METHOD AND APPARATUS FOR ENSURING PACKET TRANSMISSION SECURITY
    91.
    发明申请
    METHOD AND APPARATUS FOR ENSURING PACKET TRANSMISSION SECURITY 失效
    用于保护分组传输安全的方法和装置

    公开(公告)号:US20110252228A1

    公开(公告)日:2011-10-13

    申请号:US12672178

    申请日:2008-07-22

    IPC分类号: H04L9/00

    摘要: An apparatus and method for ensuring distributed packet transmission security are provided. In an embodiment of the present invention, a main control board allocates SA information to multiple processing boards according to a pre-defined criterion, so that each processing board which receives and stores the SA information may implement IPSec processing. As such, the IPSec processing is shared by the multiple processing boards. Accordingly, when there are a large number of IPSec tunnels on one interface, the IPSec processing to the packets passing the IPSec tunnels will not completely rely on only the processing board where the interface is located. Instead, the IPSec processing is allocated to different processing boards. Therefore, the multiple processing boards effectively share the IPSec processing corresponding to multiple SAs. The efficiency of the IPSec processing is increased.

    摘要翻译: 提供了一种用于确保分布式分组传输安全性的装置和方法。 在本发明的一个实施例中,主控板根据预先定义的标准将SA信息分配给多个处理板,从而接收和存储SA信息的每个处理板可以实现IPSec处理。 因此,IPSec处理由多个处理板共享。 因此,当一个接口上存在大量IPSec隧道时,对IPSec隧道传输的报文进行IPSec处理不能完全依赖接口所在的处理板。 而是将IPSec处理分配给不同的处理板。 因此,多个处理板有效共享与多个SA相对应的IPSec处理。 IPSec处理效率提高。

    Method and provider edge device for advertising and processing pseudo-wire information
    92.
    发明授权
    Method and provider edge device for advertising and processing pseudo-wire information 有权
    用于广告和处理伪线信息的方法和提供者边缘设备

    公开(公告)号:US08023506B2

    公开(公告)日:2011-09-20

    申请号:US12373862

    申请日:2008-04-25

    申请人: Wei Wei

    发明人: Wei Wei

    IPC分类号: H04L12/28

    摘要: The present invention discloses a method for advertising and processing pseudo-wire (PW) information, which comprises: the sending provider edge (PE) device using two or more methods to group PWs, identifying the group identifier assigned to each PW with each grouping method, and sending all group identifiers of each PW to the receiving PE device; the sending PE device sending to the receiving PE device the notification message that carries information identifying the affected PW group, and the receiving PE device identifying the PWs belonging to the affected PW group according to the received notification. The present invention also discloses the sending and receiving PE devices for advertising and processing PW information. The method and the devices of the present invention can support grouping PWs with more than one method, allowing for flexible use of PW group-based messaging and message processing.

    摘要翻译: 本发明公开了一种广播和处理伪线(PW)信息的方法,包括:使用两种或多种方式对PW进行分组的发送提供商边缘(PE)设备,用分组方法识别分配给每个PW的组标识符 并将每个PW的所有组标识符发送给接收PE设备; 发送PE设备向接收PE设备发送携带识别受影响的PW组的信息的通知消息,以及根据接收到的通知来标识属于受影响的PW组的PW的接收PE设备。 本发明还公开了发送和接收用于广告和处理PW信息的PE设备。 本发明的方法和设备可以通过多种方式支持对PW进行分组,从而允许灵活使用基于PW组的消息和消息处理。

    Midplane of communication device
    93.
    发明授权
    Midplane of communication device 有权
    通讯设备的中平面

    公开(公告)号:US07955087B2

    公开(公告)日:2011-06-07

    申请号:US12297045

    申请日:2007-07-05

    IPC分类号: H01R12/00 H05K1/00

    摘要: A midplane of a communication device, includes the first connectors and the second connectors which connect with each other via high-speed traces, the first connectors arrange in parallel at one side of the midplane, the second connectors arrange in parallel at the other side of the midplane and in parallel with the first connectors. The wiring of high-speed traces between the first connectors and the second connectors can be disposed on the whole midplane, so that it avoids the high density of wiring in part of midplane, reduces the number of layers of the midplane and the complexity of design, and reduces the crosstalk in signals. And the cooling of the whole communication device can be accomplished by only one heat dissipation system, it reduces the complexity of design of the communication device. The area between each frames of the midplane is provided to allocate electrical power in the communication device with two or multiple frames, it reduces the costs of the communication device.

    摘要翻译: 通信装置的中平面包括第一连接器和第二连接器,它们通过高速迹线相互连接,第一连接器在中平面的一侧并排布置,第二连接器在 中平面并与第一连接器并联。 第一连接器和第二连接器之间的高速迹线的布线可以设置在整个中平面上,从而避免了在中平面部分的高密度布线,减少了中平面的层数和设计的复杂性 ,并减少信号中的串扰。 整个通信设备的冷却只能通过一个散热系统来实现,降低了通信设备的设计复杂度。 提供中平面的每个帧之间的区域以在具有两个或多个帧的通信设备中分配电力,这降低了通信设备的成本。

    Method for synchronizing connection state in data communication, and communication node using the same
    94.
    发明授权
    Method for synchronizing connection state in data communication, and communication node using the same 有权
    用于在数据通信中同步连接状态的方法,以及使用其的通信节点

    公开(公告)号:US07860985B2

    公开(公告)日:2010-12-28

    申请号:US12094025

    申请日:2006-06-30

    申请人: Ju Wang

    发明人: Ju Wang

    IPC分类号: G06F15/16

    摘要: The present invention discloses a method for synchronizing connection state in data communication, which includes: a node requests connection state information from an opposite node connected with it and the node updates the local connection state according to the connection state information returned by the opposite node. The invention further discloses a communication node using the method. In the invention, by synchronizing the connection state information between a node that may be out of synchronization and its opposite node connected, the problem of connection state synchronization may be solved substantially, and synchronization may be recovered simply by holding the connection. Further, according to the embodiment of the invention, frequent connection state synchronization inside a high-availability system is no longer necessary, so that system bandwidth and processing capability may be saved, and the original connection may be recovered at any moment when an active/standby switching occurs.

    摘要翻译: 本发明公开了一种在数据通信中同步连接状态的方法,包括:节点从与其相连的相对节点请求连接状态信息,节点根据相对节点返回的连接状态信息更新本地连接状态。 本发明还公开了一种使用该方法的通信节点。 在本发明中,通过使可能不同步的节点与其相连的节点之间的连接状态信息同步,可以实质上解决连接状态同步的问题,并且可以简单地通过保持连接来恢复同步。 此外,根据本发明的实施例,不再需要高可靠性系统内的频繁连接状态同步,从而可以节省系统带宽和处理能力,并且可以在主动/ 发生待机切换。

    Method, apparatus and system for detecting sequence number of packet for transmission of multi-units
    95.
    发明授权
    Method, apparatus and system for detecting sequence number of packet for transmission of multi-units 有权
    用于检测多单元传输的分组序列号的方法,装置和系统

    公开(公告)号:US07860010B2

    公开(公告)日:2010-12-28

    申请号:US12282780

    申请日:2006-07-28

    申请人: Yinzhu Yang

    发明人: Yinzhu Yang

    IPC分类号: H04J1/16 H04L12/28

    摘要: The present invention discloses a method for detecting sequence number of the packet during multi-units sending process, wherein all of the sequence numbers of the packets are pre-divided into non-overlapping subsets, the number of the subsets being at least equal to the number of units comprised by the sending party, and each subset is assigned to a unit; the receiving party determines a sliding window according to each subset, and records the correlation between the sliding window and the sequence number subset; then, the receiving party determines whether the packet is a valid packet according to the correlation and the sequence number of the packet sent from the sending party. At the same time, the invention discloses a packet sending device, a packet receiving device, and a system for detecting sequence number of the packet during multi-units sending process. With the invention, the sequence numbers of the packets sent by the units of the sending party are not overlapped, and after the receiving party receives a packet, it finds the corresponding sliding window according to the sequence number and detects the validity of the packet, so that the accuracy of packet validity detection may be improved, and packet loss may be avoided.

    摘要翻译: 本发明公开了一种用于在多单元发送过程中检测分组的序列号的方法,其中分组的所有序列号被划分为非重叠子集,子集的数量至少等于 发送方包含的单位数,每个子集分配给单位; 接收方根据每个子集确定滑动窗口,并记录滑动窗口和序列号子集之间的相关性; 那么接收方根据从发送方发送的分组的相关性和序列号来确定分组是否是有效分组。 同时,本发明公开了一种分组发送装置,分组接收装置,以及用于在多单元发送处理期间检测分组的序列号的系统。 通过本发明,由发送方发送的分组的序列号不重叠,在接收方接收到分组后,根据序列号找到对应的滑动窗口,并检测分组的有效性, 从而可以提高分组有效性检测的准确性,并且可以避免分组丢失。

    Learning a MAC address in VXLAN
    96.
    发明授权

    公开(公告)号:US10956194B2

    公开(公告)日:2021-03-23

    申请号:US15515443

    申请日:2015-09-23

    摘要: A source Medium Access Control (MAC) address is learned upon receiving a data message from a local network, and a learned local MAC address entry is added to a MAC address forwarding table. A source MAC address is not learned upon receiving a data message from a tunnel. When a local MAC address entry in the MAC address forwarding table changes, a synchronization message is sent via each tunnel associated with a Virtual Extensible Local Area Network (VXLAN) in the changed local MAC address entry, and is saved into a database corresponding to the tunnel. Each tunnel corresponds to one database.

    Port mode synchronization between switches
    97.
    发明授权
    Port mode synchronization between switches 有权
    交换机之间的端口模式同步

    公开(公告)号:US09467397B2

    公开(公告)日:2016-10-11

    申请号:US14403882

    申请日:2013-10-31

    摘要: According to an example, after a primary port of a primary switch and a secondary port of a secondary switch are connected to each other and the primary port is configured to operate in a fabric mode, the primary switch may send a mode switch request packet to the secondary switch through the primary port. The secondary switch may change the secondary port from operating in an Ethernet mode to the fabric mode based on information contained in the mode switch request packet and may send a mode switch response packet to the primary switch.

    摘要翻译: 例如,在主交换机的主端口和辅助交换机的辅助端口相互连接并且主端口被配置为以架构模式操作之后,主交换机可以向模式切换请求分组发送模式切换请求分组 辅助交换机通过主端口。 二级交换机可以根据模式切换请求报文中包含的信息,将二级端口从以太网模式更改为Fabric模式,并可向主交换机发送模式切换响应报文。

    SDN PACKET FORWARDING
    98.
    发明申请
    SDN PACKET FORWARDING 有权
    SDN分组转发

    公开(公告)号:US20160277297A1

    公开(公告)日:2016-09-22

    申请号:US15030508

    申请日:2014-10-23

    发明人: Huifeng CHANG

    IPC分类号: H04L12/743

    CPC分类号: H04L45/7453 H04L45/54

    摘要: A method for forwarding a Software Defined Networking (SDN) packet, applied in a data forwarding device in a SDN network, comprising: dividing a flow table with a plurality of flow table entries according to a class in advance, and obtaining multi-layer flow tables serial in sequence; wherein each layer of flow table corresponds to a class of flow table; and receiving a SDN packet, searching each layer of flow table in sequence according to a precedence order of the multi-layer flow tables, or directly pointing to a specified flow table to search a matched flow table entry, and processing the SDN packet.

    摘要翻译: 一种应用在SDN网络中的数据转发设备中的软件定义网络(SDN)分组的转发方法,其特征在于,包括:根据预先划分具有多个流表表项的流表,并获得多层流 表顺序排列; 其中每个流程表层对应于一类流程表; 并接收SDN分组,根据多层流表的优先顺序依次搜索每个流表,或直接指向指定的流表,搜索匹配的流表项,并处理该SDN分组。

    CALCULATING A SHORTEST PATH FIRST TREE
    99.
    发明申请
    CALCULATING A SHORTEST PATH FIRST TREE 审中-公开
    计算最短路径第一树

    公开(公告)号:US20160277283A1

    公开(公告)日:2016-09-22

    申请号:US15031166

    申请日:2014-10-28

    发明人: Zhiming HUANG

    IPC分类号: H04L12/721 H04L12/751

    摘要: A method is described in which a first shortest path bridging (SPB) node and a neighboring second SPB node are connected via n links; a plurality of different neighborhoods are established between the first node and the second SPB node; and a shortest path first (SPF) tree is calculated in accordance with the links with the same cost.

    摘要翻译: 描述了一种通过n个链路连接第一最短路径桥接(SPB)节点和相邻的第二SPB节点的方法; 在第一节点和第二SPB节点之间建立多个不同的邻域; 并且根据具有相同成本的链路来计算最短路径优先(SPF)树。

    Expanding member ports of a link aggregation group between clusters
    100.
    发明授权
    Expanding member ports of a link aggregation group between clusters 有权
    在群集之间扩展链路聚合组的成员端口

    公开(公告)号:US09450856B2

    公开(公告)日:2016-09-20

    申请号:US14352940

    申请日:2012-12-20

    摘要: According to an example, in a method and an apparatus for expanding member ports of a link aggregation group between clusters, each apparatus in a cluster receives a port joining link aggregation group message sent by a master control board on a master apparatus in the cluster. In response to an apparatus determining that a newly joined port is a port on the apparatus itself and also is the first member port in the link aggregation group of the cluster, the newly joined port is associated with the link aggregation group. By applying the method and the apparatus for expanding member ports of a link aggregation group between clusters in this manner, according to an example, the number of member links in the link aggregation group between clusters is able to be increased, and the robustness of the network interconnection between clusters is also able to be enhanced.

    摘要翻译: 根据示例,在群集之间的用于扩展链路聚合组的成员端口的方法和装置中,群集中的每个装置在集群中的主设备上接收由主控板发送的端口加入链路聚合组消息。 响应于设备确定新加入的端口是设备本身的端口,并且也是集群的链路聚合组中的第一成员端口,新加入的端口与链路聚合组相关联。 通过以这种方式应用用于在集群之间扩展链路聚合组的成员端口的方法和装置,根据一个示例,可以增加集群之间的链路聚合组中的成员链路的数量,并且可靠性 集群之间的网络互连也能够被增强。