IP Library Granted Patent US 7,944,858
Granted Patent B2
US 7,944,858 · App. 12/319,496 · Granted May 17, 2011

Method for protecting a network configuration set up by a spanning tree protocol

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,944,858
App. No.
12/319,496
Granted
May 17, 2011
Kind
B2
Abstract

A method for protecting a network configuration set up by a spanning tree protocol, STP, by selecting one of a plurality of bridges ( 2 to 11 ) of a computer network ( 1 ) as a root bridge ( 2 ) and by selecting one of a plurality of bridge ports ( 2 a to 11 a , 3 b, 4 b , 6 b, 7 b, 9 b, 10 b ) of each of the plurality of bridges ( 2 to 11 ) as a root port ( 2 a to 11 a ), the method comprising the steps of: setting a sub-state of at least one bridge port ( 2 a to 11 a, 3 b, 4 b, 6 b, 7 b, 9 b, 10 b ) of at least one of the bridges ( 2 to 11 ) to an active sub-state in case that bidirectional traffic passes through the bridge port ( 2 a to 11 a, 3 b, 4 b, 6 b, 7 b, 9 b, 10 b ), receiving an STP message, in particular a Bridge Protocol Data Unit, BPDU, in one of the bridge ports ( 2 a to 11 a, 3 b, 4 b, 6 b, 7 b, 9 b, 10 b ) being in the active sub-state, and protecting the network configuration by discarding the STP message and/or by sending an alarm message to a network management unit ( 27 ) in case that the STP message indicates a change of the root bridge ( 2 ) of the network configuration.

Claims (17)

1. A method for protecting a network configuration set up by a spanning tree protocol, STP, by selecting one of a plurality of bridges of a computer network as a root bridge and by selecting one of a plurality of forwarding bridge ports of each of the plurality of bridges as a root port, wherein the selected one of the plurality of forwarding bridge ports is in a forwarding state, the method comprising the steps of:

splitting the forwarding state of the bridge port to an active and a passive sub-state through an additional state machine unit added to each of the forwarding bridge ports;

setting a sub-state of at least one forwarding bridge port of at least one of the bridges to an active sub-state as long as bidirectional payload traffic is conveyed through the forwarding bridge port;

receiving an STP message, in particular a Bridge Protocol Data Unit, BPDLT, in one of the forwarding bridge ports being in the active sub-state, and

protecting the network configuration by discarding the STP message and by sending an alarm message to a network management unit in case that the STP message indicates a change of the root bridge of the network configuration;

wherein the change of the root bridge is indicated by a bridge port ID of the BPDU which is smaller than the bridge port ID of the root bridge of the network configuration.

2. Method according to claim 1 , further comprising the step of checking the root path costs of the STP message for plausibility in case that the STP message indicates a change of the root port and a decrease of the root path costs.

3. Method according to claim 2 , wherein checking of the root path costs for plausibility is performed by comparing the root path costs of the STP message with the actual root path costs, taking into account the topology of the network and/or a permitted range of root path costs set by the network management unit.

4. Bridge for operating in a network configuration of a computer network set up by a spanning tree protocol, STP, by selecting one of a plurality of forwarding bridge ports of the bridge as a root port and by selecting one of a plurality of bridges of the computer network as a root bridge, the bridge comprising:

a sub-state setting unit for splitting a forwarding state of the bridge port to an active and a passive sub-state through an additional state machine unit added to each of the forwarding bridge ports and for setting the sub-state of the forwarding state of at least one of the forwarding bridge ports to an active sub-state as long as bidirectional payload traffic passes through the forwarding bridge port,

a receiving unit for receiving a STP message, in particular a Bridge Protocol Data Unit, BPDU, in one of the forwarding bridge ports being in the active sub-state, and

a network configuration protection unit for protecting the network configuration by discarding the STP message and by sending an alarm message to a network management unit in case that the STP message indicates a change of the root bridge of the network configuration;

wherein a change of the root bridge is indicated in the network configuration protection unit by a bridge port ID of the BPDU which is smaller than the bridge port ID of the root bridge.

5. Bridge according to claim 4 , wherein the network configuration protection unit is adapted to check the root path costs of the STP message for plausibility in case that the STP message indicates a change of the root port and a decrease of the root path costs.

6. Bridge according to claim 5 , wherein the network configuration protection unit is adapted to check the root path costs for plausibility by comparing the root path costs of the STP message with the actual root path costs, taking into account the topology of the network and/or a permitted range of root path costs set by the network management unit.

7. Computer network comprising a plurality of bridges according to claim 4 , the computer network operating in a network configuration set up by a spanning tree protocol, STP, by selecting one of the plurality of bridges as a root bridge and by selecting one of a plurality of forwarding bridge ports of each of the plurality of bridges as a root port.

8. Computer network according to claim 7 , further comprising a network management unit.

Assignments (11)
CHANGE OF NAME Recorded Jan 27, 2022
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058871/0336 →
RELEASE OF SECURITY INTEREST Recorded Dec 12, 2018
From: NOKIA USA INC.
To: PROVENANCE ASSET GROUP, LLC
Reel/Frame 047791/0566 →
RELEASE OF SECURITY INTEREST Recorded Dec 12, 2018
From: NOKIA USA INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC
Reel/Frame 049139/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2018
From: PROVENANCE ASSET GROUP LLC
To: FACEBOOK, INC.
Reel/Frame 047190/0360 →
PARTIAL RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 043967/0001 Recorded Aug 30, 2018
From: CORTLAND CAPITAL MARKET SERVICES LLC
To: PROVENANCE ASSET GROUP, LLC
Reel/Frame 046981/0600 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033868/0001 →
SECURITY AGREEMENT Recorded Jan 30, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 029821/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2009
From: TABERY, PETER; KLOTSCHE, RALF
To: ALCATEL-LUCENT
Reel/Frame 022424/0555 →