APPLYING NETWORK POLICIES ON A PER-USER BASIS

    公开(公告)号:US20220182826A1

    公开(公告)日:2022-06-09

    申请号:US17112264

    申请日:2020-12-04

    摘要: In one example, an Access Point (AP) configures a first mapping of a first cellular network connection to a first local access network group, and further configures a second mapping of a second cellular network connection to a second local access network group. The AP determines whether a user device is authorized to use the first cellular network connection or the second cellular network connection. If the user device is authorized to use the first cellular network connection, the AP associates, for the user device, a first user device identifier with the first local access network group. If the user device is authorized to use the second cellular network connection, the AP associates, for the user device, a second user device identifier with the second local access network group.

    Large Scale Residential Cloud Based Application Centric Infrastructures
    3.
    发明申请
    Large Scale Residential Cloud Based Application Centric Infrastructures 有权
    大规模住宅云应用中心基础设施

    公开(公告)号:US20160352632A1

    公开(公告)日:2016-12-01

    申请号:US14726875

    申请日:2015-06-01

    摘要: A first customer edge network device receives an encapsulated packet that includes inner headers comprising source address information for a first service running on a first computing apparatus in a first home cloud and destination address information for a second service running on a second computing apparatus in a second home cloud. The customer edge network device inserts a predetermined portion of bits of a virtual domain identifier of the encapsulated packet into a label to form a virtual domain label for label-based routing. The virtual domain label is appended to the encapsulated packet. The encapsulated packet is sent to a first provider edge network device of a provider network. The first provider edge network device appends an virtual private network label to the encapsulated packet, and sends the encapsulated packet to a provider network device for label-based routing in the provider network.

    摘要翻译: 第一客户边缘网络设备接收包含内部报头的封装分组,所述内部报头包括在第一家庭云中的第一计算设备上运行的第一服务的源地址信息和在第二家庭云中的第二计算设备上运行的第二服务的目的地地址信息 家庭云。 客户边缘网络设备将封装分组的虚拟域标识符的预定部分位置插入到标签中以形成用于基于标签的路由的虚拟域标签。 虚拟域标签附加到封装的数据包。 封装的分组被发送到提供商网络的第一提供商边缘网络设备。 第一个提供商边缘网络设备向封装的分组附加虚拟专用网络标签,并将封装的分组发送到提供商网络设备,以在提供商网络中进行基于标签的路由。

    OPTIMIZED CONTENT ROUTING DISTRIBUTION USING PROXIMITY BASED ON PREDICTIVE CLIENT FLOW TRAJECTORIES
    4.
    发明申请
    OPTIMIZED CONTENT ROUTING DISTRIBUTION USING PROXIMITY BASED ON PREDICTIVE CLIENT FLOW TRAJECTORIES 有权
    基于预测客户端流量的优化内容路由分配

    公开(公告)号:US20150146722A1

    公开(公告)日:2015-05-28

    申请号:US14087061

    申请日:2013-11-22

    IPC分类号: H04L12/747

    摘要: System, method, and computer program product to perform an operation, the operation comprising capturing, at one or more peering routers, parameters for a plurality of data packets sent by a client device and specifying a destination network address, identifying which peering router captured the parameters for each of the plurality of data packets, determining, based on the identified peering routers, a first peering router nearest to the client, relative to the other peering routers, identifying a first content cache, of a plurality of content caches in a content distribution network, nearest to the first peering router, and fulfilling a content request from the client device using content stored on the first content cache.

    摘要翻译: 用于执行操作的系统,方法和计算机程序产品,所述操作包括在一个或多个对等路由器处捕获由客户端设备发送的多个数据分组的参数并指定目的地网络地址,识别哪个对等路由器捕获 对于所述多个数据分组中的每一个的参数,基于所识别的对等路由器,相对于其他对等路由器最近的第一对等路由器识别内容中的多个内容高速缓存的第一内容高速缓存 分发网络,最接近第一对等路由器,以及使用存储在第一内容高速缓存上的内容从客户端设备完成内容请求。

    Group member recovery techniques
    6.
    发明授权

    公开(公告)号:US09832175B2

    公开(公告)日:2017-11-28

    申请号:US15230924

    申请日:2016-08-08

    IPC分类号: H04L29/06

    摘要: Techniques are presented for optimizing secure communications in a network. As disclosed herein, a key server is configured to provision a plurality of routers that are part of a virtual private network. The key server selects a counter value that is part of a security association and calculates a key value. The key server sends the key value, together with the security association, to the plurality of routers that are part of the virtual private network to enable them to exchange encrypted packets with each other in the virtual private network using the key value and the security association. The key server then increments the counter value to a value within a range of counter values capable of being predicted by the plurality of routers that received the key value.

    Detection of Stale Encryption Policy By Group Members
    8.
    发明申请
    Detection of Stale Encryption Policy By Group Members 审中-公开
    按组成员检测陈旧的加密策略

    公开(公告)号:US20160164848A1

    公开(公告)日:2016-06-09

    申请号:US15010679

    申请日:2016-01-29

    IPC分类号: H04L29/06 H04L12/18

    摘要: Various techniques that allow group members to detect the use of stale encryption policy by other group members are disclosed. One method involves receiving a message from a first group member via a network. The message is received by a second group member. The method then detects that the first group member is not using a most recent policy update supplied by a key server, in response to information in the message. In response, a notification message can be sent from the second group member. The notification message indicates that at least one group member is not using the most recently policy update. The notification message can be sent to the key server or towards the first group member.

    摘要翻译: 公开了允许组成员检测到其他组成员使用过时加密策略的各种技术。 一种方法涉及经由网络从第一组成员接收消息。 该消息由第二组成员接收。 然后该方法检测到第一组成员不响应于消息中的信息使用由密钥服务器提供的最新策略更新。 作为响应,可以从第二组成员发送通知消息。 通知消息表示至少有一个组成员没有使用最近的策略更新。 通知消息可以发送到密钥服务器或朝向第一个组成员。

    DYNAMIC CONTENT DISTRIBUTION NETWORK SELECTION BASED ON CONTEXT FROM TRANSIENT CRITERIA
    9.
    发明申请
    DYNAMIC CONTENT DISTRIBUTION NETWORK SELECTION BASED ON CONTEXT FROM TRANSIENT CRITERIA 有权
    基于瞬态标准的动态动态内容分配网络选择

    公开(公告)号:US20150006615A1

    公开(公告)日:2015-01-01

    申请号:US13929369

    申请日:2013-06-27

    IPC分类号: H04L29/06

    摘要: In one embodiment, a client device queries a location server using a client-selected interface for content retrieval from a content distribution network (CDN), and receives a location attribute from the location server based on a location of the client device. The client device then presents the location attribute to a CDN selector within a first content retrieval request, and may receive a redirection from the CDN selector to a selected content source based on the location attribute. As such, the client device may then initiate a second content retrieval request to the selected content source. In another embodiment, a CDN selector receives a content retrieval request from a client device, and determines that the content retrieval request contains a location attribute indicating a location of the client device. Based on the location attribute, the CDN selector selects a content source, and redirects the client device to the selected content source.

    摘要翻译: 在一个实施例中,客户端设备使用客户端选择的接口从内容分发网络(CDN)查询内容检索的位置服务器,并且基于客户端设备的位置从位置服务器接收位置属性。 然后,客户端设备将位置属性呈现给第一内容检索请求内的CDN选择器,并且可以基于位置属性从CDN选择器接收到所选内容源的重定向。 这样,客户端设备然后可以向所选择的内容源发起第二内容检索请求。 在另一个实施例中,CDN选择器从客户端设备接收内容检索请求,并确定内容检索请求包含指示客户端设备的位置的位置属性。 基于location属性,CDN选择器选择内容源,并将客户端设备重定向到所选择的内容源。

    Encryption for gateway tunnel-based VPNs independent of wan transport addresses

    公开(公告)号:US10904217B2

    公开(公告)日:2021-01-26

    申请号:US15994590

    申请日:2018-05-31

    IPC分类号: H04L29/00 H04L29/06 H04L9/08

    摘要: A source virtual private network (VPN) gateway supports a local source subnet and communicates over a wide area network (WAN) with a destination VPN gateway that supports a local destination subnet. The source VPN gateway receives from the local source subnet an Internet Protocol (IP) packet destined for the local destination subnet, determines a security association (SA) based on a source IP address and a destination IP address of the IP packet, and encapsulates the IP packet with tunnel encapsulation including a tunnel protocol header and a tunnel outer IP header, to produce a clear-text tunnel packet. The source VPN gateway encrypts the IP packet and the tunnel protocol header but not the tunnel outer IP header using an encryption key and a security parameter index for the SA, to produce an encrypted tunnel packet, and tunnels it to the destination VPN gateway over the WAN.