US2015319139A1PendingUtilityA1
Method and device for processing source role information
Est. expiryMay 24, 2030(~3.8 yrs left)· nominal 20-yr term from priority
H04L 63/0245H04L 63/105H04L 12/4645H04L 63/0254H04L 63/101H04L 12/4675H04L 12/4641
43
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method and device for processing source role information in which a source role tag is inserted into a packet as an inner VLAN tag of the packet and used to perform role based access control processing for the packet.
Claims
exact text as granted — not AI-modified1 . A method for processing source role information, applied to a network comprising an Ingress device and an Egress device, comprising:
receiving, by the Ingress device, a packet from user equipment; receiving, by the Ingress device, source role information of the user equipment after a verification of the user equipment; converting, by the Ingress device, the source role information of the user equipment into a source role tag, wherein the source role tag corresponds to a role of the user equipment; inserting, by the Ingress device, the source role tag into the packet; and forwarding the packet to the Egress device.
2 . The method of claim 1 , further comprising:
after receiving a verification request of the user equipment, forwarding, by the Ingress device, the verification request to an access verification server, obtaining the source role information of the user equipment from the access verification server to convert the source role information of the user equipment into the source role tag, and applying a corresponding relation between the Ingress device's ingress port receiving the verification request and the source role tag to a hardware plane of the Ingress device; and determining the source role tag corresponding to the Ingress device's ingress port receiving the verification request according to the corresponding relation applied to the hardware plane of the Ingress device.
3 . The method of claim 1 , further comprising:
forwarding, by a common device, a verification request of the user equipment to an access verification server, obtaining source role information of the user equipment issued by the access verification server, and transmitting a corresponding relation between the source role information of the user equipment and source address information of the verification request to the Ingress device; applying, by the Ingress device, the corresponding relation between the source role tag corresponding to the source role information of the user equipment and the source address information or a protocol number of the verification request to a hardware plane of the Ingress device; and determining the source role tag corresponding to the source address information or the protocol number of the packet according to the corresponding relation applied to the hardware plane of the Ingress device.
4 . The method of claim 1 , further comprising: performing, by the Egress device, a role based access control processing for the packet based on the source role tag in the packet,
wherein performing the role based access control processing for the packet comprises: determining, by the Egress device, destination role information of the packet, matching the source role tag and the destination role information with items in a Role Based Access Control List (RBACL), and performing access control processing for the packet according to a matching result.
5 . The method of claim 4 , further comprising:
after receiving a verification request of a resource side device, forwarding, by the Egress device, the verification request to the access verification server, obtaining destination role information of the resource side device issued by the access verification server, and applying a corresponding relation between source address information of the verification request and the destination role information of the resource side device to a hardware plane of the Egress device; obtaining a role based control policy from the access verification server, wherein the destination role information of the resource side device issued by the access verification server is taken as destination role information; converting the source role information into the source role tag, obtaining the RBACL, and applying the RBACL to the hardware plane of the Egress device, wherein the RBACL contains source role tag, destination role information and access control mode; determining the destination role information of the packet from the user equipment comprises: determining the destination role information corresponding to destination address information of the packet from the user equipment according to the corresponding relation applied to the hardware plane of the Egress device; and performing, by the Egress device, matching processing according to the RBACL applied to the hardware plane of the Egress device.
6 . The method of claim 1 , further comprising:
when the source role tag is taken as an inner VLAN tag, setting a Tag Protocol Identity (TPID) of the inner VLAN tag to a preset value unequal to 0 X 8100 to identify the inner VLAN tag as the source role tag; keeping, by an intermediate device connected between the user equipment and the Ingress device, the inner VLAN tag unchangeable when determining that the TPID of the inner VLAN tag of the packet is the preset value; and obtaining, by the Egress device, the source role tag as the inner VLAN tag from the packet when determining that the TPID of the inner VLAN tag of the packet is the preset value.
7 . The method of claim 1 , wherein forwarding the packet to the Egress comprises:
A1) if the packet does not contain an outer VLAN tag (Vtag), determining the Vtag of the packet, inserting the Vtag into the packet, and performing a step A2); if the packet contains a Vtag, directly performing the step A2); A2) searching a layer-2 or layer-3 forwarding list according to the Vtag contained in the packet and the destination address information of the packet to determine an egress port; and A3) forwarding the packet containing the source role tag through the determined egress port.
8 . The method of claim 1 , further comprising:
B1) if the packet does not contain an outer VLAN tag (Vtag(, determining, by the Egress device, the Vtag of the packet, inserting the Vtag into the packet, and performing a step B2); if the packet contains a Vtag, directly performing the step B2); B2) searching a layer-2 or layer-3 forwarding list according to the Vtag contained in the packet and the destination address information of the packet to determine an egress port; B3) stripping the source role tag of the packet, and forwarding the packet through the determined egress port when the access control processing indicates to forward the packet.
9 . An Ingress device, comprising:
a packet receiving unit to receive a packet from user equipment; a role tag determining unit to receive source role information of the user equipment and convert the source role information into a source role tag for the packet, wherein the source role tag corresponds to a role of the user equipment; a role tag inserting unit to insert the source role tag into the packet; and a forwarding processing unit to forward the packet.
10 . The Ingress device of claim 9 , further comprising a verification processing unit and a first tag configuring unit; wherein
the verification processing unit is to forward a verification request from the user equipment to an access verification server; the first tag configuring unit is to obtain the source role information of the user equipment from the access verification server after a verification of the user equipment, convert the source role information of the user equipment into the source role tag, and apply a corresponding relation between the Ingress device's ingress port receiving the verification request and source role tag to a hardware plane of the Ingress device; and the role tag determining unit is to perform, according to the corresponding relation applied to the hardware plane of the Ingress device, an operation of determining the source role tag according to the source information of the packet, wherein the source information of the packet includes the Ingress device's ingress port receiving the packet.
11 . The Ingress device of claim 10 , further comprising: a role obtaining unit and a second tag configuring unit; wherein
the role obtaining unit is to obtain from a common device a corresponding relation between the source role information of the user equipment and source address information or a protocol number of the verification request, wherein the source role information of the user equipment is issued to the common device by the access verification server after the common device forwards the verification request of the user equipment to the access verification server; the second tag configuring unit is to apply the corresponding relation between the source role tag corresponding to the role information of the user equipment and the source address information or the protocol number of the packet to the hardware plane of the Ingress device; and the role tag determining unit is to perform, according to the corresponding relation applied to the hardware plane of the Ingress device, an operation of determining the source role tag according to the source information of the packet, wherein the source information of the packet is the source address information or the protocol number of the packet.
12 . The Ingress device of claim 9 , wherein the role tag inserting unit is to insert the source role tag into the packet as an inner VLAN tag of the packet, and set a Tag Protocol Identity (TPID) of the inner VLAN tag to a preset value unequal to 0 X 8100 .
13 . The Ingress device of claim 9 , wherein the forwarding processing unit comprises:
an outer tag inserting sub-unit to determine an outer Virtual Local Area Network (VLAN) tag (Vtag) of the packet when the packet received by the packet receiving unit does not contain the Vtag, and insert the Vtag into the packet; a forwarding list searching sub-unit to search a layer-2 or layer-3 forwarding list according to the Vtag and destination address information contained in the packet which is received by the packet receiving unit or according to the Vtag and the destination address information contained in the packet which has been processed by the outer tag inserting sub-unit; and an egress port processing sub-unit to strip the Vtag contained in the packet, and forward the packet containing the source role tag through a determined egress port.
14 .- 20 . (canceled)
21 . A method for processing source role information, applied to a network comprising an Ingress device and an Egress device, comprising:
receiving, by the Egress device, a packet from user equipment via the Ingress device; obtaining, by the Egress device, a source role tag in the packet, wherein the source role tag was inserted into the packet by the Ingress device after the Ingress device has converted source role information of the user equipment into the source role tag; and performing, by the Egress device, a role based access control processing for the packet based on the source role tag of the packet.
22 . The method of claim 21 , wherein performing the role based access control processing comprises:
determining, by the Egress device, destination role information of the packet; matching, by the Egress device, the source role tag and the destination role information with items in a Role Based Access Control List (RBACL); and performing, by the Egress device, an access control processing for the packet according to a result of the matching.
23 . The method of claim 22 , further comprising:
forwarding, by the Egress device, a verification request from a resource side device to an access verification server, and obtaining destination role information of the resource side device from the access verification server; applying a corresponding relation between source address information of the verification request from the resource side device and the destination role information of the resource side device to a hardware plane of the Egress device; obtaining a role based control policy, wherein the role based control policy contains source role tags, destination role information and access control mode; converting the source role information into the source role tag, obtaining the RBACL, and applying the RBACL to the hardware plane of the Egress device, wherein the RBACL contains source role tags, destination role information and access control mode; determining the destination role information corresponding to a destination address of the packet from the user equipment according to the corresponding relation applied to the hardware plane of the Egress device; and performing a matching processing for the RBACL applied to the hardware plane of the Egress device.
24 . The method of claim 21 , further comprising:
determining an outer Virtual Local Area Network (VLAN) tag (Vtag) of the packet in response to a determination that the packet does not contain a Vtag; inserting the Vtag into the packet; searching a layer-2 or layer-3 forwarding list according to the Vtag and destination address information contained in the packet; and stripping the source role tag and the Vtag contained in the packet, and forwarding the packet through an egress port.
25 . The method of claim 21 , wherein the source role information of the user equipment is received from an access verification server after the user equipment has been verified by the access verification server.Join the waitlist — get patent alerts
Track US2015319139A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.