METHOD AND DEVICE FOR PROCESSING SOURCE ROLE INFORMATION
First Claim
Patent Images
1. A method for processing source role information, applied to a network comprising an Ingress device and an Egress device, comprising:
- an Ingress device receiving a packet from user equipment and, determining a source role tag according to source information of the packet, inserting the source role tag into the packet as an inner Virtual Local Area Network (VLAN) tag of the packet, and forwarding the packet, wherein the source role tag corresponds to a role of the user equipment;
if there are one or more intermediate devices between the Ingress device and the Egress device, the intermediate device or intermediate devices forwarding the packet to the Egress device, said intermediate device or intermediate devices keeping the source role tag unchanged during said forwarding;
the Egress device receiving the packet, obtaining the source role tag from the inner VLAN tag of the packet, and performing role based access control processing for the packet based on said source role tag.
2 Assignments
0 Petitions
Accused Products
Abstract
A method and device for processing source role information in which a source role tag is inserted into a packet as an inner VLAN tag of the packet and used to perform role based access control processing for the packet.
-
Citations
20 Claims
-
1. A method for processing source role information, applied to a network comprising an Ingress device and an Egress device, comprising:
-
an Ingress device receiving a packet from user equipment and, determining a source role tag according to source information of the packet, inserting the source role tag into the packet as an inner Virtual Local Area Network (VLAN) tag of the packet, and forwarding the packet, wherein the source role tag corresponds to a role of the user equipment; if there are one or more intermediate devices between the Ingress device and the Egress device, the intermediate device or intermediate devices forwarding the packet to the Egress device, said intermediate device or intermediate devices keeping the source role tag unchanged during said forwarding; the Egress device receiving the packet, obtaining the source role tag from the inner VLAN tag of the packet, and performing role based access control processing for the packet based on said source role tag. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. An Ingress device, comprising:
-
a packet receiving unit, configured to receive a packet from user equipment; a role tag determining unit, configured to determine a source role tag according to source information of the packet, where the source role tag corresponds to a role of the user equipment; a role tag inserting unit, configured to insert the source role tag into the packet as an inner Virtual Local Area Network (VLAN) tag of the packet; and a forwarding processing unit, configured to forward the packet. - View Dependent Claims (10, 11, 12, 13)
-
-
14. An Egress device, comprising:
-
a packet receiving unit, configured to receive a packet from user equipment; a role tag obtaining unit, configured to obtain a source role tag as an inner Virtual Local Area Network (VLAN) tag from the packet, wherein the source role tag corresponds to a role of the user equipment transmitting the packet; an access control unit, configured to perform role based access control processing for the packet according to the source role tag. - View Dependent Claims (15, 16, 17)
-
-
18. An intermediate device, comprising:
-
a packet receiving unit, configured to receive a packet from an Ingress device or another intermediate device; a tag identifying unit, configured to identify an inner Virtual Local Area Network (VLAN) tag of the packet as a source role tag; a forwarding processing unit, configured to forward the packet and keep the inner VLAN tag unchanged when the tag identifying unit determines that the inner VLAN tag is a source role tag;
whereinthe inner VLAN tag corresponds to a role of user equipment transmitting the packet. - View Dependent Claims (19, 20)
-
Specification