IP Library Patent Application 14776759
Patent Application
App. No. 14/776,759

EMULATE VLANS USING MACSEC

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/776,759
Abstract

Emulating virtual local area networks (VLAN)s using media access control security (MACsec) can include a network controller to provision a first client device of a plurality of client devices within a network with a MACsec key associated with a MACsec flow. The network controller can provision a second client device with the MACsec key associated with the MACsec flow to emulate a VLAN with secure communication between the first and the second client devices.

Claims (29)

1 . A method, comprising:

provisioning, with a network controller, a first client device of a plurality of client devices within a network with a media access control security (MACsec) key associated with a MACsec flow; and

provisioning, with the network controller, a second client device with the MACsec key associated with the MACsec flow to emulate a virtual local area network (VLAN) with secure communication between the first and the second client devices.

2 . The method of claim 1 , wherein the first and the second client devices comprise endpoints of the MACsec flow, and wherein the method includes:

encrypting the MACsec flow with the first client device according to the MACsec key;

decrypting the MACsec flow with the second client device according to the MACsec key; and

not provisioning a network switch between, with respect to the first and the second client devices, with a MACsec key.

3 . The method of claim 1 , wherein the method includes provisioning the first and the second client devices with an updated MACsec key.

4 . The method of claim 1 , wherein provisioning the first client device with the MACsec key comprises provisioning the first client device with a set of MACsec keys; and

wherein provisioning the second client device with the MACsec key comprises provisioning the second client device with the set of MACsec keys.

5 . The method of claim 4 , wherein the method includes instructing the first client device and the second client device to use one of the set of MACsec keys.

6 . A non-transitory machine-readable medium storing instructions executable by a network controller to cause the network controller to:

specify a first client device and a second client device as endpoints of a media access control security (MACsec) flow;

provision, with the network controller, the first client device of a plurality of client devices within the network with a MACsec key associated with the MACsec flow based on an association including the first and the second client devices; and

provision, with the network controller, the second client device with the MACsec key associated with the MACsec flow based on the association to emulate a virtual local area network (VLAN) with secure communication between the first and the second client devices.

7 . The medium of claim 6 , wherein the instructions to provision the second client device with the MACsec key include instructions executable by the network controller to enable a secure channel between the first client device and the second client device.

8 . The medium of claim 6 , wherein the instructions are executable to cause the network controller not to provision a plurality of network switches between, with respect to the first and the second client devices, with a MACsec key.

9 . The medium of claim 6 , wherein the instructions to provision the first client device with the MACsec key and the instructions to provision the second client device with the MACsec key include instructions executable by the network controller to provision the first and the second client devices with symmetric MACsec keys.

10 . The medium of claim 6 , wherein the instructions to provision the first client with the MACsec key include instructions executable by the network controller to provision the first MACsec key to memory associated with the first client device, and wherein the instructions executable to provision the second client device with the MACsec key include instructions executable by the network controller to provision the second MACsec key to memory associated with the second client device.

11 . The medium of claim 6 , wherein the instructions to provision the first client device with the MACsec key and the instructions to provision the second client device with the MACsec key include instructions executable by the network controller to provision a group key among a group of client devices, the group comprising at least two of the plurality of client devices, including the first and second client devices, having a number of secure channels therebetween, wherein at least one of the secure channels is unidirectional with respect to the first and second client devices.

12 . The medium of claim 6 , wherein the instructions to provision the first client device with the MACsec key and the instructions to provision the second client device with the MACsec key include instructions executable by the network controller to provision a group key among a group of client devices, the group comprising at least two of the plurality of client devices having a number of secure channels therebetween to enable the first and second client devices to encrypt and decrypt a broadcast communication, a multicast communication, or an unknown address communication via the secure channels therebetween according to the group key.

13 . A network controller, comprising:

a processing resource in communication with a memory resource, wherein the memory resource includes a set of instructions to:

define associations between a plurality of client devices to enable a media access control security (MACsec) flow between the plurality of client devices;

provision, with a network controller, a first client device of the plurality of client devices within a network with a MACsec key associated with the MACsec flow based on an association including the first client device and a second client device;

provision, with the network controller, the second client device with the MACsec key based on the association including the first and the second client devices to emulate a virtual local area network (VLAN) with secure communication between the first and the second client devices; and

not to provision each of a plurality of network switches with a MACsec key, the plurality of network switches being between the first and the second client devices with respect to the MACsec flow.

14 . The network controller of claim 13 , wherein the first client device comprises an endpoint of the MACsec flow and wherein the second device comprises an endpoint of the MACsec flow, and wherein the first client device, the second client device, and the network controller are on a common Layer 2 network.

15 . The network controller of claim 13 , wherein the instructions are executable by the processing resource to allow the plurality of client devices access to the network in response to authentication of the plurality of client devices.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2015
From: WAKUMOTO, SHAUN K.; MILLS, CRAIG J.; PARVEZ SYED, MOHAMED
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 036563/0069 →