IP Library Granted Patent US 11,463,425
Granted Patent B2
US 11,463,425 · App. 15/784,028 · Granted Oct 4, 2022

Restricting broadcast and multicast traffic in a wireless network to a VLAN

Inventors: Mohan Ram (Banashankari, IN); Sung-Wook Han (Sunnyvale, CA)
Assignee: Fortinet, Inc.
H04L63/065H04L45/586H04L49/354H04L63/10H04L63/104H04W12/041H04W12/0431H04W12/0433H04W36/08H04L12/189H04W88/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,425
App. No.
15/784,028
Granted
Oct 4, 2022
Kind
B2
Abstract

Traffic broadcast to a VLAN is restricted. To do so, a plurality of stations are associated with a BSSID (basic service set identifier). A first VLAN is configured by sending a first group key to each station from the plurality of stations that is a member of the first VLAN, wherein each VLAN is associated with a unique group key. One or more frames addressed to the first VLAN are received. The one or more frames are encrypted with the first group key to prevent stations without the first group key from being able to decrypt the one or more frames. The one or more encrypted VLAN frames are broadcast to the plurality of stations associated with the BSSID.

Claims (13)

1. A computer-implemented method, in an access point of a wireless network, for restricting broadcast traffic to a VLAN (virtual local access network) of stations, the method comprising the steps of:

associating a plurality of stations with a BSSID (basic service set identifier);

receiving a list of members of the first VLAN;

configuring a first VLAN of stations of a plurality of VLANs of stations by sending a first station group VLAN key to each station from the plurality of stations that is a member of the first VLAN, wherein each VLAN is associated with a unique station group key to decrypt restricted broadcast packets from the first access point, wherein the first station group VLAN key is sent to the station using the IEEE 802.1X protocol;

receiving one or more frames addressed to the first VLAN;

encrypting the one or more frames with the first group VLAN key to prevent stations without the first station group VLAN key from being able to decrypt the one or more frames; and

broadcasting the one or more encrypted VLAN frames to the plurality of stations associated with the BSSID;

configuring a second VLAN by sending a second group VLAN key to each station that is a member of the second VLAN, wherein the second station group VLAN key is sent to the station using the IEEE 802.1X protocol;

receiving one or more frames addressed to the second VLAN;

receiving a list of members of the second VLAN;

encrypting the one or more frames with the second station group VLAN key to prevent stations without the second station group VLAN key from being able to decrypt the one or more frames,

wherein at least one station from the first VLAN is transparently handed-off to a second access point while retaining membership in the first VLAN,

wherein the first and second VLANs span across both the first and second access points.

Assignments (2)
MERGER Recorded Feb 28, 2018
From: MERU NETWORKS, INC.
To: FORTINET, INC
Reel/Frame 045474/0392 →
MERGER Recorded Jan 23, 2018
From: MERU NETWORKS, INC.
To: FORTINET, LLC
Reel/Frame 045112/0786 →
Continuity (3)
Continuation 15043561 · Feb 13, 2016
Continuation 13772358 · Feb 21, 2013
Related Publication 20180152425A1 · May 31, 2018