IP Library Granted Patent US 9,294,477
Granted Patent B1
US 9,294,477 · App. 11/417,371 · Granted Mar 22, 2016

Media access control address security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,294,477
App. No.
11/417,371
Granted
Mar 22, 2016
Kind
B1
Abstract

An access interface system for interfacing between an enterprise network and a service provider network comprises an interface and a processing system. The interface is configured to receive traffic from the service provider network wherein the traffic identifies a virtual link and a media access control address, transmit the traffic to the enterprise network if the media access control address is allowed for the virtual link, and block the traffic if the media access control address is not allowed for the virtual link. The processing system is configured to determine if the media access control address is allowed for the virtual link.

Claims (25)

1. A method of operating an access interface system to interface between a local area network and a service provider network, the method comprising:

receiving data traffic transmitted from an originating device over a virtual private network (VPN), wherein the data traffic contains a media access control (MAC) address of a device along a path between the access interface system and the originating device;

determining if the MAC address is associated with the VPN;

transmitting the data traffic to the local area network if the MAC address is associated with the VPN; and

blocking the data traffic from transfer to the local area network if the MAC address is not associated with the VPN.

2. The method of claim 1 wherein determining if the MAC address is associated with the VPN comprises checking the MAC address against an access control list, wherein the access control list identifies the VPN and a group of MAC addresses associated with the VPN.

3. The method of claim 2 wherein the MAC address is associated with the VPN if the MAC address is in the group of MAC addresses associated with the VPN.

4. The method of claim 2 further comprising allowing an operator of the local area network to modify the access control list.

5. The method of claim 1 wherein the data traffic identifies an originating network and wherein the method further comprises if the MAC address is not allowed then providing a notification to the originating network identifying the MAC address.

6. An access interface system to interface between a local area network and a service provider network, the access interface system comprising:

a communication interface configured to receive data traffic transmitted from an originating device over a virtual private network (VPN), wherein the data traffic contains a media access control (MAC) address of a device along a path between the access interface system and the originating device; and

a processing system comprising circuitry configured to determine if the MAC address is associated with the VPN, and if the MAC address is associated with the VPN, direct the communication interface to transmit the data traffic to the local area network, and if the MAC address is not associated with the VPN, direct the communication interface to block the data traffic from transfer to the local area network.

7. The access interface system of claim 6 wherein the processing system configured to determine if the MAC address is associated with the VPN comprises the processing system configured to check the MAC address against an access control list, wherein the access control list identifies the VPN and a group of MAC addresses associated with the VPN.

8. The access interface system of claim 7 wherein the MAC address is associated with the VPN if the MAC address is in the group of MAC addresses associated with the VPN.

9. The access interface system of claim 7 further comprising the processing system configured to allow an operator of the local area network to modify the access control list.

10. The access interface system of claim 6 wherein the data traffic identifies an originating network and wherein if the MAC address is not allowed then the processing system is configured to provide a notification to the originating network identifying the MAC address.

11. A communication system comprising:

a first node coupled to a first network and configured to transfer data traffic for delivery to a second network over a virtual private network (VPN) link provided through a service provider network;

an access interface system configured to receive the data traffic from the service provider network over the VPN link, wherein the data traffic contains a media access control (MAC) address of a device along a path between the access interface system and the first node;

the access interface system configured to process the MAC address to determine if the data traffic is associated with the VPN link; and

the access interface system configured to transfer the data traffic to the second network if the data traffic is associated with the VPN link, and block the data traffic from transfer to the second network if the MAC address is not associated with the VPN link.

12. The communication system of claim 11 wherein the access interface system configured to process the MAC address to determine if the data traffic is associated with the VPN link comprises the access interface system configured to check the MAC address against an access control list, wherein the access control list identifies the VPN and a group of MAC addresses associated with the VPN.

13. The communication system of claim 12 wherein the MAC address is associated with the VPN if the MAC address is in the group of MAC addresses associated with the VPN.

14. The communication system of claim 12 further comprising allowing an operator of the local area network to modify the access control list.

15. The communication system of claim 11 wherein the data traffic identifies an originating network and wherein if the MAC address is not allowed then the access interface system is configured to provide a notification to the originating network identifying the MAC address.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2006
From: BUGENHAGEN, MICHAEL K.
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 017865/0934 →