Preserving security association in MACsec protected network through VLAN mapping
    1.
    发明授权
    Preserving security association in MACsec protected network through VLAN mapping 有权
    通过VLAN映射保护MACsec保护网络中的安全关联

    公开(公告)号:US08700891B2

    公开(公告)日:2014-04-15

    申请号:US12463204

    申请日:2009-05-08

    CPC分类号: H04L63/101 H04L63/162

    摘要: According to one general aspect, a method of using a network device may include receiving, via an ingress port, a data packet that includes a payload portion, a source network address and a destination network address. In various embodiments, the method may also include determining if the data packet includes a security tag that includes a role based authentication tag. In some embodiments, the method may include, if the data packet includes a security tag that includes a role based authentication tag, transmitting, via an egress port, at least the payload portion and the role based authentication tag towards, in a topological sense, the destination network address.

    摘要翻译: 根据一个一般方面,使用网络设备的方法可以包括经由入口端口接收包括有效载荷部分,源网络地址和目的地网络地址的数据分组。 在各种实施例中,该方法还可以包括确定数据分组是否包括包括基于角色的认证标签的安全标签。 在一些实施例中,如果数据分组包括包括基于角色的认证标签的安全标签,那么该方法可以包括,至少在有效载荷部分和基于角色的认证标签上, 目的网络地址。

    Method and system for implementing energy efficient ethernet techniques in a MACSec enabled PHY
    4.
    发明授权
    Method and system for implementing energy efficient ethernet techniques in a MACSec enabled PHY 有权
    在启用MACSec的PHY中实现节能以太网技术的方法和系统

    公开(公告)号:US08995289B2

    公开(公告)日:2015-03-31

    申请号:US12482194

    申请日:2009-06-10

    CPC分类号: H04L63/16 H04L12/10

    摘要: Aspects of a method and system for implementing energy efficient Ethernet techniques in a MACSec enabled PHY are provided. In this regard, an Ethernet PHY comprising memory may be operable to perform packet processing functions comprising MACSec protocol processing and energy efficient Ethernet (EEE) processing. In this regard, the memory may be utilized for implementing the MACSec protocol processing and energy efficient Ethernet (EEE) processing. The Ethernet packet processing functions may comprise packet inspection, packet generation, and packet modification. The energy efficient Ethernet (EEE) processing may comprise generating and/or inspecting messages for controlling when to transition into and out-of an energy-saving mode. The Ethernet PHY may be operable to monitor signals and/or conditions within the Ethernet PHY and control transitions into and out-of an energy-saving mode based on the monitored signals and/or conditions. The energy saving mode may comprise a low power idle mode and/or a subset PHY mode.

    摘要翻译: 提供了一种用于在启用MACSec的PHY中实现高能效以太网技术的方法和系统的方面。 在这方面,包括存储器的以太网PHY可以用于执行包括MACSec协议处理和能效以太网(EEE)处理的分组处理功能。 在这方面,存储器可以用于实现MACSec协议处理和能效以太网(EEE)处理。 以太网分组处理功能可以包括分组检查,分组生成和分组修改。 能效以太网(EEE)处理可以包括生成和/或检查用于控制何时转换到节能模式和从节能模式转移的消息。 以太网PHY可以用于监视以太网PHY中的信号和/或条件,并且基于所监视的信号和/或条件来控制转换到和超出节能模式。 节能模式可以包括低功率空闲模式和/或子集PHY模式。

    Dataset Processing Using Network Performance Information
    5.
    发明申请
    Dataset Processing Using Network Performance Information 审中-公开
    使用网络性能信息的数据集处理

    公开(公告)号:US20130262679A1

    公开(公告)日:2013-10-03

    申请号:US13432643

    申请日:2012-03-28

    IPC分类号: G06F15/173

    摘要: Dataset processing based on network performance information. Processing of large datasets can be based on particular network computing resources that are selected based on network performance information (e.g., link speed, latency, energy efficiency, etc.) associated with the network computing resources. With the network performance information, a network topology of the computing resources can be created that considers not only the processing capabilities of the network computing resources but also the performance of the network that interconnects the computing devices.

    摘要翻译: 基于网络性能信息的数据集处理。 大数据集的处理可以基于基于与网络计算资源相关联的网络性能信息(例如,链路速度,等待时间,能量效率等)来选择的特定网络计算资源。 利用网络性能信息,可以创建计算资源的网络拓扑,其不仅考虑网络计算资源的处理能力,而且考虑与计算设备互连的网络的性能。

    Distributed Switch Domain of Heterogeneous Components
    8.
    发明申请
    Distributed Switch Domain of Heterogeneous Components 有权
    分布式交换机域的异构组件

    公开(公告)号:US20120027018A1

    公开(公告)日:2012-02-02

    申请号:US12872738

    申请日:2010-08-31

    申请人: Nicholas Ilyadis

    发明人: Nicholas Ilyadis

    IPC分类号: H04L12/56

    摘要: A method of integrating virtual and physical network switching components into a heterogeneous switching domain is provided. Such method including, attaching, by a switching device, a header to a packet received from a virtual machine, the header including domain information, and processing the packet by the switching device, the processing being controlled by the header. Finally, the packet is forwarded, the forwarding being controlled by the header.

    摘要翻译: 提供了一种将虚拟和物理网络交换组件集成到异构交换域中的方法。 这种方法包括:通过交换设备将报头附加到从虚拟机接收的分组,所述报头包括域信息,以及由所述交换设备处理所述分组,所述处理由所述报头控制。 最后,数据包被转发,转发由报头控制。

    System, device, and method for address management in a distributed communication environment

    公开(公告)号:US20050190754A1

    公开(公告)日:2005-09-01

    申请号:US10606847

    申请日:2003-06-26

    IPC分类号: H04L12/56 H04L29/12 H04Q11/00

    摘要: A distributed address database management technique involves maintaining an address database by each of a number of interconnected modules. Each module maintains a number of locally owned address entries and a number of remotely owned address entries in the address database. Each module monitors the status of its locally owned address entries, maintains the locally owned address entries based upon the status, and provides the status to the other interconnected modules. Each module maintains the remotely owned address entries based upon the status received from the other interconnected modules. When a module adds a locally owned address entry to its address database, the module notifies the other interconnected modules, which in turn add a corresponding remotely owned address entry to their respective address databases. When a module purges a locally owned address entry from its address database, the module notifies the other interconnected modules, which in turn purge the corresponding remotely owned address entries from their respective address databases. Each module may periodically send a keep-alive message including a list of active addresses to the other interconnected modules, which maintain a persistence timer for each of the remotely owned address entries and purge a particular remotely owned address entry if the corresponding persistence timer expires before receiving a keep-alive message identifying the remotely owned address entry as an active remotely owned address entry. Upon receiving a keep-alive message, a module adds a remotely owned address entry for a particular address to its address database if such a remotely owned address entry is not already maintained in the address database. A module purges all remotely owned address entries from its address database if the module is reconfigured to operate in a stand-alone mode. A module purges all remotely owned address entries associated with a particular interconnected module if that particular interconnected module is removed.

    Method of round robin bus arbitration
    10.
    发明授权
    Method of round robin bus arbitration 失效
    轮询总线仲裁方法

    公开(公告)号:US5898694A

    公开(公告)日:1999-04-27

    申请号:US774775

    申请日:1996-12-30

    IPC分类号: G06F13/374 H04J3/14

    CPC分类号: G06F13/374

    摘要: An arbitration unit contains a method of arbitration which includes distributed arbitration, a priority mechanism to support different classes of traffic, a unique arbitration ID bits for each module, a round robin arbitration within a given priority level to produce fair access to a bus 36, an arbitration timeout, and a bandwidth allocation between priority levels. The method of round robin bus arbitration includes the steps of providing a plurality of modules, providing a bus having a plurality of data lines, the bus connecting the plurality of modules, the bus having an arbitration unit, setting the bus to a wait state, signaling a first bus request to the bus by a first module needing to transmit a first plurality of data packets on to the bus, the first module having a first module priority level and a first unique arbitration number, signaling a second bus request to the bus by a second module needing to transmit a second plurality of data packets on to the bus, the second module having a second module priority level and a second unique arbitration number, establishing a bus priority according to a comparison of the first module priority level and the second module priority level, asserting the first unique arbitration number on the bus by the first module, asserting the second unique arbitration number on the bus by the second module, determining whether the first module and the second module have been waiting for the bus, comparing the first unique arbitration number and the second unique arbitration number, scheduling transmission of data packets in response to the steps of determining and comparing, and repeating the steps of setting, signaling, establishing, asserting, determining, comparing, and scheduling.

    摘要翻译: 仲裁单元包含一种仲裁方法,其包括分布式仲裁,支持不同类别的业务的优先级机制,每个模块的唯一仲裁ID比特,给定优先级别内的循环仲裁以产生对总线36的公平访问, 仲裁超时,以及优先级之间的带宽分配。 循环总线仲裁的方法包括提供多个模块的步骤,提供具有多个数据线的总线,连接多个模块的总线,总线具有仲裁单元,将总线设置为等待状态, 通过需要将第一多个数据分组发送到总线的第一模块向总线发出第一总线请求,第一模块具有第一模块优先级和第一唯一仲裁号,向总线发信号通知第二总线请求 通过需要将第二多个数据分组发送到总线的第二模块,第二模块具有第二模块优先级和第二唯一仲裁号,根据第一模块优先级和第二模块优先级的比较来建立总线优先级 第二模块优先级,由第一模块在总线上声明第一唯一仲裁号,由第二模块在总线上断言第二唯一仲裁号,阻止 挖掘第一模块和第二模块是否等待总线,比较第一唯一仲裁号和第二唯一仲裁号,响应于确定和比较的步骤调度数据包的传输,并重复设置步骤 ,信号,建立,断言,确定,比较和调度。