摘要:
A distributed packet processing apparatus capable of distributing packet load across a plurality of packet processing engines is provided. The distributed packet processing apparatus includes a plurality of processing engines each configured to process allocated packets, a first tag generating unit configured to allocate an input packet to a processing engine, which has a processing engine index corresponding to a tag index for the input packet, among the plurality of processing engines, a second tag generating unit configured to calculate a tag index for an output packet, and an index conversion unit configure to convert the tag index for the output packet to one processing engine index among a plurality of processing indexes for the plurality of the processing engines and allocates the output packet to a processing engine having the one processing engine such that loads are distributed among the plurality of processing engines.
摘要:
Provided is a packet forwarding structure for supporting network based content caching of aggregate contents. The packet forwarding structure includes: a forwarding table including forwarding information on a content in order to forward a request packet from a terminal; a request list table transmitting the request packet to a destination node according to the forwarding table when the request packet arrives; a content caching information table including the forwarding table, the request list table, and position information on where a content cashed based on a content ID or a content name is stored; and a content server function block storing the cached content.
摘要:
A distributed packet processing apparatus capable of distributing packet load across a plurality of packet processing engines is provided. The distributed packet processing apparatus includes a plurality of processing engines each configured to process allocated packets, a first tag generating unit configured to allocate an input packet to a processing engine, which has a processing engine index corresponding to a tag index for the input packet, among the plurality of processing engines, a second tag generating unit configured to calculate a tag index for an output packet, and an index conversion unit configure to convert the tag index for the output packet to one processing engine index among a plurality of processing indexes for the plurality of the processing engines and allocates the output packet to a processing engine having the one processing engine index such that loads are distributed among the plurality of processing engines.
摘要:
Provided are an IP address lookup system and method for forwarding a packet over a data plane of a router. The IP address lookup system includes a forwarding table which has a three-layer table architecture so that it can search for each address group that constitutes an IP destination address of an input packet and a forwarding engine which obtains packet processing information and next hop information for the input packet by searching for the forwarding table using the IP destination address as a search key.
摘要:
A device for providing forwarding and QoS information in a flow based network environment acquires first information and second information from a flow table therein on the basis of status information of a predetermined flow in order to provide dynamically updated information in a flow based network environment. When it is determined that first information and second information acquired based on a route ID of a series of information are updated, the flow table is updated and the updated information is provided.
摘要:
A high-speed content inspection apparatus for minimizing system overhead is provided. The high-speed content inspection apparatus extracts content in unit of sub-pattern by inspecting a payload of a packet in units of sub-pattern, and extract target content by inspecting a correlation between the extracted sub-patterns. If a sub-pattern present at the end of a payload is smaller than a predetermined unit of a sub-pattern, position information of the sub-pattern at the end of the payload is rolled back and the correlation is inspected. Accordingly, without having to add another hardware or high-performance hardware, target content can be efficiently detected in real time.
摘要:
A packet scheduling apparatus and method to fairly share network bandwidth between multiple subscribers and to fairly share the bandwidth allocated to each subscriber between multiple flows are provided. The packet scheduling method includes calculating first bandwidth for each subscriber to fairly share total bandwidth set for the transmission of packets between multiple subscribers; calculating second bandwidth for each flow to fairly share the first bandwidth between one or more flows that belong to each of the multiple subscribers; and scheduling a packet of each of the one or more flows based on the second bandwidth.
摘要:
There are provided a quality of service (QoS)-providing system and a method for providing quality of service for mobile nodes in the QoS-providing system. Under a network environment running a host-based network layer mobility protocol based on tunneling mechanism, the QoS-providing system may be useful to allow effective mobility supports by distributing binding information to the distributed nodes, in order to provide session-based quality of service for tunneled packets between the mobile nodes on the access nodes and distribute traffic load concentrated on the central mobility control platform as well. Also, the QoS-providing system according to one exemplary embodiment of the present invention may be useful to provide the function of hiding locations of mobile nodes since a care-of address of the mobile node is not transferred to a correspondent node and to automatically perform a route optimization procedure even when the mobile node does not directly perform a route optimization procedure.
摘要:
A traffic analysis and flow-based dynamic access control system and method. The flow-based dynamic access control system for controlling a user's access to an internal communication network through an external communication network includes an access control unit operating in an access control mode in which traffic received from a user is basically blocked, generating state management information of a flow, which is received from the user, based on a specified packet of the flow, and verifying whether access of the flow to the internal communication network is a normal access. As a proactive defense concept of allowing only normal users to access an internal network, a method of blocking attacks from a system contaminated by a worm virus, detecting a cyber attack on a certain system in advance and automatically avoiding the cyber attack, and guaranteeing the quality of normal traffic even under cyber attacks without performance degradation of the internal network is provided.
摘要:
A method and system for supporting Internet protocol (IP) mobility independently of the IP version of a transport network are provided. The method includes providing a mobility control apparatus, which maps the home addresses of a plurality of mobile terminals, including first and second mobile terminals, and the Care-of-Addresses (CoAs) of the mobile terminals, and setting a first control tunnel between the mobility control apparatus and the first mobile terminal, the care-of-addresses varying from one transport network to another transport network; setting a second control tunnel between the mobility control apparatus and the second mobile terminal; and enabling the first and second mobile terminals to exchange a data packet with each other through the first and second control tunnels.