IP Library Granted Patent US 8,225,389
Granted Patent B2
US 8,225,389 · App. 10/646,976 · Granted Jul 17, 2012

Method and system to provide physical port security in a digital communication system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,225,389
App. No.
10/646,976
Granted
Jul 17, 2012
Kind
B2
Abstract

A method and system of providing physical port security in a digital data network is disclosed. The system keeps bit maps of allowed physical output ports for each physical network connection. The map of allowed ports can be different for different source addresses connected to the device. When digital data, such as an IP packet, is received, the appropriate physical port security bit map is retrieved and a logical AND is done on the physical port bit map generated by the destination information. The resulting bit map is used to determine which physical ports the data is routed to, blocking any requested destinations that are not appropriate destinations based on the port security bit map.

Claims (41)

1. A method of providing physical port security in a digital communication system, comprising:

receiving a frame of digital data at a network device;

generating a destination port bit map based on the destination address information contained in said frame of digital data;

generating a physical port security bit map of allowed destination ports, wherein said physical port security bit map is generated based at least in part on information in said received frame of digital data;

comparing, using at least one logical operation, said destination port bit map with said physical port security bit map to generate a bit map of allowed destination ports; and

forwarding said frame of digital data to one or more of said allowed destination ports.

2. The method of claim 1 , wherein said comparing comprises conducting a logical AND on said destination port bit map and physical port security bit map.

3. The method of claim 1 , comprising generating said physical port security bit map using source address information contained in said digital data frame.

4. The method of claim 1 , comprising generating said physical port security bit map using destination address information contained in said digital data frame.

5. The method of claim 1 , comprising generating said physical port security bit map using a combination of source and destination address information contained in said digital data frame.

6. The method of claim 1 , wherein said address information comprises IP address information.

7. The method of claim 1 , wherein said frame of digital data is received by a router.

8. The method of claim 1 , wherein said frame of digital data is received by a network file server.

9. The method of claim 1 , wherein said network device comprises one or more physical ports connected to a local area network.

10. The method of claim 1 , wherein said received frame of digital data is received from a process that is inside of said network device.

11. The method of claim 1 , wherein said physical port security bit map is generated dynamically based on a variable parameter.

12. A system for providing physical port security, comprising:

at least one processor within a network device, said network device having a communications port for receiving digital data from a digital communications system and two or more physical data ports for forwarding said digital data, said at least one processor being configured to:

generate a destination port bit map based on destination address information contained in said received digital data;

generate a physical port security bit map of allowed destination ports,

wherein said physical port security bit map is generated based at least in part on information in said received frame of digital data;

compare, using at least one logical operation, said destination port bit map with said physical port security bit map to generate a bit map of allowed destination ports; and

forward said digital data to one or more of said allowed destination ports.

13. The system of claim 12 , wherein said at least one processor is configured to conduct a logical AND operation on said destination port bit map and said physical port security bit map.

14. The system of claim 12 , wherein said physical port security bit map is generated using source address information contained in said digital data.

15. The system of claim 12 , wherein said physical port security bit map is generated using destination address information contained in said digital data.

16. The system of claim 12 , wherein said physical port security bit map is generated from a table of stored allowed physical port addresses that varies depending on a combination of source and destination address information contained in said digital data.

17. The system of claim 12 , wherein said address information comprises IP address information.

18. The system of claim 12 , wherein said network device comprises a router.

19. The system of claim 12 , wherein said network device comprises a network file server.

20. The system of claim 12 , wherein said two or more physical data ports of said network device are connected to a local area network.

21. The system of claim 12 , wherein said digital data comprises IP data.

22. The system of claim 12 , wherein said at least one processor is configured to retrieve said physical port security bit map based on an IP source address contained in said digital data.

23. The system of claim 12 , wherein said network device is the source of said received digital data.

24. The system of claim 12 , wherein said physical port security bit map is dynamically altered based on a variable parameter.

25. A system for providing physical port security, comprising:

means for receiving a frame of digital data at a network device;

means for generating a destination port bit map based on the destination address information contained in said frame of digital data;

means for generating a physical port security bit map of allowed destination ports, wherein said physical port security bit map is generated based at least in part on information in said received frame of digital data;

means for comparing, using at least one logical operation, said destination port bit map with said physical port security bit map to generate a bit map of allowed destination ports; and

means for forwarding said frame of digital data to one or more of said allowed destination ports.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF MERGER TO 09/05/2018 PREVIOUSLY RECORDED AT REEL: 047230 FRAME: 0133. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047630/0456 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047230/0133 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2003
From: LUND, MARTIN
To: BROADCOM CORPORATION
Reel/Frame 014429/0839 →