Method for control of communications from an edge device of an access network and edge device and network management module for performing said method
21 claims: 21 independent, 0 dependent
- 1Method for control of communications from an edge device (ED1) of an access network (AN), via the provisioning or the non-provisioning of at least one layer 2 destination address (MAC2) of at least one other edge device (ED2) of said access network (AN) to said edge device (ED1) by a network management module (NMM) of said access network (AN), characterised in that, upon arrival of a packet including at least one layer 2 destination address, said edge device (ED1) - checks whether said at least one layer 2 destination address is stored within a communications restriction filter (CRF) of said edge device (ED1) and- generates a request including said at least one layer 2 destination address only in case said at least one layer 2 destination address is not stored within said communication restriction filter (CRF). Procédé de contrôle de communications d'un dispositif de frontière (ED1) d'un réseau d'accès (AN), par le biais de la fourniture ou la non-fourniture d'au moins une adresse de destination de couche 2 (MAC2) d'au moins un autre dispositif de frontière (ED2) dudit réseau d'accès (AN) au dit dispositif de frontière (ED1) par un module de gestion de réseau (NMM) dudit réseau d'accès (AN), caractérisé en ce que, à l'arrivée d'un paquet comprenant au moins une adresse de destination de couche 2, ledit dispositif de frontière (ED1) - vérifie si ladite au moins une adresse de destination de couche 2 est stockée dans un filtre de restriction de communications (CRF) dudit dispositif de frontière (ED1) et- génère une demande comprenant ladite au moins une adresse de destination de couche 2 seulement dans le cas où ladite au moins une adresse de destination de couche 2 n'est pas stockée dans ledit filtre de restriction de communications (CRF). Verfahren zur Steuerung von Nachrichten von einer Netzperipherie-Vorrichtung (ED1) eines Zugangsnetzwerks (AN) durch Bereitstellung oder Nicht-Bereitstellung mindestens einer Ebene-2-Zieladresse (MAC2) mindestens einer Netzperipherie-Vorrichtung (ED2) des Zugangsnetzwerks (AN) an die Netzperipherie-Vorrichtung (ED1) durch ein Netzwerkverwaltungs-Modul (NMM) des Zugangsnetzwerks (AN), dadurch gekennzeichnet, dass bei Eintreffen eines Paketes, das mindestens eine Ebene-2-Zieladresse enthält, die Netzperipherie-Vorrichtung (ED1) - überprüft, ob die mindestens eine Ebene-2-Zieladresse in einem Kommunikations-Einschränkungs-Filter (CRF) der Netzperipherie-Vorrichtung (ED1) gespeichert ist und- eine Anforderung erzeugt, welche die mindestens eine Ebene-2-Zieladresse nur in dem Fall enthält, dass die mindestens eine Ebene-2-Zieladresse nicht in dem Kommunikations-Einschränkungs-Filter (CRF) gespeichert ist.
- 2Method according to claim 1 wherein additional information is delivered and stored together with said at least one layer 2 destination address (MAC2) in said edge device (ED1). Procédé selon la revendication 1 dans lequel des informations supplémentaires sont délivrées et stockées ensemble avec ladite au moins une adresse de destination de couche 2 (MAC2) dans ledit dispositif de frontière (ED1). Verfahren gemäß Anspruch 1, wobei zusätzliche Information geliefert und zusammen mit der mindestens einen Ebene-2-Zieladresse (MAC2) in der Netzperipherie-Vorrichtung (ED1) gespeichert wird.
- 3Method according to claim 2 wherein said additional information comprises layer 2 forwarding information. Procédé selon la revendication 2 dans lequel lesdites informations supplémentaires comprennent des informations de retransmission de couche 2. Verfahren gemäß Anspruch 2, wobei die zusätzliche Information Ebene-2-Weiterleitungs-Information umfasst.
- 4Method according to claim 2 wherein said additional information comprises higher OSI layer information. Procédé selon la revendication 2 dans lequel lesdites informations supplémentaires comprennent des informations de couche OSI plus élevée. Verfahren gemäß Anspruch 2, wobei die zusätzliche Information aus Informationen über höhere OSI-Ebenen besteht.
- 5Method according to any of the previous claims 1 to 4 wherein said at least one layer 2 destination address (MAC2) of said at least one other edge device (ED2) is removed from said communication restriction filter (CRF) of said edge device (ED1) after a predetermined period of time. Procédé selon l'une quelconque des revendications précédentes 1 à 4, dans lequel ladite au moins une adresse de destination de couche 2 (MAC2) dudit au moins un autre dispositif de frontière (ED2) est supprimée dudit filtre de restriction de communications (CRF) dudit dispositif de frontière (ED1) après une période de temps prédéterminée. Verfahren gemäß einem beliebigen der vorherigen Ansprüche 1 bis 4, wobei die mindestens eine Ebene-2-Zieladresse (MAC2) der mindestens einen Netzperipherie-Vorrichtung (ED2) aus dem Kommunikations-Einschränkungs-Filter (CRF) der Netzperipherie-Einrichtung (ED1) nach einer vorher festgelegten Zeitdauer entfernt wird.
- 6Method according to any of the previous claims 1 to 5 wherein said request further comprises user information with respect to the sender of said packet. Procédé selon l'une quelconque des revendications précédentes 1 à 5, dans lequel ladite demande comprend en outre des informations d'utilisateur relatives à l'expéditeur dudit paquet. Verfahren gemäß einem beliebigen der vorherigen Ansprüche 1 bis 5, wobei die Anforderung weiterhin Benutzer-Information bezüglich des Senders des Paketes enthält.
- 7Method according to claim 6 wherein said network management module (NMM) provides said user information to a charging module (CM). Procédé selon la revendication 6, dans lequel ledit module de gestion de réseau (NMM) fournit lesdites informations d'utilisateur à un module de facturation (CM). Verfahren gemäß Anspruch 6, wobei das Netzwerkverwaltungs-Modul (NMM) die Benutzer-Information an ein Abrechnungs-Modul (CM) liefert.
- 8Method according to claim 7 wherein said charging module (CM) provides further charging information with respect to the sender of said packet to said network management module (NMM), which thereupon may proceed with delivering said at least one layer 2 destination address to said edge node (ED1). Procédé selon la revendication 7, dans lequel ledit module de facturation (CM) fournit en outre des informations de facturation relatives à l'expéditeur dudit paquet au dit module de gestion de réseau (NMM), lequel, sur la base de ces informations, peut procéder à la délivrance de ladite au moins une adresse de destination de couche 2 au dit noeud de frontière (ED1). Verfahren gemäß Anspruch 7, wobei das Abrechnungs-Modul (CM) weitere Gebührenerfassungs-Information bezüglich des Paket-Absenders an das Netzwerkverwaltungs-Modul (NMM) liefert, das daraufhin mit der Lieferung der mindestens einen Ebene-2-Zieladresse an den Netzperipherie-Knoten (ED1) fortfahren kann.
- 9Method according to any of the previous claims 1 to 8 wherein, if said at least one layer 2 destination address is not stored within said edge device (ED1), or is not received by said edge device from said network management module (NMM), said edge device (ED1) blocks said incoming packet from further passing through said access network (AN). Procédé selon l'une quelconque des revendications précédentes 1 à 8, dans lequel, si ladite au moins une adresse de destination de couche 2 n'est pas stockée dans ledit dispositif de frontière (ED1), ou n'est pas reçue par ledit dispositif de frontière en provenance dudit module de gestion de réseau (NMM), ledit dispositif de frontière (ED1) empêche ledit paquet arrivant de traverser ledit réseau d'accès (AN). Verfahren gemäß einem beliebigen der obigen Ansprüche 1 bis 8, wobei wenn die mindestens eine Ebene-2-Zieladresse nicht in der Netzperipherie-Vorrichtung (ED1) gespeichert ist oder sie nicht an der Netzperipherie-Vorrichtung vom Netzwerkverwaltungs-Modul (NMM) empfangen wird, die Netzperipherie-Vorrichtung (ED1) verhindert, dass das eintreffende Paket das Zugangsnetzwerk (AN) weiter durchläuft.
- 10Dispositif de frontière (ED1) d'un réseau d'accès (AN), ledit dispositif de frontière (ED1) comprenant un filtre de restriction de communications (CRF) adapté pour stocker au moins une adresse de destination de couche 2 (MAC2) d'au moins un autre dispositif de frontière (ED2) dudit réseau d'accès (AN) caractérisé en ce que ledit dispositif de frontière (ED1) comprend en outre un dispositif de contrôle de communications (CCD) adapté, à l'arrivée d'un paquet comprenant au moins une adresse de destination de couche 2 (MAC2), - pour vérifier si ladite au moins une adresse de destination de couche 2 est déjà stockée dans ledit filtre de restriction de communications (CRF),- pour demander ladite au moins une adresse de destination de couche 2 à un module de gestion de réseau (NMM) en dehors dudit réseau d'accès si ladite au moins une adresse de destination de couche 2 n'est pas stockée dans ledit filtre de restriction de communications (CRF), et- pour fournir en outre ladite au moins une adresse de destination de couche 2 au dit filtre de restriction de communications (CRF). Edge device (ED1) of an access network (AN), said edge device (ED1) including a communication restriction filter (CRF) adapted to store at least one layer 2 destination address (MAC2) of at least one other edge device (ED2) of said access network (AN) characterised in that said edge device (ED1) further includes a communications control device (CCD) adapted, upon the arrival of a packet including at least one layer 2 destination address (MAC2), - to check whether said at least one layer 2 destination address is already stored within said communication restriction filter (CRF),- to request said at least one layer 2 destination address to a network management module (NMM) outside said access network if said at least one layer 2 destination address is not stored within said communication restriction filter (CRF), and- to further provisioning said at least one layer 2 destination address to said communication restriction filter (CRF). Netzperipherie-Vorrichtung (ED1) eines Zugangsnetzwerks (AN), wobei die Netzperipherie-Vorrichtung (ED1) einen Kommunikations-Einschränkungs-Filter (CRF) enthält, der so angepasst ist, dass er mindestens eine Ebene-2-Zieladresse (MAC2) von mindestens einer anderen Netzperipherie-Vorrichtung (ED2) des Zugangsnetzwerks (AN) speichert, dadurch gekennzeichnet, dass die Netzperipherie-Vorrichtung (ED1) weiterhin eine Kommunikations-Steuerungs-Vorrichtung (CCD) enthält, die so angepasst ist, dass sie bei Eintreffen eines Paketes, das mindestens eine Ebene-2-Zieladresse (MAC2) enthält, - überprüft, ob die mindestens eine Ebene-2-Zieladresse bereits in dem Kommunikations-Einschränkungs-Filter (CRF) gespeichert ist,- eine Anforderung der mindestens einen Ebene-2-Zieladresse an ein Netzwerkverwaltungs-Modul (NMM) außerhalb des Zugangsnetzwerks sendet, wenn die mindestens eine Ebene-2-Zieladresse nicht in dem Kommunikations-Einschränkungs-Filter (CRF) gespeichert ist, und- die mindestens eine Ebene-2-Zieladresse weiter an den Kommunikations-Einschränkungs-Filter (CRF) liefert.
- 11Dispositif de frontière (ED1) selon la revendication 10, dans lequel ledit filtre de restriction de communications (CRF) est capable de stocker des informations supplémentaires associées à ladite au moins une adresse de destination de couche 2. Edge device (ED1) according to claim 10 wherein said communications restriction filter (CRF) is able to store additional information associated to said at least one layer 2 destination address. Netzperipherie-Vorrichtung (ED1) gemäß Anspruch 10, wobei der Kommunikations-Einschränkungs-Filter (CRF) in der Lage ist, zusätzliche mit der mindestens einen Ebene-2-Zieladresse verbundene Informationen zu speichern.
- 12Dispositif de frontière (ED1) selon la revendication 11, dans lequel lesdites informations supplémentaires comprennent des informations de destination de couche 2, des informations de routage ou d'autres informations de couche physique. Edge device (ED1) according to claim 11 wherein said additional information comprises layer 2 destination information, routing information or further physical layer information. Netzperipherie-Vorrichtung (ED1) gemäß Anspruch 11, wobei die zusätzlichen Informationen Ebene-2-Ziel-Information, Leitweglenkungs-Information oder weitere Informationen über die physikalische Ebene umfassen.
- 13Dispositif de frontière (ED1) selon l'une quelconque des revendications précédentes 10 à 12, dans lequel ledit filtre de restriction de communications (CRF) est adapté pour supprimer ladite au moins une adresse de destination de couche 2 après une période de temps prédéterminée. Edge device (ED1) according to any of the previous claims 10 to 12 wherein said communication restriction filter (CRF) is adapted to remove said at least one layer 2 destination address after a predetermined period of time. Netzperipherie-Vorrichtung (ED1) gemäß einem beliebigen der obigen Ansprüche 10 bis 12, wobei der Kommunikations-Einschränkungs-Filter (CRF) so angepasst ist, die mindestens eine Ebene-2-Zieladresse nach einer vorher festgelegten Zeitdauer zu entfernen.
- 14Dispositif de frontière (ED1) selon l'une quelconque des revendications précédentes 10 à 13, dans lequel ledit dispositif de contrôle de communication (CCD) est en outre adapté pour insérer dans ladite demande des informations d'utilisateur relatives à l'expéditeur dudit paquet. Edge device (ED1) according to any of the previous claims 10 to 13 wherein said communication control device (CCD) is further adapted to insert user information with respect to the sender of said packet, in said request. Netzperipherie-Vorrichtung (ED1) gemäß einem beliebigen der obigen Ansprüche 10 bis 13, wobei die Kommunikations-Steuerungs-Vorrichtung (CCD) weiterhin so angepasst ist, Benutzer-Informationen bezüglich des Absenders des Paketes in die Anforderung einzufügen.
- 15Dispositif de frontière (ED1) selon l'une quelconque des revendications précédentes 10 à 14, dans lequel ledit dispositif de contrôle de communication (CCD) est en outre adapté pour empêcher que ledit paquet arrivant ne traverse ledit réseau d'accès, si ladite au moins une adresse de destination de couche 2 n'est pas stockée dans ledit filtre de restriction de communications (CRF) ou n'est pas reçue dudit module de gestion de réseau (NMM). Edge device (ED1) according to any of the previous claims 10 to 14 wherein said communication control device (CCD) is further adapted to block said incoming packet from further passing within said access network, if said at least one layer 2 destination address is not stored in said communications restriction filter (CRF) or not received from said network management module (NMM). Netzperipherie-Vorrichtung (ED1) gemäß einem beliebigen der obigen Ansprüche 10 bis 14, wobei die Kommunikations-Steuerungs-Vorrichtung (CCD) weiterhin so angepasst ist, die Weitergabe des eintreffenden Paketes im Zugangsnetzwerk zu blockieren, wenn die mindestens eine Ebene-2-Zieladresse nicht im Kommunikations-Einschränkungs-Filter (CRF) gespeichert ist oder nicht von dem Netzwerkverwaltungs-Modul (NMM) empfangen wird.
- 16Communications restriction module (CRM) of a network management module (NMM) for an access network (AN), adapted to obtain from a memory device (M1) of said network management module (NMM) at least one layer 2 destination address (MAC2), for delivery to an edge device (ED1) of said access network (AN), characterised in that said communications restriction module (CRM) is further adapted to only deliver said at least one layer 2 destination address (MAC2) to said edge device (ED1), upon receipt of a request from said edge device (ED1) and upon retrieving said at least one layer 2 destination address within said request from said edge device (ED1). Kommunikations-Einschränkungs-Modul (CRM) eines Netzwerkverwaltungs-Moduls (NMM) für ein Zugangsnetzwerk (AN), das so angepasst ist, von einer Speichervorrichtung (M1) des Netzwerkverwaltungs-Moduls (NMM) mindestens eine Ebene-2-Zieladresse (MAC2) zu erhalten, um sie an eine Netzperipherie-Vorrichtung (ED1) des Zugangsnetzwerks (AN) zu liefern, dadurch gekennzeichnet, dass das Kommunikations-Einschränkungs-Modul (CRM) weiterhin so angepasst ist, die Ebene-2-Zieladresse (MAC2) nur an die Netzperipherie-Vorrichtung (ED1) zu liefern, wenn eine Anforderung von der Netzperipherie-Vorrichtung (ED1) empfangen wird und wenn die mindestens eine Ebene-2-Zieladresse in der Anforderung von der Netzperipherie-Vorrichtung (ED1) abgerufen wird. Module de restriction de communications (CRM) d'un module de gestion de réseau (NMM) pour un réseau d'accès (AN), adapté pour obtenir d'un dispositif de mémoire (M1) dudit module de gestion de réseau (NMM) au moins une adresse de destination de couche 2 (MAC2), à des fins de délivrance à un dispositif de frontière (ED1) dudit réseau d'accès (AN), caractérisé en ce que ledit module de restriction de communications (CRM) est en outre adapté pour délivrer ladite au moins une adresse de destination de couche 2 (MAC2) au dit dispositif de frontière (ED1) uniquement lors de la réception d'une demande provenant dudit dispositif de frontière (ED1) et lors de la récupération de ladite au moins une adresse de destination de couche 2 dans ladite demande provenant dudit dispositif de frontière (ED1).
- 17Communications restriction module (CRM) according to claim 16, being further adapted to retrieve and to provide additional information associated to said at least one layer 2 destination address (MAC2) in addition to said at least one layer 2 destination address (MAC2) to said edge device (ED1) . Kommunikations-Einschränkungs-Modul (CRM) gemäß Anspruch 16, das weiterhin so angepasst ist, zusätzlich zu der mindestens einen Ebene-2-Zieladresse (MAC2) zusätzliche Informationen, die mit der mindestens einer Ebene-2-Zieladresse (MAC2) verbunden sind, abzurufen und an die Netzperipherie-Vorrichtung (ED1) zu liefern. Module de restriction de communications (CRM) selon la revendication 16, étant en outre adapté pour retrouver et fournir au dit dispositif de frontière (ED1) des informations supplémentaires associées à ladite au moins une adresse de destination de couche 2 (MAC2) en plus de ladite au moins une adresse de destination de couche 2 (MAC2).
- 18Communications restriction module (CRM) according to claim 17, being further adapted to obtain additional layer 2 destination information from another memory means (VLANM) of said network management module (NMM) and to provide said additional layer 2 destination information to said edge device (ED1). Kommunikations-Einschränkungs-Modul (CRM) gemäß Anspruch 17, das weiterhin so angepasst ist, zusätzliche Ebene-2-Ziel-Informationen aus anderen Speicher-Mitteln (VLANM) des Netzwerkverwaltungs-Moduls (NMM) zu erhalten und die zusätzlichen Ebene-2-Ziel-Informationen an die Netzperipherie-Vorrichtung (ED1) zu liefern. Module de restriction de communications (CRM) selon la revendication 17, étant en outre adapté pour obtenir des informations supplémentaires de destination de couche 2 d'autres moyens de mémoire (VLANM) dudit module de gestion de réseau (NMM) et pour fournir lesdites informations supplémentaires de destination de couche 2 au dit dispositif de frontière (ED1).
- 19Communications restriction module (CRM) according to claim 17, being further adapted to obtain higher OSI layer information pertaining to said at least one layer 2 destination address (MAC2) from an aggregation resource platform module (ARP) and to provide said higher OSI layer information to said edge device (ED1). Kommunikations-Einschränkungs-Modul (CRM) gemäß Anspruch 17, das weiterhin so angepasst ist, Informationen über höhere OSI-Ebenen, welche die mindestens eine Ebene-2-Zieladresse (MAC2) betreffen, von einem Zusammenfassungs-Ressourcen-Plattform-Modul (Aggregation Resource Platform, ARP) zu erhalten und die Informationen über höhere OSI-Ebenen an die Netzperipherie-Vorrichtung (ED1) zu liefern. Module de restriction de communications (CRM) selon la revendication 17, étant en outre adapté pour obtenir des informations de couche OSI plus élevée se rapportant à ladite au moins une adresse de destination de couche 2 (MAC2) d'un module de plate-forme de ressource d'agrégation (ARP) et pour fournir lesdites informations de couche OSI plus élevée au dit dispositif de frontière (ED1).
- 20Communications restriction module (CRM) according to any of the previous claims 16 to 19, being further adapted to extract from said request from said edge device (ED1) additional user information, for further provisioning to a charging module (CM). Kommunikations-Einschränkungs-Modul (CRM) gemäß einem beliebigen der obigen Ansprüche 16 bis 19, das weiterhin so angepasst ist, zusätzliche Benutzer-Informationen aus der Anforderung von der Netzperipherie-Vorrichtung (ED1) zu entnehmen, um sie weiterhin zu einem Abrechnungs-Modul (CM) zu liefern. Module de restriction de communications (CRM) selon l'une quelconque des revendications précédentes 16 à 19, étant en outre adapté pour extraire de ladite demande provenant dudit dispositif de frontière (ED1) des informations d'utilisateur supplémentaires afin de les fournir ensuite à un module de facturation (CM).
- 21Communications restriction module (CRM) according to claim 20, being further adapted to receive from said charging module (CM) user billing information, on the basis of which said communications restriction module (CRM) is adapted to provide said at least one layer 2 destination address even when said at least one layer 2 destination address could not be retrieved from said memory device (M1). Kommunikations-Einschränkungs-Modul (CRM) gemäß Anspruch 20, das weiterhin so angepasst ist, von dem Abrechnungs-Modul (CM) Benutzer-Rechnungserstellungs-Informationen zu empfangen, wobei das Kommunikations-Einschränkungs-Modul (CRM) so angepasst ist, auf deren Basis die mindestens eine Ebene-2-Adresse zu liefern, sogar wenn die mindestens eine Ebene-2-Adresse nicht aus der Speichervorrichtung (M1) abgerufen werden konnte. Module de restriction de communications (CRM) selon la revendication 20, étant en outre adapté pour recevoir dudit module de facturation (CM) des informations de facturation d'utilisateur, sur la base desquelles ledit module de restriction de communications (CRM) est adapté pour fournir ladite au moins une adresse de destination de couche 2 même lorsque ladite au moins une adresse de destination de couche 2 ne pouvait pas être récupérée du dispositif de mémoire (M1).
Independent claims21
29 paragraphs, as filed
The present invention relates to method for communications control from an edge device of an access network, via the provisioning or the non-provisioning of at least one layer 2 destination address of at least one other edge node of this access network, to this edge device as is further described in the preamble of claim 1.
Such a method is already known in the art, e.g. by using pre-configured filters in access multiplexers of Ethernet access networks, wherein the allowed MAC-addresses of outgoing edge nodes are stored in these filters. The prior art method and system either use a pre-configured filter in the edge nodes themselves, or use a more centralised push-mechanism from where a central control server in the network management module provides each of the edge-nodes with their pre-configured lists of allowed network devices with which they may communicate.
In some access networks, for instance connectionless aggregation networks such as Ethernet access networks, failures or reconfigurations in this network after such failures are not known to the edge nodes. This means that, if a network failure takes place, and another MAC address is associated with the same layer 3 address of the other edge node, this information is not available to the filters in the ingress edge node. The existing push mechanisms which centrally keep track of these changes but only provide this information to the edge nodes from time to time are not dynamic enough to quickly signal the changes to the edge nodes such as the access multiplexers. The other mechanism whereby the filters in the edge nodes are preconfigured at start up does not provide a solution at all since with this method the changes are never known during the operation of edge devices such as the access multiplexers.
An object of the present invention is thus to provide a method for communications control from an edge device of an access network of the above known kind, but which is dynamic enough to adapt to changes in the layer 2 destination addresses due to unforeseen circumstances such as for instance network failures.
According to the invention, this object is achieved by the fact that these layer 2 destination addresses are only delivered upon request of the edge device itself, as is further stated in the characteristic part of claim 1 .
In this way, since the centralised network management module keeps track of the changes with respect to the allowed layer 2 destination addresses of edge devices within the access network, each time a request from an edge device is received with respect to such a communication to another edge device, the network management module performs an updated check and may send the latest known information to the edge node which accordingly has the up-to-date information available for its further communications.
Furthermore, the request is generated in the edge node upon arrival of a packet including the layer 2 destination address of the destination edge node in the access network, and upon checking whether this layer 2 destination address is not yet stored within a communications restriction filter in the edge node. This ensures that, for not yet locally stored destinations, always the latest information is obtained from the network management module.
It is to be noted that the US Patent US-A-5 968 176 by SHERER William Paul et al (19 October 1999) discloses a multilayer firewall system that provides for establishing security in a network that include nodes having security functions operating in multiple protocol layers. Therein is disclosed a method for control of communications from an edge device or node of an access network (column 3, lines 20-40), via provisioning or the non-provisioning of at least one layer 2 destination address of at least one other edge device of the access network to the edge device by a network management module of the access network (column 4, lines 21-26; column 5, line 4) as in the present invention. However, this known document doesn't disclose nor teach that, upon arrival of a packet including at least one layer 2 destination address, the edge device checks whether this layer 2 destination address is already stored within a communications restriction filter of the edge device and generates a request including this layer 2 destination address only in case this one layer 2 destination address is not yet stored within the communication restriction filter.
It is further to be noted that the International Patent Application WO-00 52575-A of "PACKET TECHNOLOGIES LTD" by DANIELY GAD (8 September 2000) also discloses a system for local, distributed security for a computer (22) connected to a network (42). The network (42) transmits packets to and from the computer (22). The system includes a local security device (20) for connecting the computer (22) to the network (42) and for examining each packet to determine whether the packet is received by the computer (22) according to one or more rules. Here again, even if the method disclosed in this other known document may be compared to the method for control of communications from an edge device or node of an access network as mentioned in the preamble of the present claim 1, this other known document also doesn't disclose nor teach that, upon arrival of a packet including at least one layer 2 destination address, the edge device checks whether this layer 2 destination address is already stored within a communications restriction filter of the edge device and generates a request including this layer 2 destination address only in case this one layer 2 destination address is not yet stored within the communication restriction filter. Moreover, this other known document doesn't mention anything about destination allowance as described above. Yet another characteristic feature of the present invention is described in claim 2.
This is extremely interesting in case of network failures where not only it will be known whether a desired MAC address can still be used or not for a destination, but by providing additional layer 2 forwarding information such as a VLAN tag, possibilities for service mapping and class of service segregation are provided. Furthermore by providing higher OSI layer information such as OSI layer 3 or OSI layer 4 information possibilities for protocol and application control can be provided. For example protocols and applications that are using a certain TPC port can be allowed or blocked. With these OSI layers reference is made to the well-known 7-layer OSI model in data communications of which layer 1 represents the physical layer, layer 2 the data layer, layer 3 the network layer, layer 4 the transport layer, layer 5 the session layer, layer 6 the presentation layer and layer 7 the application layer.
Still a further characteristic feature of the present invention is described in claim 5.
Thereby, ageing is introduced to the filters within the edge nodes which keep the allowed MAC addresses. This ensures again that on a regular basis the latest information is stored within the filters ensuring a dynamic communications control.
Yet a further characteristic feature of the present invention is described in claim 6.
By having the request containing additional user information with respect to the sender of the packet, possibilities for charging are opened, as is also stated in claim 7. This further allows the control of user-to-user communications within the access network itself, which are in general not allowed under normal operating conditions, since these are normally not stored within the network management module. By yet providing the possibility to deliver such MAC addresses upon consulting the charging device, as stated in claim 8, such user-to-user communications within the access network become now possible.
Claim 9 further states that the further passage of an incoming packet through the access network is blocked in case the layer 2 destination address, for instance the MAC address of that packet, is not stored within the edge device or not received by said edge device from the network management module.
The present invention also relates to an edge node and a communications restrictions module of a network management module which are able to perform the above described method, as respectively claimed in claims 10-15 and 16-21.
The above mentioned and other objects and features of the invention will become more apparent and the invention itself will be best understood by referring to the following description of an embodiment taken in conjunction with the accompanying drawings in which <ul id="ul0001" list-style="none" compact="compact"><li>Fig. 1 gives an overview picture of an access network AN with several edge devices, internal switches , a network management module, and other neighbouring networks in which a communication is desired from edge device ED 1 to edge device ED 2, and</li><li>Fig. 2 shows details of edge device ED 1 and the network management module NMM for performing the method according to the invention.</li></ul>
The present invention relates to a method for controlling and restricting communications to allowed edge devices in an access network. Such an access network, preferably a connectionless aggregation network such as an Ethernet access network, is depicted in Fig. 1. This figures shows 4 edge devices ED1 to ED4 of this network AN, of which ED1 and ED2 are access multiplexers for aggregation of traffic from several users which are depicted by the small houses coupled to these access multiplexers. Other edge devices such as ED3 and ED4 comprise interface devices with one or more service provider networks e.g. ED3 provides an interface to network service providers NSP B and NSP C, and ED4 provides an interface to network service provider NSP A.
Access networks are in general managed by a network management module which is depicted on Fig. 1 by block NMM. In general the task of such a network management module is to configure the access network by allocating bandwidths, charging, and user management possibilities. For the present invention one particular aspect of the network management is important, being its memory M1 for storing a list of allowed layer 2 addresses for corresponding allowed destination edge devices, for each edge device to which packets are entering the access network.
Looking more into detail to this network management module on Fig. 2, one can observe that, apart from this memory M1 where these lists for all allowed edge destination nodes and their corresponding layer 2 destination addresses are stored, the network management module includes a communications restriction module (CRM) which is able to retrieve from the memory M1 these layer 2 destination addresses, and delivers them to an edge node , for instance ED1, but only after having received a request from ED1 with respect to this particular destination address. To this purpose edge device ED1 includes a communications control device CDD which generates these requests. In some embodiments these requests are always generated upon arrival of a packet. In a preferred embodiment of the invention these requests are only generated upon arrival of a packet including this layer 2 destination address , and only after checking within said edge device (ED1) that this layer 2 destination address is not stored yet within a communications restriction filter (CRF) therein. This check is indicated in Fig. 2 by a first communication arrow from the CCD to the CFR with the message "MAC2?" , indicating that CCD informs whether MAC2 is present within CFR. The answer of CFR to CDD is indicated by the arrow from CRF to CCD with the message "noMAC2", indicating that this layer 2 destination address is not yet stored within the communications restriction filter. It may be remarked that, upon initialisation of the edge device, the filter may be preconfigured with some predetermined allowed addresses, or be empty.
If the communications control device CDD has thus not found this layer 2 destination address within this filter, it generates the request including this desired layer 2 destination address and forwards this to the communications restrictions module (CRM) in the network management module (NMM). This is schematically depicted by the arrow with the message "req MAC2". Upon receipt of this request, the CRM checks in the memory device M1 whether ED1 is allowed to forward packets to layer 2 destination address MAC2. This is represented by the arrow with the message schematically denoted "MAC2/ED1?" from CRM to M1 .If this address is contained within the list of M1 for device ED1, this is retrieved from M1 to CRM, and represented by the arrow back from M1 to CRM denoted "MAC2". This information is subsequently passed to the communications control device CDD of the edge node ED1 which subsequently forwards this address MAC2 to the communications restriction filter CRF, as denoted by the arrow from CCD to CRF with the message "MAC2". It is stored there for a predetermined time, for instance 120 seconds. After this time has elapsed, this entry is again removed from the filter CRF. This allows to regularly request whether layer 2 destination addresses are still allowed such as to also become regularly updated of the changes. Other possibilities for having a very dynamic mechanism comprise requesting the communications restriction module each time a new packet arrives. Then each time such a packet arrives the filter is updated, independent on whether the layer 2 destination address is already present in the filter or not. For these implementations even a filter may be omitted from the edge devices. This type of solution however requires extra communication time between the edge node and the network management module.
In the case the requested address MAC 2 is not allowed for communications from ED1, the communications restriction module CRM will thus not find this address in M1, and accordingly cannot send this address back to ED1. This address can thus also not be stored within the communication restriction filter, such that the communications control device CCD, upon receiving an incoming packet with this layer 2 address as destination, will then block this packet from entry within the access network.
In case a failure has occurred in the destination edge node ED2 of which MAC2 was a layer 2 address of one port, a new port with a new MAC address will be used. The network management module, via an ARP module therein, transfers this up-to-date information to M1, either directly or via the CRM. ARP is the abbreviation of Address Resolution Protocol, which is an existing mechanism that takes care of the distribution of the updated addresses. This is however beyond the scope of this patent, and more information about this mechanism can be found in specialised literature.
Fig. 2 shows this mechanism via an arrow denoted MAC20 between ARP and M1. The sender of the packet is also informed, using the ARP mechanism that another port having for instance layer 2 address MAC20, has to be used. M1 now contains for ED1 an updated list wherein MAC2 is omitted and instead MAC20 is added. The sender of the packet, now informed to use MAC20, inserts this new layer 2 address in the header of its packet. If CRM subsequently asks M1 whether MAC20 is allowed for ED1, M1 will provide the info that indeed this MAC20 is allowed.
Address MAC 20 is subsequently provided by CRM to CCD, which subsequently stores this information within CRF. Accordingly, if new packets will then arrive in CCD having MAC20 in their header, CCD will then get from CRF the information that MAC20 is allowed.
In addition to the retrieval of allowed layer2 destination addresses such as MAC addresses in Ethernet networks, the CRM can further get from another memory denoted VLANM in NMM additional layer 2 forwarding information such as a VLAN tag. VLAN is the abbreviation of virtual local area network and has the advantage to provide increased performance and manageability, physical topology independence and increased security. The above mentioned advantages can be used in the above described scenario for service segregation in the access network.
It is also possible that CRM gets from another memory, for instance M3 in Fig. 2, layer 3 or higher layer associated with the allowed layer 2 MAC addresses. The higher layer information is useful when certain protocols or applications have to be restricted.
CRM may be implemented as a communications restriction software agent in the network management module or as a hardware module.
In some embodiments of the method and of the edge device , the communications control device CDD of the edge node may also be able to insert, within the generated requests, user information with respect to the user which has sent the packet. This user information may comprise physical layer information such as for instance the line of the access multiplexer to which the user is connected. This user information is thus further passed through in the request to the CRM of the network management module. The latter extracts this user information from the request , and may provide this to a charging module CM. CM may accordingly respond by providing some charging information to CRM. This information is useful in case the desired layer 2 address is not stored within M1. This happens for instance for user-to-user communications within the access network itself, which are normally not allowed by the network management, since these cannot normally be charged. Using the present mechanism however, where the CRM consults the charging module CM upon receipt of such a request, the charging module becomes aware of this kind of communications, such that it can charge for it. CM can then further provide this information to CRM which can use this information to decide to allow the requested layer 2 address, thus by providing this address in response to a request including this layer 2 address from the ED1. While the principles of the invention have been described above in connection with specific apparatus, it is to be clearly understood that this description is made only by way of example and not as a limitation on the scope of the invention.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| WO0052575A | Cites | World Intellectual Property Organization (WIPO) |
| US5479642A | Cites | United States of America |
| US5968176A | Cites | United States of America |
| US2001054101A1 | Cites | United States of America |
10 members in 5 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 03292316 | European Patent Office (EPO) | A | |
| EP20030292316 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| EP1517473A1 | European Patent Office (EPO) | A1 | |
| US2005063384A1 | United States of America | A1 | |
| CN1601962A | China | A | |
| EP1517473B1This record | European Patent Office (EPO) | B1 | |
| AT347211T | Austria | T | |
| ATE347211T1 | Austria | T1 | |
| DE60310074D1 | Germany | D1 | |
| DE60310074T2 | Germany | T2 | |
| CN100525189C | China | C | |
| US7701879B2 | United States of America | B2 |
66 legal events, as 6 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04L0012240000R079 | R079 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20190829 AND 20190904732E | 732E | GB | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of representativeR082 | R082 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Change of addressCA | CA | FR | |
| Change of addressCA | CA | FR | |
| Lien (pledge) constitutedGC | GC | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Fr: translation filedET | ET | EP | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Party data changed (patent owner data changed or rights of a patent transferred)RAP2 | RAP2 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Designation fees paidAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1517473
- Publication, DOCDB
- 1517473
- Publication, EPODOC
- EP1517473
- Application
- 3292316
- Application, DOCDB
- 03292316
- Application, EPODOC
- EP20030292316
Titles3
- German
- Verfahren zur Steuerung von Nachrichten in einer Netzperipherie-Vorrichtung eines Zugangsnetzwerks und Netzperipherie-Vorrichtung und Netzwerkverwaltungs-Vorrichtung zur Ausführung dieses Verfahrens
- English
- Method for control of communications from an edge device of an access network and edge device and network management module for performing said method
- French
- Procédé de contrôle de communications dans un dispositif de frontière d'un réseau d'accès et dispositif de frontière d'un réseau et module de gestion de réseau pour la mise en oeuvre de ce procédé
Classification
- CPC, 10
- H04L41/082
- H04L12/4625
- H04L12/4641
- H04L29/12018
- H04L45/742
- H04L41/00
- H04L61/10
- H04L63/02
- H04L63/0272
- H04L63/101
- IPC, 5
- H04L12 24
- H04L12 46
- G06F1 00
- H04L29 06
- H04L29 12
Designated states27
- Contracting states, 27
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Romania
- Sweden
and 3 moreShow fewer
- Slovenia
- Slovakia
- Türkiye
