IP Library Granted Patent US 8,000,344
Granted Patent B1
US 8,000,344 · App. 11/313,187 · Granted Aug 16, 2011

Methods, systems, and computer program products for transmitting and receiving layer 2 frames associated with different virtual local area networks (VLANs) over a secure layer 2 broadcast transport network

Assignee: Extreme Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,000,344
App. No.
11/313,187
Granted
Aug 16, 2011
Kind
B1
Abstract

Methods, systems, and computer program products for sending and receiving frames associated with different VLANs over a secure layer 2 broadcast transport network are disclosed. According to one method, a layer 2 frame is received at a transmit port of a layer 2 forwarding device. The layer 2 frame is to be sent over a secure layer 2 broadcast transport network. A VLAN identifier corresponding to a first VLAN is extracted from the layer 2 frame. The first VLAN identifier is mapped to a second VLAN identifier used by the secure broadcast transport layer 2 network to identify the first VLAN. A portion of the layer 2 frame including the first VLAN identifier is encrypted. The layer 2 frame is transmitted over the secure layer 2 broadcast transport network with the second VLAN identifier in a cleartext portion of the frame.

Claims (32)

1. A method for transmitting a layer 2 frame over a secure layer 2 broadcast transport network, the method comprising:

(a) receiving, at a transmit port of a layer 2 forwarding device, a layer 2 frame to be sent over a secure layer 2 broadcast transport network, the layer 2 frame including a first VLAN identifier used to identify a first VLAN;

(b) mapping the first VLAN identifier to a second VLAN identifier used by the secure layer 2 broadcast transport network to identify the first VLAN and to limit the layer 2 broadcast domain of the layer 2 frame in the layer 2 broadcast transport network to the first VLAN;

(c) encrypting a portion of the layer 2 frame including the first VLAN identifier and inserting the second VLAN identifier in an unencrypted portion of the layer 2 frame; and

(d) transmitting the layer 2 frame over the secure layer 2 broadcast transport network.

2. The method of claim 1 wherein the secure layer 2 broadcast transport network comprises a service network, the sending site comprises a customer network, the first VLAN identifier comprises a customer VLAN tag inserted by the customer network, and the second VLAN identifier comprises a service VLAN identifier.

3. The method of claim 2 wherein the customer network and the service network are under a common administrative domain.

4. The method of claim 2 wherein the customer network and the service network are under different administrative domains.

5. The method of claim 1 wherein encrypting a portion of the layer 2 frame includes encrypting the portion of the layer 2 frame prior to the mapping of the first VLAN identifier to the second VLAN identifier.

6. The method of claim 1 wherein encrypting a portion of the layer 2 frame includes encrypting the portion of the layer 2 frame simultaneously with the mapping of the first VLAN identifier to the second VLAN identifier.

7. The method of claim 1 wherein encrypting a portion of the layer 2 frame includes encrypting the portion after the mapping of the first VLAN identifier to the second VLAN identifier.

8. The method of claim 1 wherein transmitting the layer 2 frame over the secure layer 2 broadcast transport network includes using the second VLAN identifier to restrict a broadcast domain of the layer 2 frame in the secure layer 2 broadcast transport network.

9. The method of claim 1 wherein transmitting the layer 2 frame over a secure layer 2 broadcast transport network includes transmitting the secure layer 2 frame over a metro Ethernet network.

10. The method of claim 1 comprising, at a receiving site, decrypting the layer 2 frame and forwarding the layer 2 to the first VLAN using the first VLAN identifier.

11. The method of claim 1 comprising, at a receiving site, decrypting the layer 2 frame, replacing the first VLAN identifier with a third VLAN identifier used by the receiving site to identify the first VLAN, and forwarding the layer 2 frame to nodes associated with the first VLAN.

12. The method of claim 11 wherein the first VLAN identifier corresponds to a first customer VLAN of a first customer network, wherein the receiving site comprises a second customer network, and wherein the third VLAN identifier corresponds to a second customer VLAN of the second customer network.

13. A system for transmitting frames associated with different VLANs over a secure layer 2 broadcast network, the system comprising:

(a) a layer 2 frame encryption module for receiving a layer 2 frame to be transmitted over a secure layer 2 broadcast transport network and for encrypting a portion of the layer 2 frame including a first VLAN identifier associated with a first VLAN;

(b) a service VLAN identifier mapper for mapping the first VLAN identifier to a second VLAN identifier used by the secure layer 2 broadcast transport network to identify the first VLAN and to limit the layer 2 broadcast domain of the first layer 2 frame in the layer 2 broadcast transport network to the first VLAN and for inserting the second VLAN identifier in an unencrypted portion of the layer 2 frame; and

(c) an outbound layer 2 frame transmitter for transmitting the layer 2 frame over the secure layer 2 broadcast transport network.

14. The system of claim 13 wherein the secure layer 2 broadcast transport network comprises a service network, the sending site comprises a customer network, the first VLAN identifier comprises a customer VLAN tag inserted by the customer network, and the second VLAN identifier comprises a service VLAN identifier.

15. The system of claim 14 wherein the customer network and the service network are under a common administrative domain.

16. The system of claim 14 wherein the customer network and the service network are under different administrative domains.

17. The system of claim 13 wherein the layer 2 frame encryption module is adapted to encrypt the portion of the layer 2 frame prior to the mapping of the first VLAN identifier to the second VLAN identifier.

18. The system of claim 13 wherein the layer 2 frame encryption module is adapted to encrypt the portion of the layer 2 frame simultaneously with the mapping of the first VLAN identifier to the second VLAN identifier.

19. The system of claim 13 wherein the layer 2 frame encryption module is adapted to encrypt the portion of the layer 2 frame after the service VLAN transport identifier mapper maps the first VLAN identifier to the second VLAN identifier.

20. The system of claim 13 wherein the outbound layer 2 frame transmitter is adapted to transmit the layer 2 frame over a metro Ethernet.

21. A computer program product comprising computer-executable instructions embodied in a non-transitory computer-readable medium for performing steps comprising:

(a) receiving, at a transmit port of a layer 2 forwarding device, a layer 2 frame to be sent over a secure layer 2 broadcast network, the layer 2 frame including a first VLAN identifier used to identify a first VLAN;

(b) mapping the first VLAN identifier to a second VLAN identifier used by the secure layer 2 broadcast transport network to identify the first VLAN and to limit the layer 2 broadcast domain of the layer 2 frame in the layer 2 broadcast network to the first VLAN;

(c) encrypting a portion of the layer 2 frame and inserting the second VLAN identifier in an unencrypted portion of the layer 2 frame; and

(d) transmitting the layer 2 frame over the secure layer 2 broadcast transport network.

Assignments (10)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
SECURITY AGREEMENT Recorded Jul 27, 2015
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 036189/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2011
From: FRICK, J. KEVIN
To: EXTREME NETWORKS, INC.
Reel/Frame 026233/0930 →