Application-aware policy enforcement
    5.
    发明授权
    Application-aware policy enforcement 有权
    应用感知策略执行

    公开(公告)号:US07966645B2

    公开(公告)日:2011-06-21

    申请号:US11715187

    申请日:2007-03-06

    IPC分类号: H04L9/00

    摘要: In one embodiment, a method includes receiving a first message from a first manager. The first message includes a first element of a request for policy authorization. The request for policy authorization attempts to reserve particular network resources for a particular application context. The method includes, in response to the first message, establishing a policy rendezvous state at a policy manager for a policy decision on the request for policy authorization. The method includes receiving a second message from a second manager subsequent to the first message. The second message includes a second element of the request for policy authorization, and the second element completes the request for policy authorization. The method includes, in response to the second message, making the policy decision based on the first and second elements of the request for policy authorization. The method includes, if the policy decision grants the request for policy authorization, generating a complete policy facet and communicating the complete policy facet to the first manager or the second manager to authorize use of the particular resources for the particular application context.

    摘要翻译: 在一个实施例中,一种方法包括从第一管理器接收第一消息。 第一个消息包括策略授权请求的第一个元素。 策略授权请求尝试为特定应用程序上下文保留特定的网络资源。 该方法包括响应于第一消息,在策略管理器处建立策略集合状态以进行策略授权请求的策略决定。 该方法包括在第一消息之后从第二管理器接收第二消息。 第二个消息包括策略授权请求的第二个元素,第二个元素完成策略授权请求。 该方法包括响应于第二消息,基于策略授权请求的第一和第二要素进行策略决定。 该方法包括,如果策略决定授予策略授权请求,则生成完整的策略方面,并将完整的策略方面传递给第一管理者或第二管理器以授权对特定应用上下文使用特定资源。

    System and method for offloading data in a communication system
    9.
    发明授权
    System and method for offloading data in a communication system 有权
    用于在通信系统中卸载数据的系统和方法

    公开(公告)号:US09014158B2

    公开(公告)日:2015-04-21

    申请号:US13179541

    申请日:2011-07-10

    摘要: A method is provided in one example embodiment and includes receiving a data packet transported on a backhaul link at a first network element; de-capsulating the data packet; identifying whether the data packet is an upstream data packet; identifying whether the data packet matches an internet protocol (IP) access control list (ACL) or a tunnel endpoint identifier; and offloading the data packet from the backhaul link. In more specific embodiment, the method can include identifying that the data packet does not match the IP ACL or the tunnel endpoint identifier; and communicating the data packet to a second network element. In other examples, the method can include identifying that the data packet is a downstream data packet; identifying a service to be performed for the data packet that cannot be performed at the first network element; and communicating the data packet to a second network element.

    摘要翻译: 在一个示例性实施例中提供了一种方法,并且包括接收在第一网络元件处的回程链路上传送的数据分组; 解封装数据包; 识别数据分组是否是上行数据分组; 识别数据分组是否与互联网协议(IP)访问控制列表(ACL)或隧道端点标识符匹配; 并从回程链路卸载数据包。 在更具体的实施例中,该方法可以包括识别数据分组与IP ACL或隧道端点标识符不匹配; 以及将所述数据分组传送到第二网络单元。 在其他示例中,该方法可以包括识别数据分组是下游数据分组; 识别对于在第一网络元件不能执行的数据分组执行的服务; 以及将所述数据分组传送到第二网络单元。

    System and method for offloading data in a communication system
    10.
    发明授权
    System and method for offloading data in a communication system 有权
    用于在通信系统中卸载数据的系统和方法

    公开(公告)号:US08897183B2

    公开(公告)日:2014-11-25

    申请号:US13179542

    申请日:2011-07-10

    摘要: A method is provided in one example embodiment and includes receiving a data packet transported on a backhaul link at a first network element; identifying whether the data packet is an upstream data packet; identifying whether the data packet matches an internet protocol (IP) access control list (ACL) or a tunnel endpoint identifier; performing a network address translation on the data packet; and offloading the data packet from the backhaul link. In certain implementations, the method can include identifying that the data packet does not match the IP ACL or the tunnel endpoint identifier; and communicating the data packet to a second network element. In other instances, the method can include identifying that the data packet is a downstream data packet; and restoring a tunnel header and tunnel identification based on an IP address of the data packet.

    摘要翻译: 在一个示例性实施例中提供了一种方法,并且包括接收在第一网络元件处的回程链路上传送的数据分组; 识别数据分组是否是上行数据分组; 识别数据分组是否与互联网协议(IP)访问控制列表(ACL)或隧道端点标识符匹配; 对数据包执行网络地址转换; 并从回程链路卸载数据包。 在某些实现中,该方法可以包括识别数据分组与IP ACL或隧道端点标识符不匹配; 以及将所述数据分组传送到第二网络单元。 在其他情况下,该方法可以包括识别数据分组是下游数据分组; 并根据数据包的IP地址恢复隧道头和隧道标识。