Group identity assignment and policy enforcement for devices within the same network

US12526282B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12526282-B2
Application numberUS-202117552394-A
CountryUS
Kind codeB2
Filing dateDec 16, 2021
Priority dateDec 16, 2021
Publication dateJan 13, 2026
Grant dateJan 13, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Group identity assignment and policy enforcement may be provided. A User Defined Network Identifier (UDN ID) defining a group of client devices may be received. Next, a client identifier (ID) associated with a source client device that is associated with the group of client devices may be received. The UDN ID and the client ID may be encoded in an Extended Local Identifier (ELI) Media Access Control (MAC) address associated with the source client device. A source MAC address of a packet received from the source client device may then be substituted with the ELI MAC address. Then the packet may be forwarded.

First claim

Opening claim text (preview).

The invention claimed is: 1 . A method comprising: receiving, by a first Access Point (AP), a User Defined Network Identifier (UDN ID) defining a group of client devices, wherein each client device of the group of client devices is assigned a same UDN ID; receiving, by the first AP, a client ID associated with a source client device that is associated with the group of client devices; encoding, by the first AP, the UDN ID and the client ID in an Extended Local Identifier (ELI) Media Access Control (MAC) address associated with the source client device; substituting, by the first AP, a source MAC address of a packet received from the source client device with the ELI MAC address; and forwarding, by the first AP, the packet. 2 . The method of claim 1 , further comprising: receiving, by a second AP, the packet; extracting the UDN ID from the ELI MAC address of the packet; and comparing the UDN ID from the ELI MAC address with a UDN ID associated with a destination client. 3 . The method of claim 2 , further comprising: forwarding, by the second AP, the packet to the destination client when comparing the UDN ID from the ELI MAC address with the UDN ID associated with the destination client indicates the UDN ID from the ELI MAC address and the UDN ID of the destination client match. 4 . The method of claim 2 , further comprising: dropping, by the second AP, the packet when comparing the UDN ID from the ELI MAC address with the UDN ID associated with the destination client indicates the UDN ID from the ELI MAC address and the UDN ID of the destination client do not match. 5 . The method of claim 1 , further comprising mapping the ELI MAC address to the source MAC address in a table. 6 . The method of claim 1 , further comprising encoding a Company ID in a first three octets of the ELI MAC address. 7 . The method of claim 1 , wherein encoding the UDN ID and the client ID in the ELI MAC address comprises encoding the UDN ID and the client ID in the ELI MAC address in a second three octets of the ELI MAC address. 8 . The method of claim 7 , wherein encoding the UDN ID and the client ID in the ELI MAC address in the second three octets of the ELI MAC address comprises encoding the UDN ID in two bytes of the second three octets of the ELI MAC address. 9 . The method of claim 7 , wherein encoding the UDN ID and the client ID in the ELI MAC address in the second three octets of the ELI MAC address comprises encoding the client ID in one byte of the second three octets of the ELI MAC address. 10 . The method of claim 1 , wherein the UDN ID was generated when the group of client devices was provisioned. 11 . The method of claim 1 , wherein the client ID was generated when the source client device was authenticated. 12 . A system comprising: a memory storage; and a processing unit implemented using at least one hardware processor coupled to the memory storage, wherein the processing unit is operative to: receive a User Defined Network Identifier (UDN ID) defining a group of client devices, wherein each client device of the group of client devices is assigned a same UDN ID, receive a client ID associated with a source client device that is associated with the group of client devices, encode the UDN ID and the client ID in an Extended Local Identifier (ELI) Media Access Control (MAC) address associated with the source client device, substitute a source MAC address of a packet received from the source client device with the ELI MAC address, and forward the packet. 13 . The system of claim 12 , wherein the processing unit is further operative to encode a Company ID in a first three octets of the ELI MAC address. 14 . The system of claim 12 , wherein the processing unit being operative to encode the UDN ID and the client ID in the ELI MAC address comprises the processing unit being operative to encode the UDN ID and the client ID in the ELI MAC address in a second three octets of the ELI MAC address. 15 . The system of claim 14 , wherein the processing unit being operative to encode the UDN ID and the client ID in the ELI MAC address in the second three octets of the ELI MAC address comprises the processing unit being operative to encode the UDN ID in two bytes of the second three octets of the ELI MAC address. 16 . The system of claim 14 , wherein the processing unit being operative to encode the UDN ID and the client ID in the ELI MAC address in the second three octets of the ELI MAC address comprises the processing unit being operative to encode the client ID in one byte of the second three octets of the ELI MAC address. 17 . A non-transitory computer-readable medium that stores a set of instructions which when executed perform a method executed by the set of instructions comprising: receiving, by a first Access Point (AP), a User Defined Network Identifier (UDN ID) defining a group of client devices, wherein each client device of the group of client devices is assigned a same UDN ID; receiving a client ID associated with a source client device that is associated with the group of client devices; encoding the UDN ID and the client ID in an Extended Local Identifier (ELI) Media Access Control (MAC) address associated with the source client device; substituting a source MAC address of a packet received from the source client device with the ELI MAC address; and forwarding the packet. 18 . The non-transitory computer-readable medium of claim 17 , wherein encoding the UDN ID and the client ID in the ELI MAC address comprises encoding the UDN ID and the client ID in the ELI MAC address in a second three octets of the ELI MAC address. 19 . The non-transitory computer-readable medium of claim 18 , wherein encoding the UDN ID and the client ID in the ELI MAC address in the second three octets of the ELI MAC address comprises encoding the UDN ID in two bytes of the second three octets of the ELI MAC address. 20 . The non-transitory computer-readable medium of claim 18 , wherein encoding the UDN ID and the client ID in the ELI MAC address in the second three octets of the ELI MAC address comprises encoding the client ID in one byte of the second three octets of the ELI MAC address.

Assignees

Inventors

Classifications

  • Layer-2 addresses, e.g. medium access control [MAC] addresses · CPC title

  • for local use, e.g. in LAN or USB networks, or in a controller area network [CAN] · CPC title

  • H04L45/74Primary

    Address processing for routing · CPC title

  • Grouping of entities · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12526282B2 cover?
Group identity assignment and policy enforcement may be provided. A User Defined Network Identifier (UDN ID) defining a group of client devices may be received. Next, a client identifier (ID) associated with a source client device that is associated with the group of client devices may be received. The UDN ID and the client ID may be encoded in an Extended Local Identifier (ELI) Media Access Co…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L45/74. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 13 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).