password, a source group identification, and a source port identification supplied by said network;authenticating said source user password and source user, source user group, and source user port identifications;recording, in source tables, authorization for said identifications of said source user, source group, and source port;recording, in routing tables, authorization for said destination user and said destination group, and an identity of said destination port;for each transmitted packet, checking a source user identification and source group identification, and a source port identification supplied by said network, in said source tables, and finding a destination port using a destination user identification and a destination group identification in said routing tables;if results of said source checking and destination port finding steps indicate that said source and said destination have been recorded in said source tables and said destination tables, transmitting said packet to a destination port identified in said finding step.
  4. 10
    A protocol for a data network, comprising:a data packet header comprising an identification of a source and a destination;wherein said data network comprises means for checking for each data entity that transmission from said source to said destination is authorized.
  5. 11
    A network protocol for a data network, said protocol specified by a header for each data packet, said header comprising:an identification of a transmitting network port supplied by said network;an identification of the name of a source and name of a destination supplied by a source user system;said network comprising means for checking that said source is authorized to transmit to said destination from said port.
  6. 12
    A protocol for a data network, comprising a network protocol specified by a network header, comprising:an identification of a source port;an identification of a source user;an identification of a destination user system;an identification of a user group;an identification of a type of service to be provided;and a header check for detecting errors in said network header;wherein said data network comprises means for identifying said source port and for inserting an identification of said source port into said network header as said identification of a source port;wherein said data network comprises means for checking whether a combination of said source user, said user group and said source port is authorized to transmit packets over said data network;wherein said data network comprises means for generating a destination port identity from a combination of said destination user system identification and said group for transmitting said data packet to said destination port.
  7. 14
    A method of transmitting data packets in a data network comprising the steps of:inserting in a header of each data packet an identification of a source and a destination;and checking in said data network whether said source is authorized to transmit packets to said destination.
  8. 15
    In a network for serving users of a plurality of user groups, a method of preventing users of one group from obtaining unauthorized access to users of another group, comprising the steps of:generating a user authorization data base for authorizing access by a first user to members of ones of a plurality of groups;processing a login packet, comprising an identification of a login destination user group and an identification of said first user, from said first user to determine whether said first user is authorized in said authorization data base to access said destination user group;if said authorization step indicates that said first user is authorized to access said destination user group, recording data indicating that said first user is authorized to send packets to said destination user group;thereafter, ascertaining in said recorded data, for every data entity, comprising said identification of said first user and an identification of a destination user group for said data entity, whether said first user is authorized to send data to said destination user group;and transmitting said data entity to a user of said destination user group if said ascertaining step indicates that said first user is authorized.
  9. 19
    In a data network, a method of transmitting data entities from a source user to a user that is member of a group, comprising the steps of:ascertaining, for every data entity, comprising an identification of said source user and said group, whether said source user is authorized to transmit data entities to a user of said group;and transmitting said data entity to a user of said group if said ascertaining step indicates that said source user is authorized.
  10. 20
    In a network for serving users of a plurality of user groups, a method of preventing users of one group from obtaining unauthorized access to users of another group, comprising the steps of:generating a user authorization data base for authorizing access by a first user to members of ones of a plurality of groups;supplying, for data packets transmitted by said first user, a source user port identification from within said network and outside control by said first user;processing a login packet, comprising an identification of a destination user group, an identification of said first user, and a user port identification for said first user, from said first user to determine whether said first user is authorized in said authorization data base to transmit data packets from said source user port for said first user to a member of said destination user group;if said authorization step indicates that said first user is authorized to send packets to a member of said destination user group, recording data to indicate that said first user is authorized to send packets to said destination user group from said source user port;if said authorization step further indicates that said first user is authorized to receive data from members of said destination user group, recording that said first user is authorized to receive packets from said members of said destination user group at said source user port;thereafter, ascertaining, for every data packet, comprising said identification of said first user, said user port for said first user, and an identification of a destination user group, whether said first user is authorized to send data from a port identification of said data packet to a member of said destination user group;transmitting said data packet to a user of said destination group if said ascertaining step indicates that said first user is authorized;and recording identifications of users and user ports which transmit unauthorized packets.
  11. 21
    A data network, comprising:a source authorization data base comprising data indicating, for each active source user, authorization for said source user and a group of said source user;a destination authorization data base comprising data indicating, for each active destination user, authorization for said destination user and said destination user group;and means, responsive to data in a data packet received by said network for checking whether said source user and group is authorized to transmit to said destination user and group.