METHODS AND SYSTEM FOR SECURING A SDN CONTROLLER FROM DENIAL OF SERVICE ATTACK

    公开(公告)号:US20220141118A1

    公开(公告)日:2022-05-05

    申请号:US17513123

    申请日:2021-10-28

    Abstract: A Method and a system for securing a SDN controller from denial of service attack are provided. A SDN controller receives, from a networking device, data packets pertaining to a flow in Packet_IN messages, if the flow does not match flow entries in a first flow table of the networking device. A table miss flow entry pertaining to the flow is created in a second flow table of the networking device for sending the Packet_IN. The SDN controller installs a flood prevention flow entry in the second flow table to enable the networking device to drop subsequent data packets pertaining to the flow until the SDN controller installs, in the first flow table, a flow entry matching the flow. The flood prevention flow entry is deleted from the second flow table after the installation of the flow entry matching the flow.

    METHOD AND SYSTEM FOR FORWARDING DATA PACKETS IN A SERVICE FUNCTION PATH OF A NETWORK

    公开(公告)号:US20210392562A1

    公开(公告)日:2021-12-16

    申请号:US17283306

    申请日:2019-10-08

    Abstract: The present disclosure relates to a pre-5th-Generation (5G) or 5G communication system to be provided for supporting higher data rates Beyond 4th-Generation (4G) communication system such as Long Term Evolution (LTE). The present disclosure discloses systems and methods for forwarding data packets in a service function path of a network. The method includes receiving data packets associated with a first host device (111) and generating a modified source MAC address for the received data packets. The data packets are transmitted in the service function path (102) using the modified source MAC address. Further, the method involves forwarding the data packets received in the service function path to a second host device (113) based on the modified source MAC address. An embodiment of present disclosure eliminates need of special headers such as, SFC header and VLAN header for forwarding data packets on the SFP. Thus, reducing the packet size and ultimately traffic volume.

    METHOD FOR USER EQUIPMENT INITIATED NETWORK SLICE REGISTRATION AND TRAFFIC FORWARDING IN TELECOMMUNICATION NETWORKS

    公开(公告)号:US20210120484A1

    公开(公告)日:2021-04-22

    申请号:US17073131

    申请日:2020-10-16

    Abstract: The present disclosure relates to method and system for user equipment (UE)-initiated network slice registration and traffic forwarding in telecommunication networks. In an embodiment, for network slice registration, UE transmits a registration request to an AMF via a base station of telecommunication network. In response to the registration request, the AMF transmits a registration accept response comprising network slice selection assistance information (NSSAI) to the UE. For traffic forwarding, the UE transmits a PDU session establishment request comprising single NSSAI to the telecommunication network. The base station of the telecommunication network maps the single NSSAI to a Flow Label field of IPv6 header and transmits to DPAF via specific SLF of the telecommunication network. DPAF compares QoS transport characteristics of the single NSSAI with QoS transport characteristics of the NSSAI in the DPAF of the telecommunication network and transmits a PDU session establishment response to the UE based on comparison.

Patent Agency Ranking