IP Library Granted Patent US 7,703,132
Granted Patent B2
US 7,703,132 · App. 11/841,910 · Granted Apr 20, 2010

Bridged cryptographic VLAN

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,703,132
App. No.
11/841,910
Granted
Apr 20, 2010
Kind
B2
Abstract

The invention comprises three extensions of the IEEE 802.1Q VLAN bridge model. The first extension is the cryptographic separation of VLANs over trunk links. A LAN segment type referred to as an encapsulated LAN segment is introduced. All frames on such a segment are encapsulated according to an encryption and authentication code scheme. The second extension is the division of a trunk port into inbound and outbound ports. The third extension is a protocol that automatically infers for each outbound port in a bridged VLAN, a set of LAN segment types for the port that minimizes the number of transfers between encapsulated and unencapsulated segments required to transport a frame in the bridged VLAN.

Claims (21)

1. A method for extending VLAN bridging semantics, comprising the steps of:

providing an untagged frame and a tagged frame in accordance with an IEEE 802.1 Q VLAN bridge model that implements a media access control (MAC) security wherein the untagged frame and the tagged frame are sent between end stations wherein an end station has a processor and a memory;

providing a cryptographically encapsulated frame, which encapsulated frame is a tagged frame, having a VLAN tag that is different from all tags used within unencrypted tagged frames belonging to said VLAN;

providing a trunk port divided into inbound and outbound trunk ports;

providing one of said untagged, tagged, and encapsulated frame type for each segment representing a bridged, cryptographic VLAN wherein each segment implements the MAC security; and

transferring traffic between an cryptographically unencapsulated segment (tagged or untagged) and an cryptographically encapsulated segment of a same VLAN wherein the traffic is transferred between end stations.

2. The method of claim 1 , wherein the MAC security is selected from a group including a MAC Security Key Agreement and a MAC Security Entity.

3. A method for segregating traffic among a plurality of end stations associated with an access point that has a processor and a memory, comprising:

receiving a frame at the access point wherein the frame includes a cryptographic authentication code;

if the received frame carries a null virtual LAN ID (VID) or is untagged, then using the received frame's source MAC address to determine a preliminary VLAN classification of the received frame;

if the received frame carries a VID, then using the VID as the preliminary VLAN classification instead;

using the preliminary VLAN classification to index into a table of security associations, the table giving a cryptographic authentication code key;

recomputing the cryptographic authentication code, using the cryptographic authentication code key from the table, over a payload of the received frame;

comparing the recomputed cryptographic authentication code with the received cryptographic authentication code included in the received frame;

wherein if the recomputed cryptographic authentication code and the received cryptographic authentication code match, then using the preliminary VLAN classification as a final VLAN classification and decrypting the received frame; and

wherein if the recomputed cryptographic authentication code and the received cryptographic authentication code do not match, discarding the received frame.

4. The method of claim 3 , further comprising:

performing an initial authentication operation by the access point, wherein the authentication code key is generated during the initial authentication operation.

5. The method of claim 3 , wherein the cryptographic authentication code is recomputed over the payload using a cryptographic message digest algorithm determined during an initial authentication operation.

6. The method of claim 3 wherein the final VLAN classification is used as a value of a VLAN classification parameter of any corresponding data request primitives.

7. The method of claim 3 , wherein the cryptographic authentication code uniquely identifies the VLAN.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034542/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2008
From: CRANITE SYSTEMS, INC.
To: MICROSOFT CORPORATION
Reel/Frame 021006/0870 →