COMMUNICATION DEVICE FOR IMPLEMENTING SELECTIVE ENCRYPTION IN A SOFTWARE DEFINED NETWORK

    公开(公告)号:US20190124053A1

    公开(公告)日:2019-04-25

    申请号:US16230173

    申请日:2018-12-21

    Abstract: The present disclosure pertains to systems and methods for selectively encrypting data flows within a software defined network (SDN). In one embodiment, a communication device may be configured to receive a plurality of unencrypted data packets. The communication device may receive from an SDN controller a criterion used to identify at least one of the unencrypted data flows to be encrypted. Based on the criterion, an encryption subsystem may generate an encrypted data flow the unencrypted data packets based on an encryption key. In some embodiments, the encryption system may parse the packets and encrypt the data payloads without encrypting the routing information associated with the packet. In other embodiments, the encryption subsystem may be configured to encapsulate and encrypt the entire unencrypted data packet. In some embodiments, the encryption subsystem may further be configured to authenticate a sending device and/or to verify the integrity of a message.

    LINK DISCOVERY METHOD AND APPARATUS
    73.
    发明申请

    公开(公告)号:US20190020570A1

    公开(公告)日:2019-01-17

    申请号:US16133286

    申请日:2018-09-17

    Abstract: The disclosure provides a link discovery method and an apparatus. The method includes: sending, by a control plane device, a first message to a plurality of forwarding plane devices in a network to which the control plane device belongs, where the first message is used to instruct each forwarding plane device receiving the first message to send a topology discovery packet at all available ports of the forwarding plane device; receiving, by the control plane device, second messages respectively sent by the plurality of forwarding plane devices, where each of the second messages is generated, according to a first topology discovery packet received at a second port, by a second forwarding plane device sending the second message, and determining, by the control plane device, topology connections between the plurality of forwarding plane devices according to the second messages sent by the plurality of forwarding plane devices.

    Methods and apparatus for providing traffic forwarder via dynamic overlay network

    公开(公告)号:US10075373B2

    公开(公告)日:2018-09-11

    申请号:US15249127

    申请日:2016-08-26

    Applicant: ViaSat, Inc.

    Inventor: Pawan Uberoy

    Abstract: A process capable of facilitating network communication using forwarders or vforwarders interconnected via an overlay network is disclosed. The process, in one aspect, is able to receive a packet stream or network traffic from a customer premise equipment (“CPE”) using a point-to-point (“PTP”) connection via the overlay network. After identifying a service component able to provide a network function (“NF”) in accordance with the packet stream, at least a portion of the packet stream is forwarded to the service component via a second PTP connection through the overlay network according to a set of predefined requirements. Upon receipt of a processed packet stream in response to the packet stream from the service component, the processed packet stream is forwarded to another forwarder via a hop-to-hop (“HTH”) link through the overlay network in accordance with the processed packet stream.

    ROUTE DETERMINING METHOD, AND CORRESPONDING APPARATUS AND SYSTEM

    公开(公告)号:US20180248790A1

    公开(公告)日:2018-08-30

    申请号:US15965849

    申请日:2018-04-28

    Abstract: The present disclosure discloses a route determining method, including: receiving a first flow entry which includes a first route mapping relationship and a first load ratio with respect to a full load capacity of each service node; receiving a second flow entry which includes a second route mapping relationship, a second load ratio with respect to a full load capacity of each service node, and a start time of the second flow entry; receiving a first packet of a first service flow; determining, according to a service chain identifier included in the first packet, that the first service flow is a first type of service flow; determining whether a time corresponding to a timestamp precedes the start time of the second flow entry; and if so, determining a service node for receiving the first packet according to the first flow entry; if not, determining a service node for receiving the first packet according to the second flow entry.

    Method and apparatus for facilitating compatibility between communication networks

    公开(公告)号:US10063466B2

    公开(公告)日:2018-08-28

    申请号:US14609664

    申请日:2015-01-30

    Inventor: Jaye M. Sauer

    Abstract: The described embodiments provide techniques and architectures for enabling interoperability between legacy network systems and Software Defined Networking (SDN) systems. The embodiments add functionality to an SDN system to support interworking between an SDN controlled network, and a legacy network. When upgrading a legacy system to SDN, it may not be possible to upgrade all network components at once. The described embodiments facilitate the use of legacy network components together with SDN system components, by adding new functionality to the SDN data plane elements and control plane elements. The SDN forwarding network elements (NEs) terminate the physical links carrying legacy protocols that include combined data traffic and control information. The new functionality within the SDN forwarding NEs includes processing none or some of the control messages from a legacy NE within an SDN forwarding NE, and then forwarding the remaining control messages to the controller under which that particular SDN forwarding NE is subtended.

Patent Agency Ranking