Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

2234results about "Networks interconnection" patented technology

Metadata customization for virtual private label clouds

Novel techniques are disclosed for providing vPLC-specific metadata service including customized vPLC-specific metadata. In certain embodiments, each vPLC may generate a customized metadata using its corresponding vPLC-specific customization instructions. In some embodiments, a vPLC-specific metadata service may be performed using pre-generated customized vPLC-specific metadata, on-the-fly customized metadata, pre-generated CSP-format metadata, or combinations thereof.
Owner:ORACLE INT CORP

Connectivity for virtual private label clouds

Techniques for facilitating connectivity to vPLCs created in a CSP-provided infrastructure in a region. Within the CSP-provided infrastructure in a region, when the destination of a packet is determined to be an endpoint associated with a particular vPLC, the packet is tagged with information related to the particular vPLC. The vPLC-related information for the particular vPLC can include, for example, a vPLC identifier identifying the particular vPLC, an identifier identifying a customer associated with the endpoint, a virtual cloud network identifier identifying a virtual cloud network (VCN) belonging to the particular vPLC and where the endpoint is part of the VCN, and other vPLC-related information. The packet is then routed or communicated within the CSP-provided infrastructure in a region along with the tagged vPLC-related information. The vPLC-related information is used as part of the connectivity and for routing of packets within the CSP-provided infrastructure in a region.
Owner:ORACLE INT CORP

Configurable and dynamic service function chaining (SFC) interface mapping on a data processing unit (DPU)

Technologies for configuring multiple virtual bridges and interface mappings in a Service Function Chaining (SFC) architecture are described. A DPU can include memory to store a configuration file specifying the virtual bridges and interface mappings, and a processing device operatively coupled to the memory. The processing device, according to the configuration file, generates a first virtual bridge and a second virtual bridge. The first virtual bridge is controlled by a first network service hosted on the DPU, and the second virtual bridge is controlled by a user-defined logic. The processing device adds add one or more host interfaces to the second virtual bridge, a first service interface to the first virtual bridge to operatively couple to the first network service, and one or more virtual ports between the first virtual bridge and the second virtual bridge.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Extending switch fabric processing to network interface cards

An example system comprises a plurality of servers comprising respective network interface cards (NICs) connected by physical links in a physical topology, wherein each NIC of the plurality of NICs comprises an embedded switch and a processing unit coupled to the embedded switch; and an edge services controller configured to program the processing unit of a network interface card of the plurality of network interface cards to: receive, at a first network interface of the NIC, a data packet from a physical device; based on the data packet being received at the first network interface, modify the data packet to generate a modified data packet; and output the modified data packet to the physical device via a second network interface of the NIC.
Owner:JUNIPER NETWORKS INC

Extension of network control system into public cloud

Some embodiments provide a method for a first data compute node (DCN) operating in a public datacenter. The method receives an encryption rule from a centralized network controller. The method determines that the network encryption rule requires encryption of packets between second and third DCNs operating in the public datacenter. The method requests a first key from a secure key storage. Upon receipt of the first key, the method uses the first key and additional parameters to generate second and third keys. The method distributes the second key to the second DCN and the third key to the third DCN in the public datacenter.
Owner:VMWARE INC

Dynamic service scheduling in a smart fabric

An example system comprises a plurality of servers comprising respective network interface cards (NICs) connected by physical links in a physical topology, wherein each NIC of the plurality of NICs comprises an embedded switch and a processing unit coupled to the embedded switch; and an edge services controller configured to program the processing unit of a network interface card of the plurality of network interface cards to: receive, at a first network interface of the NIC, a data packet from a physical device; based on the data packet being received at the first network interface, modify the data packet to generate a modified data packet; and output the modified data packet to the physical device via a second network interface of the NIC.
Owner:JUNIPER NETWORKS INC

Extending customer premises networks onto a cloud provider network

Disclosed are various embodiments that extend customer premises networks onto a cloud provider network. In one embodiment, a layer-3 virtual private network is established between a tunneling agent and a virtual private network server on a cloud provider network. The tunneling agent is executed on an edge customer premises equipment (CPE) device on a customer premises network. A layer-2 virtual interface is established for an edge application on the cloud provider network using a tunnel to encapsulate layer-2 traffic between the customer premises network and the edge application over the layer-3 virtual private network.
Owner:AMAZON TECH INC

Parameter advertisement method and apparatus, device, and system

This application discloses a parameter advertisement method and apparatus. An unpacking end advertises a packing end of a feature of a data flow that needs to be packed and an identifier of a compression algorithm, so that the feature of the data flow and the identifier of the compression algorithm are automatically transferred from the unpacking end to the packing end. Therefore, the packing end can determine packing for some data flows and a to-be-used compression algorithm based on the received feature of the data flow and the received identifier of the compression algorithm, so that the packing end can pack a specified data flow by using a specified compression algorithm, and a process in which the feature of the data flow and the identifier of the compression algorithm are manually configured at the packing end is avoided. Therefore, configuration complexity at the packing end is reduced.
Owner:HUAWEI TECH CO LTD

Routing control method and apparatus, system and border gateway protocol peer

The present disclosure relates to a routing control method, a system, and a BGP Peer. The method of the present disclosure can be executed by a first BGP Peer, including: receiving information of adding a new VPN route sent from a second BGP Peer, wherein the information of adding the new VPN route comprises: the new VPN route and an identifier of a first VPN instance; determining whether a number of VPN routes corresponding to the identifier of the first VPN instance reaches or exceeds a limit value after adding the new VPN route; and sending first instruction information to the second BGP Peer to instruct the second BGP Peer, in a case that the number of VPN routes corresponding to the identifier of the first VPN instance reaches or exceeds the limit value, wherein the first BGP Peer is an iBGP Peer inside a first AS.
Owner:CHINA TELECOM CORP LTD

Multi-screen cooperative control method based on OpenHarmony distributed architecture and all-in-one machine system

The invention relates to the technical field of distributed architectures, and discloses a multi-screen cooperative control method based on an OpenHarmony distributed architecture and an all-in-one machine system.The method comprises the steps that a broadcast frame found by equipment is sent through an OpenHarmony distributed soft bus, security authentication is conducted on a plurality of display terminals responding to the broadcast frame, a virtual bus channel is established, and the virtual bus channel is sent to the display terminals; obtaining a virtual device group; creating a distributed industrial data object on the main control equipment of the virtual equipment group and synchronizing the distributed industrial data object to each slave display terminal to obtain a distributed data model; mapping the anonymous shared memory to an annular buffer area; and writing real-time data acquired by the industrial field equipment into an annular buffer area, and transmitting the real-time data to each slave display terminal of the virtual equipment group, in the method, each display terminal accesses an agent instance of an industrial data object through a distributed data management framework; and the requirements of high reliability, low delay and high consistency on multi-screen cooperative control in an industrial field are met.
Owner:HUALONG XUNDA ELECTRICAL TECHNOLOGY (SHENZHEN) CO LTD

Next gen zero trust network access (ZTNA) and virtual private network (VPN) including cloud secure access service edge (SASE)

Techniques for leveraging the MASQUE protocol to provide remote clients with full application access to private enterprise resources are described herein. One or more network nodes may be configured to execute a MASQUE proxy service to provide a remote client device with full access to an enterprise / private application resource executing on an application node and hosted in an enterprise / application network, behind the MASQUE proxy service. In some examples, the MASQUE proxy service may execute on a single proxy node hosted at an edge of a cloud network or at an edge of an enterprise network. Additionally, or alternatively, a first instance of the MASQUE proxy service may execute on a first proxy node hosted at an edge of a cloud network (e.g., an ingress proxy node) and a second instance of the MASQUE proxy service may execute on a second proxy node hosted at an edge of the enterprise network.
Owner:CISCO TECHNOLOGY INC

Agent-free honeypot mapping method and device

The invention discloses an agent-free honeypot mapping method and device, and relates to the technical field of network security. The method comprises the following steps: analyzing metadata of core switching equipment, and establishing a domain-address mapping matrix; periodically detecting an address space, constructing an IP asset dynamic portrait and generating an asset state map; deploying a cross-domain traffic forwarding protocol stack and a virtual domain identifier mapping rule; deploying a software-defined virtual switching unit and accessing the virtual honeypot probe cluster; allocating idle addresses for the probes and establishing a binding relationship; and periodically detecting and triggering a self-healing process when an address conflict occurs. The device comprises a core exchange and domain management unit, an IP asset detection unit, a network protocol configuration unit, a probe virtualization management unit, an address resource scheduling unit and a system cooperative control unit. According to the method, agency-free and automatic deployment of the honeypot is realized, and the problems that a traditional scheme depends on agency software, deployment is complex and IP conflict processing lags are solved.
Owner:NANJING JINGWEI XINAN TECH CO LTD +1

Method and equipment for realizing bare metal gateway based on OpenFlow flow table

The invention relates to the technical field of network intercommunication, and provides a method and equipment for realizing a bare metal gateway based on an OpenFlow flow table, and the method comprises the steps: enabling a bare metal server to be accessed to a VPC network, and creating and binding a network port to a specified bare metal gateway node in a specified VPC subnet through a cloud management platform; a logic flow table is generated through the OVN controller according to the network ports and the binding relation of the network ports, and the logic flow table is issued to the bare metal net nodes bound to the network ports; the bare metal net node translates the received logic flow table into an OpenFlow flow table and issues the OpenFlow flow table to a local OVS virtual switch; and the OVS virtual switch performs two-layer forwarding processing on the message transmitted between the bare metal server and the virtual machine in the VPC according to the received OpenFlow flow table. The bare metal gateway is realized in a pure software mode, the dependence on special hardware is avoided, and the cost is remarkably reduced. The efficient conversion between the VXLAN and the VLAN is realized based on the OpenFlow flow table, the flexibility, the expandability and the operation and maintenance automation degree are improved, and the high-performance two-layer intercommunication is ensured.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Wildcard based private application access

ActiveUS12470520B2Networks interconnectionSecuring communicationDomain nameFully qualified domain name
Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and / or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.
Owner:PALO ALTO NETWORKS INC

Management Method for Multi-Resource Pool Network, Cloud Management Platform, and Apparatus

A cloud management platform obtains service configuration information configured by a tenant on the cloud management platform, where the service configuration information includes one or more of the following: a network identifier, a terminal node identifier, and a terminal node type. The network identifier indicates identifiers of networks including at least two resource pools that establish a network connection, each terminal node corresponds to one resource pool, the resource pools correspond to a plurality of service providers, each resource pool includes a plurality of computing nodes, the plurality of computing nodes are used to run a business of the tenant, and the terminal node type indicates a type of a resource pool corresponding to the terminal node. The cloud management platform creates corresponding terminal nodes for the at least two resource pools based on the terminal node type.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Network configuration method, data forwarding method, device, equipment and storage medium

The embodiment of the invention discloses a network configuration method and device, a data forwarding method and device, equipment and a storage medium, and the network configuration method comprises the steps: obtaining slice configuration information between source end equipment and sink end equipment, and the slice configuration information comprises a network slice ID, bandwidth information, a segment routing traffic engineering strategy and a target service identifier; generating a routing path between the source end device and the sink end device according to the bandwidth information and the segment routing traffic engineering strategy; generating a slice configuration command according to the slice configuration information and the routing path, and issuing the slice configuration command to each device in the routing path, the slice configuration command is used for instructing each device to transmit target service data corresponding to the target service identifier according to a network slice channel corresponding to the network slice ID. According to the embodiment of the invention, the data transmission efficiency can be improved, and the waste of bandwidth resources is reduced.
Owner:CHINA TELECOM CORP LTD

Large-scale constellation network semi-physical simulation test system and method

The invention provides a large-scale constellation network semi-physical simulation test system and method, the system comprises a constellation simulator, a satellite-borne router, ground detection equipment and a protocol conversion network bridge, a Mininet simulation platform is deployed, and dynamic topology adjustment, an OSPF dynamic routing protocol and a multi-scene test function are supported; a user can observe network topology change, route updating time and key performance indexes in real time. A semi-physical simulation architecture is realized through unified IP subnet interconnection and the same routing protocol, a space-time synchronization engine ensures that virtual and real node routing tables take effect at an appointed moment, and in combination with a protocol consistency sandbox, hidden faults caused by inconsistent behaviors of hardware and software protocol stacks are solved, and the service life of the virtual and real node routing tables is prolonged. A plurality of real nodes are accessed in a large-scale network environment, and end-to-end data transmission test, security policy verification and protocol compatibility analysis are carried out; the invention provides an efficient, flexible and reliable solution for the design, verification and optimization of the satellite network, and has a wide application prospect.
Owner:BEIJING RES INST OF TELEMETRY

Methods and related devices for secure transmission of messages

ActiveCN119232523BNetworks interconnectionSecuring communicationWide areaEnd to end security
This application provides a method for secure message transmission, a method for negotiating IPsec SAs, and related apparatus, applicable to wide area networks (WANs). In scenarios spanning multiple tunnel segments, by extending BGP routing and based on VRF granularity, an IPsec SA for end-to-end security protection is negotiated between a first edge and a second edge. After the first edge securely protects VPN service messages based on the IPsec SA, it sends the messages through the overlay end-to-end tunnel between the first and second edges. The second edge processes the messages based on the IPsec SA to obtain the VPN service messages. In this application, security protection only needs to be performed once at the first edge; intermediate nodes do not require encryption / decryption processing, thus ensuring secure message transmission while improving transmission efficiency and reducing transmission latency.
Owner:HUAWEI TECH CO LTD

Method, device, equipment and medium for virtual machine to access cloud platform management network

The application discloses a method, device and equipment for a virtual machine to access a cloud platform management network and a medium, the method comprising: creating a first virtual bridge interworking with a business network on a physical node of a cloud platform; creating a virtual management network interworking with a management network on the physical node based on the first virtual bridge; connecting a virtual machine on the physical node with the virtual management network and configuring a default route when the virtual machine accesses the management network, so that the virtual machine can access the management network based on the virtual management network. The method provided by the application enables the virtual machine to access the cloud platform management network without changing the physical isolation of the cloud platform management network and the business network.
Owner:ANCHAO CLOUD SOFTWARE CO LTD

Device, apparatus, method and computer programs for a network gateway, server, server apparatus, server method, system, router, mobile device, vehicular gateway and cloud server

A device for controlling a network gateway comprises at least one network interface configured to communicate in at least one computer network. The device further comprises a processing module configured to at least partially execute at least a first software module and a second software module. The first software module is configured to provide a gateway functionality of the network gateway via the at least one network interface. A functionality of the second software module is different from the gateway functionality of the first software module. The second software module is encapsulated from the first software module.
Owner:MAXLINEAR INC

Can bus with publish-subscribe architecture

An example operation includes one or more of receiving a request from a first ECU disposed on a virtual bus, wherein the request identifies data to be obtained from a second ECU, generating a subscription between the first ECU and the second ECU for the identified data via a framework of a virtual bus, receiving a data frame which is published by the second ECU, and forwarding the data frame published by the second ECU to the first ECU on the virtual bus based on the generated subscription.
Owner:TOYOTA MOTOR NORTH AMERICA INC +1

VPN network communication method, apparatus, device and program product

The invention relates to the field of communication, in particular to a VPN network communication method and device, equipment and a program product. The method comprises the following steps: acquiring flow characteristics of tenants in a VPN network; calculating a service sensitivity type corresponding to the traffic feature through a first network model; according to the corresponding relationship between the service sensitivity type and the encryption level, determining the encryption level matched with the service sensitivity type corresponding to the flow characteristic, and encrypting the communication data according to the encryption level; and obtaining tunnel features based on the encryption level, predicting a tunnel health score corresponding to the tunnel features through a preset second network model, and adjusting the tunnel and / or the encryption level through the tunnel health score. The encryption level matched with the service sensitivity type is adopted for encryption, the data safety can be effectively improved, the tunnel and the encryption level are adjusted through the tunnel health score, the possibility of transverse penetration attack can be effectively reduced, and the system communication safety is improved.
Owner:SHENZHEN HONGDIAN TECH CORP

Message uploading method, data processing unit and computer program product

The invention relates to a message uploading method, a data processing unit and a computer program product, and the method comprises the steps: firstly caching and updating a count after receiving a queue message, determining the number n1 of descriptors needing to be read according to a descriptor index when a queue does not cache a descriptor, reading m1 descriptors (m1 is greater than or equal to n1) from a host side according to cache line alignment, writing the message into a host cache by using n1 descriptors, and updating a count and an index; if the message is processed and the descriptors are left, caching the descriptors which are not used; when the queue has cache descriptors, the cache descriptors are preferentially used for writing messages, if the cache descriptors are not completely written, the number n2 of the descriptors needing to be read is determined according to the descriptor index, m2 (m2 > = n2) descriptors are read from the host side according to cache line alignment to process remaining messages, and if the messages are completely processed and the descriptors are remaining after updating, the descriptors are not used in the same cache. According to the invention, the problem of read delay of the descriptor can be solved, and the overall message processing efficiency is improved.
Owner:BEIJING JAGUAR MICROSYSTEMS CO LTD +1

Weak network adaptive multipath transmission method and system, and storage medium

The invention relates to the technical field of network communication, and discloses a weak network adaptive multipath transmission method and system, and a storage medium. The method comprises the following steps: performing multi-path connectivity and quality detection on a target server, constructing a candidate set comprising a first path of a native UDP bearing QUIC, a second path of a TCP tunnel packaging QUIC and a third path of a TCP combined TLS, and performing initial selection of a main path according to the priority from high to low; periodically collecting and smoothly processing network quality indexes such as round-trip delay and packet loss rate during the connection duration; and when the monitoring data meets a preset degradation condition, reordering and switching the candidate paths in combination with a lag mechanism and a comprehensive quality scoring model. Through multi-dimensional perception and a dynamic strategy, the problem of QUIC failure caused by UDP blocking in a firewall interference or weak network environment is solved, the advantages of a QUIC protocol can be reserved to the greatest extent on the premise of not interrupting services, and the reliability and fluency of data transmission are remarkably improved.
Owner:189CSP

Method, apparatus and device for performing hardware acceleration on layer 2 tunneling protocol message, and storage medium

Disclosed are a method, an apparatus and a device for performing hardware acceleration on an L2TP message and a storage medium. The method includes: determining whether the current message requiring hardware acceleration is an L2TP type message according to a first matching rule, the first matching rule is a protocol stack configuration information only used to identify the header type of the current message; selecting a corresponding acceleration processing strategy according to the determination result, when the determination result is an plain message of a non-L2TP type, performing acceleration processing on the plain message according to a preset protocol stack standard, and when the determination result is an L2TP message, performing acceleration processing on the L2TP message according to a second matching rule, the second matching rule is protocol stack configuration information for matching inner layer information of the L2TP message.
Owner:SANECHIPS TECH CO LTD

Tunnel technology-based packet processing method and apparatus

PendingEP4668682A1Networks interconnection
Embodiments of this application disclose a packet processing method based on a tunneling technology, to improve network connectivity when a network segment conflict exists in different network environments. The method in embodiments of this application includes: A cloud management platform obtains first tunnel information, where the first tunnel information includes a first tunnel destination IP address, and the first tunnel destination IP address is an IP address of a gateway. The cloud management platform establishes a first tunnel between a first network and the gateway based on the first tunnel information, a service packet generated in a running process of a first host is transmitted to the gateway through the first tunnel, and a destination IP address of the service packet is an IP address of a second host, where the first host is deployed in the first network, the second host is deployed in a second network, and a network address conflict exists between the first network and the second network. The gateway forwards the service packet to the second host based on the first tunnel information and the IP address of the second host.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Capacity-aware local repair of tunnels in wide area networks

Solutions are disclosed that enable capacity-aware local repair of tunnels in packet switched wide area networks (WANs). Traffic engineering agents on the routers are programmed to create the tunnels and include sets of primary and alternate tunnels sharing the same source and destination. A tunnel source router is provided a traffic split for allocating incoming traffic to its primary and alternate tunnels for when the primary tunnel is operating at or near full capacity operation, and another traffic split that shifts at least some traffic from the primary tunnel to the alternate tunnel, when the primary tunnel's capacity drops below a threshold. A tunnel may lose capacity for commonly-occurring reasons, such as a disturbance to cabling and faults in optical transceivers. Traffic engineering agents along the tunnel report capacity to the tunnel source router, permitting the network to respond to capacity changes more rapidly than waiting for network tunnel reconfiguration.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Distributed link tracing data processing method, device, and storage medium

Embodiments of the present disclosure relate to a distributed link tracing data processing method, a device, and a storage medium. The method includes: receiving a service request, processing the service request, caching first tracing data generated in a local cache, constructing a sub-request of the service request, delivering the sub-request to a next-hop service node, receiving second tracing data generated by the next-hop service node through processing the sub-request of the service request and fed back through a response message, caching the second tracing data in the local cache, processing the response message, caching third tracing data generated in the local cache, obtaining the first tracing data, the second tracing data, and the third tracing data, splicing the above tracing data to obtain full link tracing data generated by processing the service request, and storing the full link tracing data in a target storage device.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Ethernet Virtual Private Network Based Fabric Congestion Management

Devices, systems, methods, and processes for fabric congestion management are described herein. At each ingress switch, virtual output (“VO”) queues are created for egress ports based on identifiers, state indicators, and encapsulation values of the egress ports received via an Ethernet Virtual Private Network (“EVPN”) control plane. When a data packet is received at the ingress switch, an egress port for the data packet is determined, an identifier and an encapsulation value of the egress port are added to the data packet, and the data packet is stored in a corresponding VO queue. The data packet remains at the ingress switch until an egress switch is available. At the egress switch, one or more tags are added in the data packet based on the encapsulation value, whereas the destination egress port is identified based on the identifier. Thus, a quick egress through the egress switch is achieved.
Owner:CISCO TECHNOLOGY INC