摘要:
A method for controlling an underlying physical network by a software defined network includes providing a physical network that comprises routers for routing data traffic on a data communication plane, providing a software defined network that comprises at least one controller and at least one feature on a control plane for controlling the data forwarding elements of the physical network, communicating, by the data forwarding elements of the data communication plane, with the controller of the control plane on a dedicated control channel, communicating, by the controller, with the at least one feature on a dedicated feature channel in the control plane, and exchanging, via the data communication plane, at least a portion of the data traffic in the control plane.
摘要:
A method for verifying the identity of a communication partner, in particular in real-time communications, wherein a caller (A) sends a message towards a callee (B), and wherein the caller (A) attaches a self-signed certificate to said message, characterized in that the caller (A) and the callee (B) are part of a web-of-trust, wherein certificates of users within said web-of-trust are stored by one or more key-servers (3), wherein trust relationships between users within said web-of-trust are employed to compute a trust-chain between the caller (A) and the callee (B) based upon the certificate attached to said message and upon the callee's certificate, and wherein the further processing of said message received by the callee (B) is based on the length of the derived trust-chain. Furthermore, a corresponding system is described.
摘要:
A method for operating a flow-based switching system in a network, including at least one network node designed to transport incoming network packets, in particular a switch (20) or a router, wherein the incoming network packets are matched to flows according to predefined policies, wherein a dynamic flow table (40)-primary flow table (50)-containing information about the flows' properties is computed inside the network node or externally and stored in a memory of the network node, is characterized in that another dynamic flow table (40)-backup flow table (60)-is computed and maintained in parallel, wherein the backup flow table (60) is more coarse grained than the primary flow table (50), and wherein the network node switches between employing the primary flow table (50) or the backup flow table (60) depending on the status of predefined observables. Furthermore, a corresponding flow-based switching system is disclosed.