NETWORK ACCESS CONTROL
    1.
    发明申请
    NETWORK ACCESS CONTROL 审中-公开
    网络访问控制

    公开(公告)号:US20160277929A1

    公开(公告)日:2016-09-22

    申请号:US15030542

    申请日:2014-10-21

    发明人: Jia LIU

    摘要: An access device receives a neighbor discovery protocol (NDP) packet sent from a user equipment (UE). The access device parses the NDP packet to obtain equipment information of the UE carried by the NDP packet. The access device transmits reporting message to a management server, wherein the reporting message carries the equipment information of the UE. Upon receiving a notification for identity authentication of the UE from the management server, the access device initiates an identity authentication invitation to the UE. The access device submits identity authentication information of the UE to the management server for authentication. The access device stores a first access control entry for the UE issued by the management server in its own data plane to control the UE's access to network resources after the identity authentication of the UE is permitted.

    摘要翻译: 接入设备接收从用户设备(UE)发送的邻居发现协议(NDP)报文。 接入设备解析NDP报文,获取NDP报文携带的UE的设备信息。 接入设备向管理服务器发送报告消息,其中报告消息携带UE的设备信息。 在从管理服务器接收到用于UE的身份认证的通知时,接入设备向UE发起身份认证邀请。 接入设备向管理服务器提交UE的身份认证信息进行认证。 访问设备在自己的数据平面中存储由管理服务器发布的UE的第一访问控制条目,以在允许UE的身份认证之后控制UE对网络资源的访问。

    DATA PROCESSING
    2.
    发明申请
    DATA PROCESSING 审中-公开
    数据处理

    公开(公告)号:US20160269428A1

    公开(公告)日:2016-09-15

    申请号:US15031630

    申请日:2014-10-31

    IPC分类号: H04L29/06 G06F17/30 H04L29/08

    摘要: A service logic layer module receives an application message forwarded by a network device, classifies and identifies an application type of the application message, and determines a first processing operation to be performed to the application message based on an identification result. The service logic layer module receives a processing result returned from a data processing layer module, and determines a second processing operation based on the processing result. When the processing operation is an I/O processing operation for a single task, the data processing layer module controls I/O concurrency processing of the single task and returns a final processing result to the service logic layer module. When the processing operation is a data searching operation, the data processing layer module performs the data searching operation to obtain a final searching result, and returns the final searching result to the service logic layer module.

    摘要翻译: 服务逻辑层模块接收由网络设备转发的应用消息,对应用消息的应用类型进行分类和识别,并根据识别结果确定要对应用消息执行的第一处理操作。 服务逻辑层模块接收从数据处理层模块返回的处理结果,并且基于处理结果确定第二处理操作。 当处理操作是单个任务的I / O处理操作时,数据处理层模块控制单个任务的I / O并发处理,并将最终处理结果返回给服务逻辑层模块。 当处理操作是数据搜索操作时,数据处理层模块执行数据搜索操作以获得最终搜索结果,并将最终搜索结果返回给服务逻辑层模块。

    DATA FORWARDING
    3.
    发明申请
    DATA FORWARDING 审中-公开
    数据转发

    公开(公告)号:US20160266925A1

    公开(公告)日:2016-09-15

    申请号:US15031514

    申请日:2014-10-23

    发明人: Chushun WEI

    摘要: A data forwarding device includes a plurality of server interface units, a plurality of virtual network card units and a network interface unit. A server interface unit of the plurality of server interface units is to obtain a data frame to be sent by a virtual network card driver running on a server corresponding to the server interface unit and obtain a first fusion descriptor, and to send the first fusion descriptor and the data frame to a virtual network card unit that corresponds to the virtual network card driver, wherein the first fusion descriptor comprises a type of the descriptor and a length of the data frame. The virtual network card unit is to process the data frame according to the first fusion descriptor, and to send a processed data frame to the network interface unit. The network interface unit is to forward the processed data frame to an external network.

    摘要翻译: 数据转发装置包括多个服务器接口单元,多个虚拟网卡单元和网络接口单元。 多个服务器接口单元的服务器接口单元是获得由与服务器接口单元相对应的服务器上运行的虚拟网卡驱动程序发送的数据帧,并获得第一融合描述符,并且发送第一融合描述符 以及数据帧到对应于虚拟网卡驱动器的虚拟网卡单元,其中第一融合描述符包括描述符的类型和数据帧的长度。 虚拟网卡单元将根据第一融合描述符处理数据帧,并将经处理的数据帧发送到网络接口单元。 网络接口单元将处理的数据帧转发到外部网络。

    PACKET FORWARDING IN DATA CENTER NETWORK
    4.
    发明申请
    PACKET FORWARDING IN DATA CENTER NETWORK 审中-公开
    数据中心网络中的数据包转发

    公开(公告)号:US20160261496A1

    公开(公告)日:2016-09-08

    申请号:US15031522

    申请日:2014-10-31

    发明人: Huifeng CHANG

    摘要: The present disclosure provides a method and apparatus for forwarding a packet, wherein the method comprising: for each Virtual Machine (VM) in the server, obtaining relevant information of a virtual Network Interface Controller (vNIC) of the VM, and associating the obtained relevant information with a local virtual port, wherein the relevant information includes a Media Access Control (MAC) address of the vNIC, a Virtual eXtensible Local Area Network (VXLAN) Network Identifier (VNI) of the VXLAN where the vNIC is located, and a Virtual Local Area Network (VLAN) Identifier (ID) of a VLAN associated with the VXLAN where the vNIC is located; after receiving an Ethernet packet sent by the server, searching a VNI according to a source MAC address of the Ethernet packet and a VLAN ID; and according to the searched VNI, encapsulating the Ethernet packet, obtaining a VXLAN packet, and forwarding the VXLAN packet.

    摘要翻译: 本公开提供了一种用于转发分组的方法和装置,其中所述方法包括:对于服务器中的每个虚拟机(VM),获得VM的虚拟网络接口控制器(vNIC)的相关信息,并且将获得的相关 具有本地虚拟端口的信息,其中相关信息包括vNIC的媒体访问控制(MAC)地址,vNIC所在的VXLAN的虚拟可扩展局域网(VXLAN)网络标识符(VNI)以及虚拟 与VNIC所在的VXLAN相关联的VLAN的局域网(VLAN)标识符(ID); 收到服务器发送的以太网报文后,根据以太网报文的源MAC地址和VLAN ID进行VNI的查询; 并根据搜索到的VNI封装以太网报文,获得VXLAN报文,并转发VXLAN报文。

    DYNAMIC LINK AGGREGATION
    5.
    发明申请
    DYNAMIC LINK AGGREGATION 有权
    动态链接聚合

    公开(公告)号:US20160212094A1

    公开(公告)日:2016-07-21

    申请号:US14899781

    申请日:2014-09-28

    发明人: Zhonghai LUO Chao LV

    摘要: At least two Ethernet sub-interfaces are established on a first Ethernet interface and a second Ethernet interface of a first device, and each Ethernet sub-interface is assigned to a VLAN. The Ethernet sub-interfaces on the same Ethernet interface are assigned to different VLANs, and Ethernet sub-interfaces of the first Ethernet interface and the second Ethernet interface which belong to the same VLAN are added into a link-aggregation group to establish an aggregated link with a second device.

    摘要翻译: 在第一个以太网接口和第一个设备的第二个以太网接口上建立至少两个以太网子接口,并将每个以太网子接口分配给一个VLAN。 同一以太网接口上的以太网子接口分配给不同的VLAN,将属于同一VLAN的第一个以太网接口和第二个以太网接口的以太网子接口添加到链路聚合组中,建立聚合链路 与第二个设备。

    PACKET FORWARDING
    6.
    发明申请
    PACKET FORWARDING 审中-公开
    分组前进

    公开(公告)号:US20160197824A1

    公开(公告)日:2016-07-07

    申请号:US14899925

    申请日:2014-09-24

    IPC分类号: H04L12/721

    CPC分类号: H04L45/38 H04L12/6418

    摘要: A controller of a virtual switch system receives an uplink packet forwarded by a SDN switch hosted on a server from a VM (virtual machine) hosted on the server. The controller determines an outgoing interface from at least two uplink interfaces on the SDN switch respectively corresponding to aggregated member ports of a physical switch by using an aggregation algorithm according to the uplink packet. The controller generates a first flow table entry and sends the first flow table entry to the SDN switch, wherein the first flow table entry is to instruct the SDN switch to forward a received uplink packet to the physical switch through the outgoing interface.

    摘要翻译: 虚拟交换机系统的控制器从托管在服务器上的VM(虚拟机)接收由托管在服务器上的SDN交换机转发的上行链路分组。 控制器通过使用根据上行链路分组的聚合算法,从分别对应于物理交换机的聚合成员端口的SDN交换机上的至少两个上行链路接口确定出局接口。 所述控制器生成第一流表条目,并将所述第一流表条目发送到所述SDN交换机,其中所述第一流表条目是指示所述SDN交换机通过所述输出接口将接收到的上行链路分组转发到所述物理交换机。

    MESSAGE FORWARDING IN A VIRTUAL LOCAL AREA NETWORK
    7.
    发明申请
    MESSAGE FORWARDING IN A VIRTUAL LOCAL AREA NETWORK 审中-公开
    虚拟本地区网络中的消息转发

    公开(公告)号:US20160191462A1

    公开(公告)日:2016-06-30

    申请号:US15018992

    申请日:2016-02-09

    发明人: Yi WANG Wei WANG Zhen MA

    IPC分类号: H04L29/12 H04L12/931

    摘要: In an example, a method for message forwarding in a network includes a first network device learning Media Access Control (MAC) address information received from a second network device. The MAC address information includes a Virtual Local Area Network (VLAN) identifier (ID), an aggregated MAC address, and an aggregated MAC address mask. The first network device receives a message addressed to the VLAN ID and a destination MAC address, and forwards the message to the second network device according to the MAC address information.

    摘要翻译: 在一个示例中,用于网络中的消息转发的方法包括从第二网络设备接收的学习媒体访问控制(MAC)地址信息的第一网络设备。 MAC地址信息包括虚拟局域网(VLAN)标识符(ID),聚合MAC地址和聚合MAC地址掩码。 第一网络设备接收寻址到VLAN ID的消息和目的MAC地址,并根据MAC地址信息将消息转发给第二网络设备。

    ADJUSTING VIRTUAL MACHINE RESOURCES
    8.
    发明申请
    ADJUSTING VIRTUAL MACHINE RESOURCES 审中-公开
    调整虚拟机资源

    公开(公告)号:US20160164828A1

    公开(公告)日:2016-06-09

    申请号:US14899792

    申请日:2014-08-22

    发明人: Songer SUN

    IPC分类号: H04L29/12 G06F9/455

    摘要: In an example of the present disclosure, a method for adjusting virtual machine resources is provided. A VIP for a virtual service is distributed, and a scheduling policy and virtual machines (VM) for the VIP may be configured. The VIP and the VMs corresponding to the VIP are configured on an underlying physical device. When status information of the VIP is received, a new VM may be added into the VMs corresponding to the VIP in response to the determination that the VIP is overloaded based on the status information of the VIP. The scheduling policy of the VIP may be used to distribute bearer services to the VMs corresponding to the VIP.

    摘要翻译: 在本公开的示例中,提供了一种用于调整虚拟机资源的方法。 分发虚拟服务的VIP,并且可以配置VIP的调度策略和虚拟机(VM)。 与VIP相对应的VIP和VM在底层物理设备上配置。 当接收到VIP的状态信息时,可以基于VIP的状态信息来响应于VIP被超载的确定,将新的VM添加到与VIP对应的VM中。 VIP的调度策略可以用于向与VIP相对应的虚拟机分配承载业务。

    Switching to a backup traffic path by a label switching router in a multi-protocol label switching network
    10.
    发明授权
    Switching to a backup traffic path by a label switching router in a multi-protocol label switching network 有权
    通过多协议标签交换网络中的标签交换路由器切换到备份流量路径

    公开(公告)号:US09350650B2

    公开(公告)日:2016-05-24

    申请号:US13979439

    申请日:2012-03-14

    申请人: Jinrong Ye

    发明人: Jinrong Ye

    摘要: A label switching router (LSR) and a method of switching data traffic to a predefined backup traffic path by the LSR in an MPLS (multi-protocol label switching) network. The LSR, upon detection of failure of a protected path during an LDP session, maintains an LDP session and forwards data traffic via the backup traffic path according to a forwarding table. The forwarding table contains logical output interface information including an outgoing label, a logical output interface, and the next hop of the predefined backup path.

    摘要翻译: 标签交换路由器(LSR)以及MPLS(多协议标签交换)网络中的LSR将数据流量切换到预定义备份流量路径的方法。 LSR在LDP会话期间检测到受保护路径发生故障后,会根据转发表通过备份业务路径维护LDP会话并转发数据流量。 转发表包含逻辑输出接口信息,包括出站标签,逻辑输出接口和预定义备份路径的下一跳。