Nova Patents
EP1556990B1

Bridged cryptographic vlan

Abstract

This record has no abstract on file.

EP1556990B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 30 October 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

23 claims: 2 independent, 21 dependent

  1. 1
    A method for extending VLAN bridging semantics in a bridged, cryptographic VLAN, the method comprising the steps of;providing an untagged frame and a tagged frame in accordance with the IEEE 802.1Q VLAN bridge model;providing a cryptographically encapsulated frame, wherein the encapsulated frame has a VLAN tag that is different from a tag used within tagged frames belonging to said bridged, cryptographic VLAN;providing a trunk port divided into inbound (22) and outbound (14a) trunk ports;providing one of said untagged, tagged, and encapsulated frames for each segment segmenting the bridged, cryptographic VLAN;and transferring traffic between an unencapsulated segment, tagged or untagged, and an encapsulated segment of said VLAN, wherein all frames in the encapsulated segment are encapsulated according to an encryption and authentication code scheme, wherein for said VLAN, there is a unique security association comprising a cryptographic authentication code key for checking integrity and authenticity of frames that are tagged as belonging to said VLAN, and a cryptographic key for ensuring privacy of all frames belonging to said VLAN.
  2. 2
    The method of Claim 1, further comprising the step of:associating with said VLAN two unique VLAN tags, said two unique VLAN tags comprising VID-T, which is used within tagged frames of said VLAN, and VID-E, which is used within encapsulated frames of said VLAN.
  3. 3
    The method of Claim 1, wherein said encapsulated frame is encapsulated in accordance with an encrypt-then-MAC method, which comprises the steps of:encrypting a data payload of a frame;and computing a message authentication code over a resulting ciphertext and said frame's sequence number.
  4. 4
    The method of Claim 1, wherein a tagged set, an untagged set, and an encapsulated set of ports is associated with said VLAN.
  5. 5
    The method of Claim 1, further comprising the step of:using the security association for said VLAN to verify authenticity and integrity of every frame tagged as belonging to said VLAN, and received at a port in said VLAN's encapsulated set.
  6. 6
    The method of Claim 5, further comprising the step of:providing an ingress-filtering rule for said port to determine whether verification occurs.
  7. 7
    The method of Claim 5, further comprising the step of:using said association to encapsulate tagged and untagged frames belonging to said VLAN cryptographically before sending them from a port in said VLAN's encapsulated set.
  8. 16
    An apparatus for sending frames in bridged, cryptographic VLANs, comprising:at least two bridges;a plurality of trunk links wherein every trunk link of said trunk links is associated with the inbound trunk port of one bridge of said at least two bridges and the outbound trunk port of another bridge of said at least two bridges;a plurality of access ports;a plurality of access links wherein every access link of said access links is associated with one access port of said access ports;and means for segmenting said VLANs in different encapsulated segments even though they share a same medium wherein, for each of the encapsulated segments segmenting the VLANs, untagged, tagged, and encapsulated frames are provided, and traffic is transferred between an unencapsulated segment, tagged or untagged, and an encapsulated segment of a VLAN of said VLANs, wherein the frames in the encapsulated segment are encapsulated according to an encryption and authentication code scheme, wherein for said VLAN, there is a unique security association comprising a cryptographic authentication code key for checking integrity and authenticity of frames that are tagged as belonging to said VLAN, and a cryptographic key for ensuring privacy of all frames belonging to said VLAN.