Nova Patents
EP1556990A2

Bridged cryptographic vlan

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 30 October 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

34 claims: 11 independent, 23 dependent

  1. 1
    Claims of equivalent WO 2004042984 A2 CLAIMS 1. A method for extending VLAN bridging semantics, comprising the steps of:providing an untagged frame and a tagged frame in accordance with the IEEE 802.1Q VLAN bridge model;providing a cryptographically encapsulated frame, wherein every encapsulated frame has a VLAN tag that is different from a tag used within tagged frames belonging to said VLAN;providing a trunk port divided into inbound and outbound trunk ports;providing one of said untagged, tagged, and encapsulated frame type for each segment representing a bridged, cryptographic VLAN;and transferring traffic between an unencapsulated segment (tagged or untagged) and an encapsulated segment of a same VLAN.
  2. 9
    An apparatus for sending frames in bridged, cryptographic VLANs, comprising:at least two bridges;a plurality of trunk links wherein every trunk link of said trunk links is associated with the inbound trunk port of one bridge of said at least two bridges and the outbound trunk port of another bridge of said at least two bridges;a plurality of access ports;a plurality of access links wherein every access link of said access links is associated with one access port of said access ports;and means for representing said VLANs by different encapsulated segments even though they share a same medium, wherein physical separation of said VLANs is cryptographic.
  3. 15
    A method for forwarding frames of a forwarding set that is defined with respect to the target port set for a received frame of a VLAN, comprising the steps of:queuing an untagged frame, if any, in said forwarding set, for transmission at every port in said target set that belongs to the untagged set for said VLAN;queuing an VLAN-tagged frame, if any, in said forwarding set, for transmission at every port in said target set that belongs to the tagged set for said VLAN;and queuing an encapsulated frame, if any, in said forwarding set, for transmission at every port in said target set that belongs to the encapsulated set for said VLAN.
  4. 16
    A method for eliminating redundant transfers between LAN segments in a bridged, cryptographic VLAN, comprising the steps of:avoiding transfer of an unencapsulated frame to a VLAN's encapsulated segment more than once in a bridged VLAN where each transfer requires encryption;performing encapsulation once, said encapsulation being shared by all egress ports that belong to said VLAN's encapsulated set across all bridges;and avoiding repeated decapsulation across bridges in said bridged VLAN where each requires decryption.
  5. 17
    A method for determining optimal transfer points between LAN segments representing a bridged, cryptographic VLAN, comprising the steps of:reducing any bridged LAN to a spanning tree whose nodes are said bridges and whose edges are trunk links to induce a partial order on said bridges;wherein a least bridge is the root of said spanning tree;wherein the set of bridges together with a partial order define a complete, partially ordered set;and wherein every nonempty subset of said bridges has a least upper bound;wherein said least upper bound of all bridges requiring a received frame of a VLAN to belong to one of said LAN segments representing said VLAN is an optimal transfer point for converting received frames to frames for that LAN segment;and deducing automatically, from an assignment of bridge access ports in said bridged VLAN to said LAN segments, the smallest set of LAN segments that must be associated with a given outbound trunk port in order to bridge said VLAN.
  6. 18
    An apparatus for implementing a transfer point protocol (TPP) in a bridged, cryptographic VLAN, comprising:at least two bridges;a plurality of trunk links wherein every trunk link of said trunk links is associated with an inbound trunk port of one bridge of said at least two bridges and an outbound trunk port of another bridge of said at least two bridges;a plurality of access ports;a plurality of access links wherein every access link of said access links is associated with one access port of said access ports;and means for representing said VLANs by different encapsulated segments even though they share a same medium, wherein physical separation of said VLANs is cryptographic;two link-layer protocols, a first link-layer protocol (TPP-T) for adding outbound ports to the tagged set of a VLAN, and a second link-layer protocol (TPP-E) for adding outbound ports to the encapsulated set of a VLAN;and wherein every access port is assigned to a tagged, untagged, or encapsulated set for a VLAN prior to execution.
  7. 20
    A transfer point protocol (TPP) in a bridged, cryptographic VLAN, comprising the steps of:a bridge sending a TPP announce frame to a TPP group address through each of its trunk ports for every VLAN known to it;when a bridge receives an announce frame, said bridge appending to received routing path an entry for itself regarding the received VLAN ID, and forwarding said frame to each of its enabled, outbound trunk ports except the receiving trunk port;wherein if said bridge has no other such trunk ports, then said bridge sending a final routing path and said received VLAN ID in a TPP reply frame to the MAC address that precedes said bridge in said routing path;an originating bridge of an announce frame creating a path consisting only of an entry for itself;when a bridge receives a TPP reply frame, said bridge forwarding said reply frame to the bridge MAC address that precedes said bridge in said routing path;and if there is none, discarding said frame.
  8. 24
    A protocol for access link displacement in a bridged, cryptographic VLAN, comprising the steps of:recognizing an access port of a bridge of said bridged VLAN with which a displaced access link can be associated, wherein said access port may be virtual and created automatically;automatically assigning said access port to a LAN segment type based on a segment type of said displaced access link;and executing a transfer port protocol (TPP) for said bridged VLAN with said access port belonging to said assigned LAN segment type.
  9. 25
    A method for establishing a group security association for a cryptographic VLAN comprising m stations, comprising the steps of:providing an encryption key K v, wherein said encryption key is a symmetric key used by v-aware bridges and stations of v to encrypt and decrypt frames belonging to v, providing an authentication code key Kø v, wherein all v-aware bridges, and stations of v, compute and verify authentication codes over encrypted frames of v using Kø v, providing a distribution key Køø v ;and providing m random values R1, R2 Rm, wherein there is one random value for each of said m stations, wherein an ith station of said group knows all m random values except Ri, wherein said m - 1 random values that said ith station knows are communicated to it by a ι -aware bridge;wherein privacy of said random values is ensured by encryption using said distribution key Køø v, while their authenticity is ensured by an authentication code computed over a resulting ciphertext using said authentication code key Kø v.
  10. 26
    A method for joining a cryptographic VLAN, comprising the steps of:adding a new station to a group;and enabling all other stations in said group to eliminate said new station later.
  11. 30
    A method for leaving a cryptographic VLAN, comprising the steps of:detecting with a v-aware bridge a subgroup of stations 1 ,..., k simultaneously leaving a cryptographic VLAN v, said bridge v-aware announcing the departure of said stations 1 / via a single broadcast frame that comprises an authentication code computed over said frame using an authentication code key Kø v, wherein said broadcast notifies every •/-aware bridge and station in group v that stations 1 ,..., /( have left;each such bridge and station then attempting to rekey encryption, authentication code, and distribution keys for v, each as a function of an old key and random values R , ... , Rk, and every v-aware bridge and all remaining stations in groups sharing a new security association as a result, comprising k fewer random values.