IP Library Granted Patent US 12,568,118
Granted Patent B2
US 12,568,118 · App. 18/194,741 · Granted Mar 3, 2026

Shortest path bridging (SPB) security group policy

Inventors: Roger Lapuh (Uesslingen, CH); Constantin Barcaru (Brasov, RO); Ludovico Stevens (La Roquette sur Siagne, FR)
Assignee: Extreme Networks, Inc.
H04L63/20H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,118
App. No.
18/194,741
Granted
Mar 3, 2026
Kind
B2
Abstract

Disclosed herein are system, method, and computer program product aspects for implementing a security group policy. Some aspects of this disclosure relate to a method for applying a security group policy. The method includes receiving a first frame from a source device and assigning a source security group identifier (ID) to the first frame. The method further includes generating a second frame based on the first frame and the source security group ID and identifying a target security group ID for the second frame. The method also includes applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID.

Claims (73)

1 . A method for applying a security group policy in a Shortest Path Bridging (SPB) network, the method comprising:

receiving a first frame from a source device;

assigning a source security group identifier (ID) to the first frame;

generating a second frame based on the first frame and the source security group ID by adding a tag protocol (TPID) field and a source security group ID field to the first frame;

identifying a target security group ID for the second frame; and

applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID by:

using a communication matrix to determine whether the source security group ID and the target security group ID are allowed to communicate; and

in response to determining that the source security group ID and the target security group ID are allowed to communicate, forwarding the second frame to a destination device associated with the target security group ID.

2 . The method of claim 1 , wherein the assigning the source security group ID comprises:

determining a port on which the first frame is received; and

assigning the source security group ID based on the determined port.

3 . The method of claim 1 , wherein the assigning the source security group ID comprises:

determining a client Media Access Control (MAC) (C-MAC) address associated with the source device; and

assigning the source security group ID based on the determined C-MAC address.

4 . The method of claim 1 , wherein the identifying the target security group ID comprises:

determining a port on which the second frame is to be transmitted to a destination device; and

identifying the target security group ID based on the determined port.

5 . The method of claim 1 , wherein the identifying the target security group ID comprises:

determining a client Media Access Control (MAC) (C-MAC) address associated with a destination device; and

identifying the target security group ID based on the determined C-MAC address.

6 . The method of claim 1 , wherein the assigning the source security group ID and the identifying the target security group ID comprises:

assigning the source security group ID based on a first Instance Service Identifiers (I-SID) or a first virtual local area network (VLAN); and

identifying the target security group ID based on a second I-SID or a second VLAN.

7 . The method of claim 1 , wherein:

the source security group ID field is immediately after the TPID field, and

a value of the TPID field indicates that the source security group ID field includes the source security group ID.

8 . A system for applying a security group policy in a Shortest Path Bridging (SPB) network, the system comprising:

a memory; and

at least one processor coupled to the memory and configured to:

receive a first frame from a source device;

assign a source security group identifier (ID) to the first frame;

generate a second frame based on the first frame and the source security group ID by adding a tag protocol (TPID) field and a source security group ID field to the first frame;

identify a target security group ID for the second frame; and

apply one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID by:

using a communication matrix to determine whether the source security group ID and the target security group ID are allowed to communicate; and

in response to determining that the source security group ID and the target security group ID are allowed to communicate, forwarding the second frame to a destination device associated with the target security group ID.

9 . The system of claim 8 , wherein to assign the source security group ID, the at least one processor is further configured to:

determine a port on which the first frame is received; and

assign the source security group ID based on the determined port.

10 . The system of claim 8 , wherein to assign the source security group ID, the at least one processor is further configured to:

determine a client Media Access Control (MAC) (C-MAC) address associated with the source device; and

assign the source security group ID based on the determined C-MAC address.

11 . The system of claim 8 , wherein to identify the target security group ID, the at least one processor is further configured to:

determine a port on which the second frame is to be transmitted to a destination device; and

identify the target security group ID based on the determined port.

12 . The system of claim 9 , wherein to identify the target security group ID, the at least one processor is further configured to:

determine a client Media Access Control (MAC) (C-MAC) address associated with a destination device; and

identify the target security group ID based on the determined C-MAC address.

13 . The system of claim 8 , wherein to assign the source security group ID and to assign the target security group ID, the at least one processor is further configured to:

assign the source security group ID based on a first Instance Service Identifiers (I-SID) or a first virtual local area network (VLAN); and

identify the target security group ID based on a second I-SID or a second VLAN.

14 . The system of claim 8 , wherein:

the source security group ID field is immediately after the TPID field, and a value of the TPID field indicates that the source security group ID field includes the source security group ID.

15 . A tangible computer-readable device having instructions stored thereon that, when executed by at least one processor, cause the at least one processor to perform operations for applying a security group policy in a Shortest Path Bridging (SPB) network, the operations comprising:

receiving a first frame from a source device;

assigning a source security group identifier (ID) to the first frame;

generating a second frame based on the first frame and the source security group ID;

identifying a target security group ID for the second frame; and

applying one or more forwarding decisions to the second frame based on the source security group ID and the target security group ID by:

using a communication matrix to determine whether the source security group ID and the target security group ID are allowed to communicate; and

in response to determining that the source security group ID and the target security group ID are allowed to communicate, forwarding the second frame to a destination device associated with the target security group ID.

16 . The computer-readable device of claim 15 , wherein the generating the second frame based on the first frame and the source security group ID comprises:

adding a tag protocol identifier (TPID) field to the first frame; and

adding a source security group ID field to the first frame,

wherein the source security group ID field is immediately after the TPID field, and

wherein a value of the TPID field indicates that the source security group ID field includes the source security group ID.

17 . The computer-readable device of claim 15 , wherein:

the assigning the source security group ID comprises:

determining a first client Media Access Control (MAC) (C-MAC) address associated with the source device; and

assigning the source security group ID based on the determined first C-MAC address, and

the identifying the target security group ID comprises:

determining a second C-MAC address associated with a destination device; and

assigning the target security group ID based on the determined second C-MAC address.

Assignments (3)
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: LAPUH, ROGER; BARCARU, CONSTANTIN; STEVENS, LUDOVICO
To: EXTREME NETWORKS, INC.
Reel/Frame 063207/0550 →
Continuity (1)
Related Publication 20240333770A1 · Oct 3, 2024
References Cited (19)
US 20040160903A1 · Gai · 2004 [cited by examiner]
US 20050129019A1 · Cheriton · 2005 [cited by examiner]
US 20060248227A1 · Hato · 2006 [cited by examiner]
US 20080013481A1 · Simons · 2008 [cited by examiner]
US 20090049196A1 · Smith · 2009 [cited by examiner]
US 20110271102A1 · Smith · 2011 [cited by examiner]
US 20140086252A1 · Keesara et al. · 2014 [cited by applicant]
US 20140280834A1 · Medved · 2014 [cited by examiner]
US 20140280838A1 · Finn · 2014 [cited by examiner]
US 20140369352A1 · Zhou · 2014 [cited by applicant]
US 20150156108A1 · Shi · 2015 [cited by examiner]
US 20160373441A1 · Sirivara · 2016 [cited by examiner]
US 20180063195A1 · Nimmagadda · 2018 [cited by examiner]
US 20230093278A1 · Majila · 2023 [cited by examiner]
Sitti et al., “Optimizing Load Distribution for Shortest Path Bridging via Network Coding”, Jan. 2014, International Conference on Computer Communication and Informatics, pp. 1-4 (Year: 2014). [cited by examiner]
International Search Report and Written Opinion of the International Searching Authority directed to International Patent Application No. PCT/US2024/011011, mailed Apr. 3, 2024; 11 pages. [cited by applicant]
“VXLAN Group Policy Option,” Internet Engineering Task Force, M. Smith, Oct. 22, 2018, 6 pages. [cited by applicant]
“Overview of Cisco TrustSec,” Chapter 2 of Cisco TrustSec Configuration Guide, 2021, 8 pages. [cited by applicant]
“Cisco TrustSec Configuration Guide,” 2021, 126 pages. [cited by applicant]