摘要:
Method and apparatus for controlling transmission of data packets in a packet-switched network. When a first end-host (A) sends an address query to a DNS system (300) for a second end-host, the DNS system responds by providing a sender key created from a destination key registered for the second end-host, if the first end-host is authorized to send packets to the second end-host. Thereby, the first end-host, if authorized, is able to get across data packets to the second end-host by attaching a sender tag (TAG) generated from the sender key, as ingress tag to each transmitted data packet. A router (302) in the network matches an ingress tag in a received packet with entries in a forwarding table and sends out the packet on an output port (X) according to a matching entry. Otherwise, the router discards the packet if no matching entry is found in the table.
摘要:
A method of allowing a nomadic terminal to access a home network on the Layer 2 level. The method comprises connecting said terminal to a remote access network via an access point, the remote access network being connected to an operator's backbone network via a remote access router. Signalling is exchanged between the access point and an authentication server within the backbone network in order to authenticate the terminal to the authentication server and, following successful authentication, a Layer 2 tunnel extending across the backbone network is established for the purpose of connecting said nomadic terminal to the home network.
摘要:
A method for setting up a VPN is described. The VPN is set up in a backbone network having a plurality of PE routers for controlling the transfer of IP traffic to and from CE routers in satellite networks. In a PE router, a VRF is configured for the VPN and populated with local routes for the VPN. A VLAN identifier is assigned for the VPN, and advertised to other PE routers in the backbone network. Alternatively, the VLAN identifier may be determined by a predetermined mapping algorithm so it will be unique to the VPN in all PE routers, in which case the advertisement to other PE routers may contain an implicit NULL label.
摘要:
There is described a method and apparatus for sending data through one or more packet data networks. A stripped-down packet is sent from a packet sending node towards a cache node, the stripped down packet including in its payload a pointer to a payload data segment stored in a file at the cache node. When the stripped-down packet is received at the cache node, the pointer is used to identify the payload data segment from data stored at the cache node. The payload data segment is inserted into the stripped-down packet in place of the pointer so as to generate a full size packet, which is sent from the cache node towards a client.
摘要:
There is described a method and apparatus for sending data through one or more packet data networks. A stripped-down packet is sent from a packet sending node towards a cache node, the stripped down packet including in its payload a pointer to a payload data segment stored in a file at the cache node. When the stripped-down packet is received at the cache node, the pointer is used to identify the payload data segment from data stored at the cache node. The payload data segment is inserted into the stripped-down packet in place of the pointer so as to generate a full size packet, which is sent from the cache node towards a client.
摘要:
In an access network, a tunnel gateway (TGW) managed network caching architecture is proposed. The proposed TGW receives a terminal request directed to a data server for a flow of data. The terminal request is forwarded to the TGW through a tunnel from a tunnel endpoint located below the TGW. The TGW selects a network cache to handle the data traffic of the flow requested by the requesting terminal. The TGW then redirects the terminal request to the selected network cache to provide the requested service. The TGW redirects the terminal request through a tunnel whose endpoint is the selected network cache.
摘要:
A technique of processing network traffic that is sent on a tunnel between a first tunnel and a second tunnel node in a communication network is provided. A device implementation of this technique comprises an enhanced network address translation, eNAT, component (10) comprising a first obtaining unit (14) configured to obtain an uplink data packet (26) from an uplink tunnel from the first tunnel node to the second tunnel node, the uplink data packet comprising a first network address associated with the first tunnel node, a second network address associated with the second tunnel node, a first identifier associated with the uplink tunnel an internal network address, and an internal port number, a second obtaining unit (16) configured to obtain a second identifier associated with a downlink tunnel from the second tunnel node to the first tunnel node, wherein the downlink tunnel is related to the uplink tunnel, a checking unit (18) configured to check, based on the second network address and the first identifier, whether a database entry comprising the second network address and the first identifier exists in a database (12), an updating unit (20) configured to update the database (12) in case the checked database entry does not exist in the database (12), and a manipulating unit (22) configured to manipulate the uplink data packet (26).
摘要:
A technique of processing network traffic that is sent on a tunnel between a first tunnel and a second tunnel node in a communication network is provided. A device implementation of this technique comprises an enhanced network address translation, eNAT, component (10) comprising a first obtaining unit (14) configured to obtain an uplink data packet (26) from an uplink tunnel from the first tunnel node to the second tunnel node, the uplink data packet comprising a first network address associated with the first tunnel node, a second network address associated with the second tunnel node, a first identifier associated with the uplink tunnel an internal network address, and an internal port number, a second obtaining unit (16) configured to obtain a second identifier associated with a downlink tunnel from the second tunnel node to the first tunnel node, wherein the downlink tunnel is related to the uplink tunnel, a checking unit (18) configured to check, based on the second network address and the first identifier, whether a database entry comprising the second network address and the first identifier exists in a database (12), an up-dating unit (20) configured to update the database (12) in case the checked database entry does not exist in the database (12), and a manipulating unit (22) configured to manipulate the uplink data packet (26).
摘要:
A technique for address resolution in data transmission networks, for example ARP-based address resolution in IPv4 networks. An embodiment of the technique comprises the following steps performed in a host of the data transmission network: Maintaining an association of at least one physical address with at least one network address range comprising multiple network addresses; obtaining a target network address; comparing the target network address with the network address range to determine an associated target physical address; and providing the determined target physical address, e.g. for initiating a data transmission.
摘要:
Method and apparatus for supporting the forwarding of received data packets in a router (402,702) of a packet-switched network. A forwarding table (706a) is configured in the router based on aggregating router keys and associated aggregation related instructions received from a key manager (400,700). Each aggregating router key represents a set of destinations. When a data packet (P) is received comprising an ingress tag derived from a sender key or router key, the ingress tag is matched with entries in the forwarding table. An outgoing port is selected for the packet according to a found matching table entry that further comprises an associated aggregation related instruction. An egress tag is then created according to the aggregation related instruction, and the packet with the created egress tag attached is sent from the selected outgoing port to a next hop router.