Device information method and apparatus for directing link-layer communication

    公开(公告)号:US11595305B2

    公开(公告)日:2023-02-28

    申请号:US17652129

    申请日:2022-02-23

    摘要: A network device has an input configured to receive a message relating to a given device attempting to forward one or more packets across a computer network. The message has given device information relating to the given device. In addition, the routing device also has a selector, operatively coupled with the input, configured to select (after receiving the given data) a given group routing policy from a plurality of group routing policies. Preferably, the selector is configured to select the given group routing policy as a function of the given device information. The routing device also has an output operatively coupled with the selector. The output is configured to cause routing of device communication across the network using link-layer routes specified by the given group routing policy.

    Service Related Routing Method and Apparatus

    公开(公告)号:US20190253341A1

    公开(公告)日:2019-08-15

    申请号:US15897728

    申请日:2018-02-15

    摘要: A method routes packets from a source to a destination across an IP network having a plurality of nodes (including the source and destination), and a plurality of network segments interconnecting the plurality of nodes. The source and destination are configured to use a given service. To those ends, the method receives information relating to the given service, and forms a path between the source and the destination. The path includes a) at least one intermediate node between the source and the destination and b) a plurality of specific network segments extending from the source to the destination. The plurality of specific network segments are a sub-set of the plurality of network segments. To form the path, the method assigns the plurality of specific network segments to the network path between the source and the destination as a function of the information relating to the given service.

    Router Device Using Flow Duplication
    5.
    发明申请

    公开(公告)号:US20180262420A1

    公开(公告)日:2018-09-13

    申请号:US15913656

    申请日:2018-03-06

    IPC分类号: H04L12/707 H04L12/801

    摘要: A method and apparatus for routing a plurality of session packets across a network toward a destination modifies each packet to include a sequence number that is different from the sequence number of other packets in the plurality of packets. Accordingly, at this point, each of the plurality of packets is transformed into a corresponding plurality of processed packets. The method also duplicates the plurality of processed packets to produce a corresponding plurality of duplicated packets. Next, the method forwards the plurality of processed packets toward the destination using a first stateful path through the network, and correspondingly forwards the plurality of duplicated packets toward the destination using a second stateful path through the network. In preferred embodiments, the first stateful path is different from the second stateful path. For example, the two paths may be entirely distinct in that they share no common intermediary elements.

    Method and Apparatus for Configuring an Administrative Domain

    公开(公告)号:US20180254947A1

    公开(公告)日:2018-09-06

    申请号:US15450680

    申请日:2017-03-06

    IPC分类号: H04L12/24 H04L29/08

    摘要: A router is configured to be part of an administrative domain having two or more networks that each have at least one router. The router has a configuration interface permitting programming of a given configuration parameter to a local configuration setting, and an input configured to receive, from a configuration manager remote from the router, global configuration settings for a plurality of configuration parameters. For the given configuration parameter, the plurality of global configuration settings includes a different setting that is different from the local configuration setting. The configuration interface has a local configuration mode that disregards received global configuration setting changes to the given configuration parameter after programming the given configuration parameter to the local configuration setting. Also when in the local configuration mode, the configuration interface overwrites the given configuration parameter with the local configuration setting when previously programmed to the different setting.

    Network device and method for processing a session using a packet signature

    公开(公告)号:US10033843B2

    公开(公告)日:2018-07-24

    申请号:US15670270

    申请日:2017-08-07

    IPC分类号: H04L9/00 H04L29/08 H04L29/06

    摘要: A method processes a session having a first session packet received by a current node in an IP network having a plurality of nodes. The plurality of nodes includes a next node, and the current node that communicates with the next node using a Layer 3 protocol. The method receives the first session packet, which has a digital signature, payload data, and meta-data, at the current node. The method uses the payload data and meta-data to produce validation information, and uses the digital signature to produce a comparator digital signature. Next, the method compares the validation information with the comparator digital signature. If the validation information does not match the comparator digital signature, then the method discards the first session packet. If there is a match, then the method digitally signs the first session packet, and routes the first session packet to the next node via the IP network.

    Apparatus and Method of Securing Network Communications

    公开(公告)号:US20170346854A1

    公开(公告)日:2017-11-30

    申请号:US15165211

    申请日:2016-05-26

    IPC分类号: H04L29/06 H04W12/02

    摘要: An apparatus and/or method secures session communications between a first network (having a first encryption device configured to encrypt at least some session communications from the first network to the second network) and a second network. The apparatus and/or method receive, at the first network, given session packets of a given session between the first and second networks, and determine that at least one of the received given session packets is encrypted (“encrypted given session packet”). The given session involves a Layer 7 application that encrypted the at least one encrypted given session packet. Next, the apparatus and/or method controls, in response to determining that the given session packet is encrypted, the first encryption device to permit communication of the given session with the second network without further encrypting a plurality of the encrypted given session packets. Preferably, the first encryption device encrypts none of the given session packets.

    Network Packet Flow Controller with Extended Session Management
    9.
    发明申请
    Network Packet Flow Controller with Extended Session Management 有权
    具有扩展会话管理的网络分组流控制器

    公开(公告)号:US20170063681A1

    公开(公告)日:2017-03-02

    申请号:US14833571

    申请日:2015-08-24

    摘要: An intermediate node obtains a lead packet of a plurality of packets in a session having a unique session identifier, modifies the lead packet to identify at least the intermediate node and also to identify source and destination port numbers assigned by the intermediate node for a possible forward association, and then forwards the lead packet toward the destination node though an intermediate node electronic output interface to the IP network. The intermediate node also may receive, through an intermediate node electronic input interface in communication with the IP network, a backward message from a next node having a next node identifier. Both the intermediate node and the next node form an association between the intermediate node identifier, the next node identifier, and the source and destination port numbers assigned by the intermediate node. This association is part of a forward association for the intermediate node and is part of a return associate for the next node.

    摘要翻译: 中间节点在具有唯一会话标识符的会话中获取多个分组的引导分组,修改引导分组以至少识别中间节点,并且还识别由中间节点为可能的前向分配的源和目的地端口号 关联,然后通过到IP网络的中间节点电子输出接口将引导分组转发到目的地节点。 中间节点还可以通过与IP网络通信的中间节点电子输入接口从具有下一个节点标识符的下一个节点接收反向消息。 中间节点和下一个节点都形成中间节点标识符,下一个节点标识符以及由中间节点分配的源和目的端口号之间的关联。 该关联是中间节点的前向关联的一部分,并且是下一个节点的返回关联的一部分。

    ROUTING USING SEGMENT-BASED METRICS
    10.
    发明公开

    公开(公告)号:US20240039827A1

    公开(公告)日:2024-02-01

    申请号:US18475790

    申请日:2023-09-27

    IPC分类号: H04L45/02

    CPC分类号: H04L45/02 H04L45/04

    摘要: A router advertises an aggregated service or route that can be evaluated by other routers as a unitary segment rather than as a group of individual links/paths associated with the aggregated service or route. The aggregated service or route can be based on service and topology state information received from one or more other routers and can be advertised with the router as the nexthop for the aggregated service or route. The router can advertise an aggregated metric for the aggregated service or route for use in such evaluation. An aggregated route can be associated with different aggregated metrics for different services.