METHOD AND DEVICE FOR MANAGING MESSAGES BROADCAST IN A LOCAL NETWORK

The method and device analyze network topology to apply filtering rules, addressing incorrect message filtering in LANs, ensuring secure and operational integrity by managing subnetworks.

FR3141586B1Active Publication Date: 2025-07-18SAGEMCOM BROADBAND SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022011405
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-02
Publication Date
2025-07-18
Estimated Expiration
2042-11-02

AI Technical Summary

Technical Problem

In local area networks (LANs), wireless communication coverage extension systems face issues with equipment incorrectly filtering messages from primary and secondary subnetworks, leading to security risks and operational problems such as clients losing access to the primary subnetwork due to indistinguishable IPv6 configurations.

Method used

A method and device that analyze the local network topology to apply filtering rules, ensuring only legitimate recipients receive broadcast messages by deleting or transforming packets based on identifying information, using compatible nodes and switches to manage subnetworks.

Benefits of technology

Guarantees that only intended recipients receive broadcast messages, preventing security risks and operational issues by correctly filtering messages between primary and secondary subnetworks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000015_0000
    Figure 00000015_0000
  • Figure 00000015_0001
    Figure 00000015_0001
  • Figure 00000015_0002
    Figure 00000015_0002
Patent Text Reader

Abstract

The present invention relates to a method and a device for managing messages broadcast in a local network comprising nodes allowing an extension of wireless communication coverage and stations, the nodes being connected to each other by a routing subnetwork, at least one node transmitting at least one wireless network called a front network to which the stations connect, the local network comprising a primary subnetwork and a secondary subnetwork, the primary subnetwork being a subnetwork to which the links of the routing network and the nodes belong, the secondary subnetwork being a subnetwork composed of at least one station and which is isolated from the rest of the local network by a virtual network.According to the invention, a node capable of applying filtering rules: - orders (E300) an analysis of the topology of the local network, - determines (E301), from the topology of the local network, the filtering rules to be applied, - applies (E302) the determined filtering rules to the broadcast packets comprising at least one piece of information identifying the virtual network. Fig. 3a.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: METHOD AND DEVICE FOR MANAGING MESSAGES BROADCAST IN A LOCAL NETWORK Technical field

[0001] The present invention relates to a method and a device for managing messages broadcast in a local network comprising a subnetwork called the primary subnetwork and one or more subnetworks called the secondary subnetwork(s), the local network comprising nodes allowing an extension of wireless communication coverage. STATE OF PRIOR ART

[0002] In local area networks (LANs), wireless communication coverage extension systems can be used to increase the range of these local area networks (LANs) by coordinating several distributed access points (APs). These different access points (APs) are integrated into communication nodes, simply called nodes hereinafter, interconnected by means of a routing or backhaul subnetwork and all provide the same wireless local area network (WLAN).

[0003] The nodes of the routing subnetwork are connected to each other using a tree-like mesh structure, whereby a node can act as a relay between two other nodes of the routing subnetwork. The nodes of the routing subnetwork are thus interconnected using wired links, for example Ethernet, or wireless links. The nodes of the routing subnetwork are connected to each other by a network also called a “BackHaul Network” which can be either wired, wireless, or a combination of both.

[0004] Each node of the routing subnetwork possibly emits at least one wireless network called a "FrontHaul Network" or front network to which the user's stations connect. This front network, if it uses Wi-Fi / IEEE 802.11 technology, is the equivalent of what is called BSS (Basic Service Set).

[0005] At least one of the nodes in the routing subnetwork is connected to a residential gateway that provides access to the Internet. The residential gateway may also be part of the routing subnetwork.

[0006] Currently, when a station, also called a client, is connected by a wired link such as Ethernet, the station can receive data that is not intended for it.

[0007] In addition to security risks (information disclosure), this situation may also cause operational problems. Indeed, some equipment does not correctly filter messages when receiving them and treats messages from the primary subnet and those from a secondary subnet in the same way.

[0008] Such equipment can therefore, for example, indifferently receive IPv6 type configurations intended respectively for each of the two subnetworks. These different configurations can cause a client to lose access to the primary subnetwork, the client retaining the configuration corresponding to the secondary subnetwork. Statement of the invention

[0009] The proposed invention makes it possible to guarantee that only legitimate recipients receive a message, for example a broadcast message, according to the criterion of the VLANs applied to these messages.

[0010] To this end, according to a first aspect, an embodiment proposes a method for managing messages broadcast in a local network comprising nodes allowing an extension of wireless communication coverage and stations, the nodes allowing an extension of coverage being connected to each other by a routing subnetwork, at least one node allowing an extension of wireless communication coverage transmitting at least one wireless network, called a front-end network, to which the stations connect, the local network comprising a primary subnetwork and a secondary subnetwork, the primary subnetwork being a subnetwork to which the links of the routing network and the nodes belong, the secondary subnetwork being a subnetwork composed of at least one station and which is isolated from the rest of the local network by a virtual network, characterized in that the method comprises the steps, executed by a node capable of applying filtering rules, of:

[0011] - ordering an analysis of the local network topology,

[0012] - determination from the topology of the local network of filtering rules to apply,

[0013] - application of the determined filtering rules on the broadcast packets comprising at least one piece of information identifying the virtual network.

[0014] The invention also relates to a device for managing messages broadcast in a local network comprising nodes allowing an extension of wireless communication coverage and stations, the nodes allowing an extension of coverage being connected to each other by a routing subnetwork, at least one node allowing an extension of wireless communication coverage transmitting at least one wireless network called a front network to which the stations are connected, the local network comprising a primary subnetwork and a secondary subnetwork, the subnetwork primary being a subnetwork to which the links of the routing network and the nodes belong, the secondary subnetwork being a subnetwork composed of at least one station and which is isolated from the rest of the local network by a virtual network, characterized in that the device is included in a node capable of applying filtering rules and comprises:

[0015] - means for controlling an analysis of the topology of the local network,

[0016] - means for determining, from the topology of the local network, rules of filtering to apply,

[0017] - means for applying the determined filtering rules to the broadcast packets containing at least one piece of information identifying the virtual network.

[0018] Thus, the present invention makes it possible to guarantee that only legitimate recipients receive a broadcast message.

[0019] According to a particular mode, the analysis of the network topology includes a determination of the presence of a node unable to apply the filtering rules and / or the presence of a switch connected to the routing subnetwork.

[0020] According to a particular mode, the application of the filtering rules to be applied is broken down into sub-steps of:

[0021] - deletion of broadcast packets containing an identifier of a subnetwork secondary on the primary network interfaces of the front-end network.

[0022] - deletion of broadcast packets containing information identifying a secondary subnet on the routing subnet interfaces connected to an incompatible switch and / or node,

[0023] - transformation of broadcast packets intended for equipment of a sub- secondary network for which the path from the transmitter passes through a switch or an incompatible node in unicast packets.

[0024] According to a particular mode, if the local network only comprises nodes capable of applying the filtering rules and no switches, each compatible node deletes the broadcast packets having information identifying a secondary subnetwork on the primary interfaces of the routing subnetwork.

[0025] According to a particular mode, the application of the filtering rules to be applied is broken down into sub-steps of:

[0026] - transformation of broadcast messages sent in secondary subnetworks into unicast messages at each compatible node.

[0027] According to a particular mode, the determination of the network topology is broken down into sub-steps of:

[0028] - generation of a table representing the subnetwork to which each belongs interface and each bridge of a node,

[0029] - generation of a table representing the list of equipment in the local network,

[0030] - generation of a table representing the type of each piece of equipment in the local network,

[0031] - generation of a table allowing the connection interface of each to be determined local network equipment,

[0032] - generation of a table describing for each interface its membership in the sub- routing network or front-end subnet,

[0033] - generation of a table describing for each equipment whether it is physically linked to a front-end network interface,

[0034] - generation of a table describing for each station whether it is connected phy only to an interface of a node.

[0035] According to a particular embodiment, the method is executed by a node called a residential gateway which provides access to an Internet network.

[0036] A particular embodiment also relates to a computer program product. It comprises instructions for implementing, by a device, the method according to one of the preceding embodiments, when said program is executed by a processor of the device.

[0037] A particular embodiment also relates to a storage medium. It stores a computer program comprising instructions for implementing, by a node device, the method according to one of the preceding embodiments, when said program is executed by a processor of the node device. Brief description of the drawings

[0038] The above-mentioned features of the invention, as well as others, will appear more clearly on reading the following description of an exemplary embodiment, said description being made in relation to the attached drawings, among which:

[0039] [Fig.l] schematically illustrates an example of a local area network in one embodiment;

[0040] [Fig.2] schematically illustrates the architecture of a node according to one embodiment;

[0041] [Fig.3a] illustrates an example of a method carried out according to one embodiment;

[0042] [Fig.3b] illustrates an example of a method for determining a network topology local according to an embodiment;

[0043] [Fig.4] illustrates an example of a table representing the subnet to which each interface and each bridge of a node belongs;

[0044] [Fig.5] illustrates an example of a table representing the list of local network equipment;

[0045] [Fig.6] illustrates an example of a table representing the type of each piece of equipment in the local network;

[0046] [Fig.7] illustrates an example of a table for determining the interface of connection of each device on the local network;

[0047] [Fig.8] illustrates an example of a table describing for each interface its ap membership in the routing subnet or front-end subnet;

[0048] [Fig.9] illustrates an example of a table describing for each equipment whether it is physically linked to a front-end network interface;

[0049] [Fig. 10] illustrates an example of a table describing for each station whether it is physically connected to an interface of a node;

[0050] [Fig. 11] illustrates an example of a table describing the topology of the local network;

[0051] [Fig. 12] illustrates an example of an algorithm for applying filtering rules according to an embodiment.

[0052] DETAILED DESCRIPTION OF EMBODIMENTS

[0053] [Fig.l] illustrates an example of a local area network in one embodiment.

[0054] The local network has three GW nodes, EXT1 and EXT2. The GW node is by example a residential GW gateway which provides access to a wide area network, such as the Internet.

[0055] The EXT1 and EXT2 nodes are, for example, wireless communication coverage extension systems which are used to increase the range of the local network by coordinating several distributed AP access points. These different AP access points are integrated into the nodes which are interconnected by means of a routing or backhaul subnetwork and all provide the same WLAN wireless local area network.

[0056] The node EXT1 is for example a compatible node according to embodiments and the node EXT2 is for example an incompatible node. A compatible node is a node capable of, or adapted to, carry out the filtering rules defined according to embodiments. An incompatible node is a node which is incapable of, or which is not adapted to, carry out the filtering rules defined according to embodiments.

[0057] The term “node” is understood hereinafter to mean equipment offering connectivity capabilities and constituting the local mesh network.

[0058] The local network comprises a plurality of PCI stations, PC2, PC3, PC4, PC5 and PC6.

[0059] The term “station” is hereinafter understood to mean fixed or mobile equipment using the resources of the mesh LAN through the nodes of said LAN. A station is, for example, a wireless mobile terminal, a wireless speaker, a personal computer.

[0060] The GW node has a BRLANG bridge, also called a “bridge” in English, belonging to the primary subnetwork and a BR_GUESTG bridge belonging to the secondary subnetwork.

[0061] The primary subnetwork is a subnetwork to which the links of the routing network and the access points belong, it is unique in the local network.

[0062] The secondary subnet is a subnet composed of one or more customer devices and which is isolated from the rest of the local network by a virtual network (VLAN). A local network can contain zero, one or more secondary subnets.

[0063] The BRLANG and BR_GUESTG bridges are interconnected, allowing data flow exchange between them.

[0064] The interfaces ETH0, ETH1, ETH4 and WL0 are connected to the BRLANG bridge and are primary type interfaces. In this non-limiting example, the prefix ETH designates a communication interface via a wired network of the Ethernet type, and the prefix WL designates a communication interface via a wireless network.

[0065] The WL0.1 interface is connected to the BR_GUESTG bridge and is a secondary type interface.

[0066] Station PC3 is connected to the BRLANG bridge via the ETH4 interface.

[0067] Station PC6 is connected to the BR_GUESTG bridge via the interface WL0.1.

[0068] The EXT1 node has a BRLAN1 bridge belonging to the primary subnet and a BR_GUEST1 bridge belonging to the secondary subnet.

[0069] The EXT1 node is a compatible node.

[0070] The BRLAN1 and BR_GUEST1 bridges are interconnected in order to be able to exchange data.

[0071] The ETH2 and ETH3 interfaces are connected to the BRLAN1 bridge and are primary type interfaces.

[0072] The APGUEST1 interface is connected to the BR_GUEST1 bridge and is a secondary type interface.

[0073] Station PC2 is connected to bridge BRLAN1 via interface ETH3.

[0074] Station PC4 is connected to bridge BR_GUEST1 via the interface APGUEST1.

[0075] A switch SW is connected to the ETH0 and ETH2 interfaces and a PCI station is connected to the switch SW. In one example, this switch SW is a packet switch called a “switch” in English.

[0076] The EXT2 node has a BRLAN2 bridge belonging to the primary subnet and a BR_GUEST2 bridge belonging to the secondary subnet.

[0077] The EXT2 node is an incompatible node.

[0078] The BRLAN2 and BR_GUEST2 bridges are connected to the ETH1 interface.

[0079] Station PC5 is connected to bridge BR_GUEST2 via interface APGUEST2.

[0080] [Fig.2] schematically illustrates the architecture of a node according to a mode of rea- lization.

[0081] According to the example of hardware architecture represented in [Fig.2], one of the nodes or several of the nodes GW, EXT1 and EXT2, comprise, connected by a communication bus 200: a processor or CPU (“Central Processing Unit” in English) 201; a RAM (“Random Access Memory” in English) 202; a ROM (“Read Only Memory” in English) 203; a storage unit such as a hard disk (or a storage media reader, such as an SD (“Secure Digital” in English) card reader) 204; at least one communication interface 205 allowing the node to communicate with the equipment of the local network.

[0082] The processor 201 is capable of executing instructions loaded into the RAM 202 from the ROM 203, from an external memory (not shown), from a storage medium (such as an SD card), or from a communication network. When the node is powered on, the processor 201 is capable of reading instructions from the RAM 202 and executing them. These instructions form a computer program causing the processor 201 to implement all or part of the method described in relation to Figs. 3.

[0083] The method described below in relation to Figs. 3 may be implemented in software form by executing a set of instructions by a programmable machine, for example a DSP (Digital Signal Processor) or a microcontroller, or be implemented in hardware form by a dedicated machine or component, for example an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). In general, the node comprises electronic circuitry configured to implement the methods described in relation to Figs. 3.

[0084] [Fig.3a] illustrates an example of a method executed according to an embodiment.

[0085] In step E300, a node, for example the GW node, commands an analysis of the topology of the local network and determines whether at least one node of the local network is incompatible or whether a switch is present in the local network. In an embodiment in which the EasyMesh standard is used, the compatible equipment adds in a message, for example of the “Auto-Configuration Search” type, information of the “vendor-specified TLV” type, the presence of which indicates the compatibility of said equipment with the method described here. The absence of this information in a message thus characterizes the equipment having sent it as not compatible.

[0086] In step E301, the GW node determines, from the topology of the local network, filtering rules to be applied.

[0087] In step E302, the GW node commands the application of the determined filtering rules.

[0088] [Fig.3b] illustrates an example of a method for determining a topology of the local network according to one embodiment.

[0089] In step E310, the GW node determines the different bridges it has, the interfaces connected to them and the type of subnetwork to which they belong.

[0090] According to the example of [Fig.4], the GW node has two bridges BRLANG and BR_GUESTG and five network interfaces ETH0, ETH1, ETH4, WL0 and WL0.1.

[0091] The BRLANG bridge belongs to the primary subnet and the BR_GUESTG bridge belongs to the secondary subnet.

[0092] The ETH0, ETH1, ETH4 and WL0 interfaces are primary type interfaces.

[0093] The WL0.1 interface is a secondary type interface.

[0094] In step E311, the GW node obtains the list of all the equipment known by the GW, EXT1 and EXT2 nodes.

[0095] According to the example of [Fig.5], the equipment is as follows: the bridges BRLAN1 and BR_GUEST1 of the node EXT1, the bridges BRLAN2 and BR_GUEST2 of the node EXT2, the PCI stations to PC6.

[0096] The list is for example obtained from the ARP (“Address Resolution Protocol”) table.

[0097] In step E312, the GW node obtains a list which, for all the equipment, identifies the compatible or incompatible equipment as well as the stations.

[0098] According to the example of [Fig.6], the bridges BRLAN1 and BR_GUEST1 of the node EXT1 have compatible PA access point interfaces, the bridges BRLAN2 and BR_GUEST2 of the node EXT2 have PA access point interfaces which are not compatible and the stations are PCI to PC6.

[0099] In step E313, the GW node completes the list which, for all the equipment, identifies the compatible or incompatible equipment as well as the stations by identifying the network interface of the GW node allowing communication with the equipment.

[0100] According to the example of [Fig.7], the bridges BRLAN1 and BR_GUEST1 of the node EXT1 are compatible and the ETH0 interface of the node GW allows communication with them. The bridges BRLAN2 and BR_GUEST2 of the node EXT are incompatible and the ETH1 interface of the node GW allows communication with them. The ETH0 interface of the node GW allows communication with the stations PCI, PC2 and PC4

[0101] The ETH4 interface of the GW node allows communication with the PC3 station, the ETH1 interface of the GW node allows communication with the PC5 station and the WL0.1 interface of the GW node allows communication with the PC6 station.

[0102] In step E314, the GW node determines a table describing for each of its network interfaces its membership in the routing subnetwork or the front subnetwork.

[0103] According to the example of [Fig.8], the network interfaces ETH0, ETH1 are primary interfaces belonging to the routing network BH, the network interface ETH4 is a interface of the primary subnet belonging to the FH front-end network, the WLO network interface is an interface of the primary subnet belonging to the front-end network, and the WL0.1 network interface is an interface of the secondary network belonging to the front-end network.

[0104] In step E315, the GW node determines a table describing for each device whether it is physically linked to an interface of the front network of the GW node.

[0105] Thus, according to the example of [Fig.9], the stations PC3 and PC6 are physically or directly connected, as illustrated by the “Direct” column of [Fig.9], to a front network of the GW node respectively by the network interface ETH4 and WL0.1.

[0106] In step E316, the GW node determines a table describing for each station whether it is physically connected to an interface of a node.

[0107] Thus, according to the example of [Fig. 10], the PCI station is not physically connected to a network interface of a node.

[0108] Station PC2 is physically connected to a network interface of node GW, station PC3 is physically connected to a network interface of node GW, station PC4 is physically connected to a network interface of node EXT1, station PC5 is physically connected to a network interface of node EXT2 and station PC6 is physically connected to a network interface of node GW.

[0109] In step E317, the GW node determines the topology of the local network.

[0110] According to the example of [Fig.l 1], the bridge BRLAN1 is a bridge of a compatible node, communicating with the GW node on the network interface ETH0 and is part of the primary subnet. The bridge BR_GUEST1 is a bridge of a compatible node, communicating with the GW node on the network interface ETH0 and is part of the secondary subnet. The bridge BRLAN2 is a bridge of an incompatible node, communicating with the GW node on the network interface ETH1 and is part of the primary subnet. The bridge BR_GUEST2 is a bridge of an incompatible node, communicating with the GW node on the network interface ETH1 and is part of the primary subnet. The PCI station communicates with the GW node on the network interface ETH0 and is part of the primary subnet. The PC2 station communicates with the GW node on the network interface ETH0 and is part of the primary subnet.Station PC3 communicates with the GW node on the ETH4 network interface, is part of the primary subnet, and is directly connected to the GW node. Station PC4 communicates with the GW node on the ETH0 network interface and is part of the secondary subnet. Station PC5 communicates with the GW node on the ETH1 network interface and is part of the secondary subnet. Station PC6 communicates with the GW node on the WL0.1 network interface, is part of the secondary subnet, and is physically or directly connected to the GW node.

[0111] In the example of [Fig.3b], the GW node executes steps E310 to E317.

[0112] Alternatively, some of steps E310 to E317 are optional. For example, some of these steps may have been performed during a previous implementation of the method for determining a topology of the local network according to an embodiment, and the result of these respective steps may have been saved by the GW node.

[0113] [Fig. 12] illustrates an example of an algorithm for applying filtering rules according to one embodiment.

[0114] In step E1200, each compatible node deletes the broadcast packets comprising information identifying a secondary subnetwork on the interfaces of the primary subnetwork of the front-end network.

[0115] In step E1201, each compatible node deletes the broadcast packets comprising at least one piece of information identifying a secondary subnetwork, for example at least one piece of information identifying a virtual network, on the interfaces of the routing subnetwork connected to a switch and / or to an incompatible node.

[0116] The broadcast packets comprising at least one piece of information identifying a secondary subnetwork are actually in the secondary subnetwork, destined for the secondary subnetwork and the at least one piece of information identifying a secondary subnetwork is for example an encapsulation of the virtual network which makes it possible to isolate the different networks from each other.

[0117] In step E1202, each compatible node transforms the broadcast packets intended for equipment of a secondary subnetwork for which the path from the transmitter passes through a switch or an incompatible node into unicast packets.

[0118] In step E1203, each compatible node maintains the multicast transmission of broadcast messages comprising information identifying a secondary subnetwork on the primary network interfaces or towards the compatible node(s).

[0119] Alternatively, when the local network comprises at least one incompatible node or switch, the broadcast messages sent in the secondary subnetworks are transformed into unicast messages at each compatible node.

[0120] Alternatively, only one or some of the steps described in association with [Fig. 12] are performed when applying filtering rules.

[0121] For example, the GW node transforms all multicast packets into unicast messages to stations PC4, PC5 and PC6 and bridges BR_GUEST1 and BR_GUEST2.

[0122] Thus, a packet broadcast on the BR_GUESTG interface is replaced by the transmission of four unicast packets. There are no more broadcast (multicast) packets transmitted on the BR_GUESTG interface.

[0123] The transformation of all broadcast packets into unicast messages intended for stations PC4, PC5 and PC6 can be carried out at the network interfaces to which stations PC4, PC5 and PC6 are connected.

[0124] It should be noted here that, when the local network only comprises compatible nodes and no switches, each compatible node deletes broadcast packets having information identifying a secondary subnet on the primary interfaces of the routing subnet.

Claims

Claims

1. Method for managing messages broadcast in a local network comprising nodes allowing an extension of wireless communication coverage and stations, the nodes allowing an extension of coverage being connected to each other by a routing subnetwork, at least one node allowing an extension of wireless communication coverage transmitting at least one wireless network called a front network to which the stations connect, the local network comprising a primary subnetwork and a secondary subnetwork, the primary subnetwork being a subnetwork to which the links of the routing network and the nodes belong, the secondary subnetwork being a subnetwork composed of at least one station and which is isolated from the rest of the local network by a virtual network, characterized in that the method comprises the steps, executed by a node capable of applying filtering rules, of: - controlling (E300) an analysis of the topology of the local network,- determination (E301), from the topology of the local network, of filtering rules to be applied, - application (E302) of the determined filtering rules on the packets broadcast containing at least one piece of information identifying the virtual network.,

2. Method according to claim 1, characterized in that the analysis of the network topology includes a determination of the presence of a node unable to apply the filtering rules and / or the presence of a switch connected to the routing subnetwork.

3. Method according to claim 2, characterized in that the application of the filtering rules to be applied is broken down into sub-steps of: - deletion of broadcast packets comprising information identifying a secondary subnetwork on the interfaces of the primary subnetwork of the front-end network, - deletion of broadcast packets comprising information identifying a secondary subnetwork on the interfaces of the routing subnetwork connected to a switch and / or to an incompatible node, - transformation of broadcast packets intended for equipment of a secondary subnetwork for which the path from the transmitter passes through a switch or an incompatible node into unicast packets.

4. Method according to claim 2, characterized in that if the local network only comprises nodes capable of applying the filtering rules and no switches, each compatible node deletes the broadcast packets having information identifying a secondary subnetwork on the primary interfaces of the routing subnetwork.

5. Method according to claim 2, characterized in that the application of the filtering rules to be applied is broken down into the sub-step of: - transformation of the broadcast messages sent in the secondary sub-networks into unicast messages at the level of each compatible node.

6. Method according to any one of the preceding claims, characterized in that the determination of the network topology is broken down into sub-steps of: - generation of a table representing the subnetwork to which each interface and each bridge of a node belong, - generation of a table representing the list of equipment of the local network, - generation of a table representing the type of each equipment of the local network, - generation of a table making it possible to determine the connection interface of each equipment of the local network, - generation of a table describing, for each interface, its membership in the routing subnetwork or in the front subnetwork, - generation of a table describing for each equipment whether it is physically linked to an interface of the front network, - generation of a table describing for each station whether it is physically connected to an interface of a node.

7. Method according to any one of the preceding claims, characterized in that the method is executed by a node called a residential gateway which provides access to an Internet network.

8. Device for managing messages broadcast in a local network comprising nodes allowing an extension of wireless communication coverage and stations, the nodes allowing an extension of coverage being connected to each other by a routing subnetwork, at least one node allowing an extension of wireless communication coverage transmitting at least one wireless network called a front network to which the stations connect, the local network comprising a primary subnetwork and a secondary subnetwork, the primary subnetwork being a subnetwork to which the links of the network belong routing and nodes, the secondary subnetwork being a subnetwork composed of at least one station and which is isolated from the rest of the local network by a virtual network, characterized in that the device is included in a node capable of applying filtering rules and comprises: - means of controlling an analysis of the topology of the local network, - means of determining, based on the topology of the local network, filtering rules to be applied, - means of applying the determined filtering rules to the broadcast packets containing at least one piece of information identifying the secondary subnetwork.

9. A computer program product characterized in that it comprises instructions for implementing, by a node, the method according to any one of claims 1 to 7, when said program is executed by a processor of a node.

10. A storage medium characterized in that it stores a computer program comprising instructions for implementing, by a node, the method according to any one of claims 1 to 7, when said program is executed by a processor of a node.