EP2640008B1

Personal virtual bridged local area networks

Abstract

This record has no abstract on file.

EP2640008B1, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Expired 1 February 2022, 4.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

7 claims: 1 independent, 6 dependent

  1. 1
    A method for segregating traffic amongst a plurality of stations that are associated with an access point, comprising the steps of:providing a protocol for virtual local area network (VLAN) discovery;allowing a station to create via a personal VLAN bridge a new port that serves a new VLAN, or to join an existing VLAN;maintaining more than one logical port per physical port;and providing cryptographic VLAN separation, wherein traffic within one VLAN is separated from another VLAN on a same physical port by cryptography, and comprising the steps of: providing for every port a personal VLAN control channel for sending and receiving control frames and authentication protocol frames;if a creator of a VLAN can authenticate a requester, then said creator sharing a security association it holds with said requester as well;if a received frame carries a null virtual LAN ID (VID) or is untagged, then using its source MAC address to determine a preliminary VLAN classification of a logical port;if said frame carries a VID, then using said VID as said preliminary classification instead;using said preliminary classification to index into a table of security associations giving an authentication code key;said received frame carrying an authentication code computed over a frame payload using a message digest algorithm agreed upon by both said personal VLAN bridge and said requester at authentication time and having been recorded in said security association;said personal VLAN bridge re-computing said authentication code, using said authentication code key, over said payload of said received frame;comparing said re-computed authentication code with said received authentication code;wherein if said re-computed authentication code and said received authentication code match, then said preliminary VLAN classification becomes a final VLAN classification;using said final classification as a value of a VLAN classification parameter of any corresponding data request primitives;decrypting said frame using said security association;and submitting said decrypted frame to a forwarding and learning process;otherwise, discarding said frame.