Techniques for Flow Control Packet Processing

By decrypting only part of the encrypted packets to obtain processing information, the inefficiency problem caused by full decryption of all packets in the communication network is solved, and efficient packet processing and resource conservation are achieved.

CN109561064BActive Publication Date: 2025-07-11INTEL CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201810973600.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2017-09-26
Filing Date
2018-08-24
Publication Date
2025-07-11
Estimated Expiration
2038-08-24

AI Technical Summary

Technical Problem

In communication networks, prior art requires decryption of all encrypted packets for processing and traffic flow decisions, resulting in problems of inefficiency and high cost.

Method used

Processing information is obtained by decrypting only part of the encrypted packet, such as the header part, so that early identification and processing of the packet is achieved, avoiding full decryption of the entire packet.

Benefits of technology

Improve the efficiency of packet processing, reduce resource consumption, can identify and process high priority packets earlier, and discard non-compliant packets earlier, reducing processing delay and bandwidth usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN109561064B_ABST
    Figure CN109561064B_ABST
Patent Text Reader

Abstract

Techniques and apparatus for processing data units are described. In one embodiment, for example, an apparatus for networking may include at least one memory, and logic, at least a portion of the logic being included in hardware coupled to the at least one memory, the logic for accessing an encrypted packet having an encrypted portion, determining at least one flow control segment of the encrypted portion, decrypting the at least one flow control segment to generate a partially decrypted packet, the partially decrypted packet including the decrypted at least one flow control segment and the remaining encrypted portion, the remaining portion including the portion of the encrypted packet that does not include the decrypted at least one flow control segment, accessing processing information in the decrypted at least one flow control segment, and processing the partially decrypted packet in accordance with the processing information. Other embodiments are described and claimed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments described herein generally relate to communication networks, and more particularly, to processing packets within a communication network. Background Art

[0002] Security procedures for communication networks typically involve encrypting data traffic flowing through a secure tunnel connection, such as in a virtual private network (VPN) or an IPSec-based network. In a typical secure tunnel connection, an inner packet can be encrypted and encapsulated within an outer packet. Thus, the inner packet may be inaccessible to network layers below the network layer performing the encryption. The inner packet can include information for determining appropriate processing and traffic flow allocation of packets sent within the communication network. For the network to perform meaningful operations (such as flow identification), the encrypted data packet must first be decrypted before the workload can view the packet. In a typical network scenario, a single tunnel can contain thousands of traffic flows, each associated with thousands of packets. Additionally, the packets can pass through multiple devices, gateways, etc., each of which needs access to the inner packet information. Thus, network operations on encrypted packets are affected by inefficiencies and processing costs because all or substantially all of each packet must be decrypted for processing and / or traffic flow decisions. Brief Description of the Drawings

[0003] Figure 1 An embodiment of a first operating environment is shown.

[0004] Figure 2 An embodiment of a second operating environment is shown.

[0005] Figure 3 An embodiment of a third operating environment is shown.

[0006] Figure 4 An embodiment of a fourth operating environment is shown.

[0007] Figure 5 An embodiment of a first logical flow is shown.

[0008] Figure 6 An embodiment of a second logical flow is shown.

[0009] Figure 7 An embodiment of a storage medium is shown.

[0010] Figure 8 An embodiment of a communication architecture is shown.

[0011] Figure 9 An example computing platform is shown. Detailed Description

[0012] Various embodiments can generally relate to techniques for processing data units transmitted within a communication network. Generally, a data unit can include a data structure for transmitting information within the communication network. In some embodiments, the data unit can be or can include a packet. A network device can be configured to receive and process the data unit. Non-limiting examples of network devices can include computing devices, servers, gateways, switches, routers, network appliances, middleboxes, firewalls, load balancers, and / or software on a computing device configured to implement the operations of any of the foregoing. For example, a network device can include: a switch or a middlebox configured to receive a packet (directly or indirectly) from a source device, process the packet for flow control, and send the packet to a destination device based on the flow control information of the packet.

[0013] In an exemplary embodiment, a data unit can include various segments, including but not limited to one or more headers, payloads, and the like. One or more segments of the data unit can include data unit processing information configured to allow a network device to process the data unit. In some embodiments, the processing of the data unit can include but is not limited to determining data unit priority, data unit consistency (e.g., whether the data unit is a non-conforming data unit), data unit destination, data unit source, and the like. In various embodiments, at least a portion of the data unit segment can be encrypted. In a traditional system, the processing of a data unit requires decrypting all or substantially all of the data unit, such as a packet. However, in some embodiments, only the portion of the data unit that includes the data unit processing information can be decrypted to allow the network device to process the data unit. For example, a network device can decrypt only the inner header of an encrypted packet to determine whether the packet is a non-conforming packet and / or to determine the priority of the packet.

[0014] Thus, in some embodiments, a network device can be configured to establish a packet type (e.g., "peek" at an encrypted packet) using limited decryption of the packet. Then, the network device can make determinations related to policies, routing, quality of service (QoS), traffic flows, and the like without decrypting the entire packet. In this way, early identification of encrypted packets allows high-priority packets to be accelerated through packet processing operations and allows non-conforming packets to be discarded earlier in the process compared to traditional systems.

[0015] In this specification, numerous specific details may be set forth, such as component and system configurations, in order to provide a more thorough understanding of the invention. However, those skilled in the art will realize that the invention can be practiced without these specific details. Additionally, some well-known structures, circuits, and other features are not shown in detail to avoid unnecessarily obscuring the invention.

[0016] In the following description, references to "one embodiment", "an embodiment", "example embodiments", "various embodiments", etc., indicate that embodiments of the present invention so described may include particular features, structures, or characteristics, but that more than one embodiment may and not every embodiment must include the particular features, structures, or characteristics. Additionally, some embodiments may have some features, all features, or no features described for other embodiments.

[0017] As used in this specification and the claims and unless otherwise specified, the use of the ordinal adjectives "first", "second", "third", etc., to describe an element merely indicates a particular instance of the element or different instances of the same element and does not imply that the elements so described must be in a particular order, whether in time, space, ranking, or any other way.

[0018] Figure 1 An example of an operating environment 100 that may represent some embodiments is shown. As Figure 1 shown, the operating environment 100 may include a network 105 that interconnects a plurality of nodes 110a - n. The network 105 may conform to various network protocols, such as the Institute of Electrical and Electronics Engineers (IEEE) 802 standard series, for example, wireless devices and wireless communications (such as IEEE 802.11) that can operate with wired communication (such as IEEE 802.1 and / or 802.3). This includes at least WiFi (or Wireless Fidelity), WiMax, and Bluetooth TM wireless technologies, third generation (3G) wireless technologies, fourth generation (4G) wireless technologies, fifth generation (5G) wireless technologies, long term evolution (LTE) wireless technologies, etc. and / or any improvements or modifications or any other variations of any of the foregoing.

[0019] Nodes 110a-n may include various network devices interconnected with network 105. Non-limiting examples of nodes may include networking devices, switches, hubs, routers, nodes (e.g., eNodeB), firewalls, gateways, middleboxes, servers, computing devices, mobile computing devices, smart phones, tablet computing devices, workstations, personal computers (PCs), laptop computers, software running on any of the foregoing computing devices, and so on. In some embodiments, certain of the nodes 110a-n may include computing devices that communicate via networking devices, means, etc. For example, node 110a may be a server that communicates with a mobile device or workstation at node 110n via a networking device and / or processes (e.g., switches, firewalls, middleboxes, etc.) at nodes 110b-d. In another example, node 110a may include a tablet computing device that communicates with a smart phone at node 110n via one or more of nodes 110b-d.

[0020] In some embodiments, nodes 110a-n may send information within network 105 using data units that include packets. Non-limiting examples of packets may include Internet Protocol (IP) packets (e.g., IP version 4 (IPv4) packets and / or IP version 6 (IPv6) developed by the Internet Engineering Task Force (IETF)), Real-time Protocol (“RTP”) packets, User Datagram Protocol (“UDP”) packets, Transmission Control Protocol (“TCP”) packets, and so on. In various embodiments, security protocols may be applied to the data units. For example, Internet Protocol Security (IPSec), Secure Sockets Layer (SSL), and so on. Generally, IPSec is a set of security protocols developed by the IETF for providing security services at the IP layer of a network. IPSec provides two security protocols, namely, the IP Authentication Header (“AH”) protocol and the Encapsulating Security Payload (ESP) protocol. AH may provide connectionless integrity, data source authentication, and optional anti-replay services, while ESP may provide encryption, limited traffic flow confidentiality, connectionless integrity, data source authentication, and anti-replay services.

[0021] IP packets protected by IPSec can be sent in "transport mode" and / or "tunnel mode". Transport mode sending can be used to securely send an IP packet directly from a source node (e.g., node 110a) to its ultimate destination node (e.g., node 110n) without any intermediate security devices, such as between peer nodes (e.g., nodes 110b-d), for example. On the other hand, tunnel mode is typically used when a packet from a source node must traverse other security devices (e.g., a security gateway including one or more routers, firewalls, and / or other network devices) before reaching its destination. Nodes. Tunnel mode can also be used to hide the flow details of the packet, as only the tunnel entry and exit points are visible to anyone who might intercept the packet. Although IPSec-protected packets can be used in some examples, embodiments are not limited thereto, as any type of decrypted packet can be used according to various embodiments. In some embodiments, at least one of nodes 110a-n can include data unit processing logic 120 and / or cryptographic logic 130 configured according to some embodiments. For example, node 110c can be configured to be the same as or substantially similar to Figure 2 device 205.

[0022] Figure 2 An example of an operating environment 200 that can represent some embodiments is shown. As Figure 2 shown, the operating environment 200 can include a device 205 having a processing circuit 210, a memory 240, and one or more network interfaces 260a-n. The network interfaces 260a-n can include various networking hardware and / or software elements, circuits, devices, logic, etc. for receiving and / or sending data packets. For example, the network interfaces 260a-n can include one or more Ethernet ports and / or wireless transceivers. In some embodiments, device 205 can be similar to or can be substantially similar to Figure 1 one of nodes 110a-n (e.g., node 110c).

[0023] According to some embodiments, the processing circuit 210 can include and / or can access logic having instructions for performing operations. The processing circuit 210 can be communicatively coupled to the memory 240 and / or the network interfaces 260a-n. In some embodiments, the processing circuit 210 can include a system-on-chip (SoC), a central processing unit (CPU), an accelerometer, logic gates, etc. In various embodiments, the processing unit 210 can include Processor. Device 205 may be or may include various network devices, including computing devices (e.g., servers) for implementing networking functions, networking devices, and / or software applications. For example, device 205 may be or may implement a middlebox, router, switch, firewall, VPN, IPSec tunnel, and so on. In some embodiments, device 205 may be a middlebox for controlling traffic within network 205, for example, according to the IPSec security protocol.

[0024] According to some embodiments, processing circuitry 210 may include and / or may access various logics for performing processing. For example, the processing circuitry may include and / or may access data unit processing logic 220 (or "packet processing logic" for embodiments in which the data unit includes packets) and / or cryptographic logic 230. The data unit processing logic 220 and / or the cryptographic logic 230 may be implemented in hardware, software, or a combination thereof. As used in this application, the terms "logic", "component", "layer", "system", "circuitry", and / or "module" are intended to refer to a computer-related entity, whether hardware, a combination of hardware and software, software, or software in execution, examples of which are provided by the exemplary computing architecture 900. For example, a logic, circuitry, or layer may be and / or may include, but is not limited to, a process running on a processor, a processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable program, an execution thread, a program, a computer, a hardware circuit, an integrated circuit, an application specific integrated circuit (ASIC), a programmable logic device (PLD), a digital signal processor (DSP), a field programmable gate array (FPGA), a memory unit, a logic gate, a register, a semiconductor device, a chip, a microchip, a chipset, a software component, a program, an application, firmware, a software module, computer code, any combination of the foregoing, and so on.

[0025] The data unit processing logic 220 may be used to implement the processing of the data units of device 205. In some embodiments, the data units may include encrypted packets (e.g., see Figure 4)。Although grouping may be used in some examples, the embodiments are not limited thereto, as any data unit capable of operating according to various embodiments is contemplated herein. For example, the data unit may include an encrypted file, an encrypted data stream, and the like. The processing of the data unit by the data unit processing logic 220 may include implementing flow control operations on the encrypted packets. Non-limiting examples of flow control operations may include determining non-conforming packets, determining packet priorities, decrypting all or a part of the packet, and / or sending the packet (e.g., via the network 270 to the nodes 280a-n). In some embodiments, the apparatus 205 may include or may have access to the cryptographic logic 230. In various embodiments, the cryptographic logic 230 may be operatively coupled to the processing circuit and / or the data unit processing logic 220 or otherwise be able to be used by the processing circuit and / or the data unit processing logic 220 to decrypt all or a part of the encrypted packet according to some embodiments.

[0026] In an exemplary embodiment, the apparatus 205 may be used to implement a flow control process for encrypted packets received at the apparatus 205. The data unit processing logic 220 may determine a target portion of the packet that includes the data unit processing information 250 (or “processing information”), and the data unit processing information 250 indicates how the packet should be processed. The target portion may include various parts or segments of the packet, such as the header of the packet. The data unit processing logic 220 may decrypt or cause to be decrypted only the target portion of the packet (e.g., via the cryptographic logic 230) to determine the processing information 250. Then, the data unit processing logic 220 may process the packet according to the processing information 250 (see, e.g., Figure 6 ).

[0027] Thus, the apparatus 205 according to some embodiments may use decrypting a limited portion of the packet to analyze (or “peek into”) the encrypted packet to determine the processing information 250, without using resources to decrypt the remaining portion of the packet that is not involved in the processing by the data unit processing logic 220. The data unit processing logic 220 may use the processing information 250 to perform flow control operations, such as policies, routing, QoS, priorities, and / or similar operations, on the partially decrypted packet without decrypting the entire packet. In this way, the apparatus 205 may provide early identification of encrypted packets (e.g., earlier in the processing path compared to traditional systems) so that high-priority packets may be accelerated through the packet processing operations and non-conforming packets, etc. may be discarded earlier (e.g., eliminating resources for processing non-conforming packets that are later found in the packet processing operations of traditional systems). For example, the data unit processing logic 220 may decrypt the first 18 bytes of the encrypted portion of the packet to allow the workload to view the internally decrypted 802.1 priority code point (PCP) or Ethernet priority bits, UP, class of service (CoS), type of service (ToS), etc.

[0028] In this way, the apparatus 205 can provide early detection of high-priority packets, e.g., based on decrypted header information (e.g., internal Differentiated Services Code Point (DSCP) information). This early processing can allow for high-priority policing, routing, and QoS decisions, etc., earlier in the packet processing path than in traditional systems, which results in lower latency for high-priority packets. Additionally, non-conforming packets can be detected earlier and discarded earlier than in traditional systems, thus saving resources and bandwidth. Further, some embodiments can remove head-of-line blocking when using software or hardware accelerators (or for example, all packets reach the accelerators for decryption, and thus, they slow down smaller and potentially higher-priority packets). Additionally, exemplary embodiments can provide various performance benefits for processing encrypted packets. For example, the decryption processing of packets can require fewer cycles because, compared to the entire packet in traditional systems, according to some embodiments for flow control processing, only a portion of the packet (e.g., for a packet of MTU size, the embodiment can provide a 30-fold performance advantage in terms of processing cycles) can be processed.

[0029] In some embodiments, the apparatus 205 can be a network device for implementing secure connections, such as VPNs, IPsec tunnels, etc. For example, the apparatus 205 can be a network middlebox. In various embodiments, the apparatus 205 can be arranged within the network 270 to terminate secure connections (e.g., IPsec tunnels) for one or more of the nodes 280a-n. In some embodiments, one or more of the nodes 280a-n can be configured to be the same as or substantially similar to the apparatus 205. In various embodiments, the apparatus 205 can access per-flow security keys, e.g., via the cryptographic logic 230, since the apparatus 205 can operate to generate and / or terminate encrypted packets within the secure connections of the network 270. In some embodiments, the apparatus 205 can be and / or can implement a mobile network gateway (e.g., in 3G networks, 4G networks, 5G networks, and / or their revisions, such as SGW / PGW, general security gateway devices, load balancers (with VPN termination), broadband networks (e.g., BNG gateways), etc.).

[0030] Figure 3 An example of an operating environment 300 that can represent some embodiments is shown. As Figure 3As shown, the operating environment 300 may include a device 305 having processing circuitry (not shown) operable to access and / or execute flow control logic 320 and / or cryptographic logic 330 to perform data unit processing in accordance with various embodiments. In various embodiments, the device 305 may be or may be substantially similar to the device 205 and / or the nodes 110a-n. A data unit 350 having a plurality of segments 360a-n may be received by the device 305. The data unit 350 may include a packet, and the segments 360a-n may include respective portions of the packet, such as a header, a payload, and the like.

[0031] In some embodiments, portions of the packet 350 may be encrypted according to an encryption protocol. For example, the segments 360c-n may be encrypted, while the segments 360a and 360b may be unencrypted headers (e.g., headers added as part of the encryption process). The packet 350 may be provided to the flow control logic 320, which may process the unencrypted or "outer" layer of the packet 350, such as the segments 360a and 360b. Non-limiting examples of the processing of the outer layer of the packet 350 may include authentication, determining the encryption type, QoS information, and the like. However, the processing of the outer layer may not be sufficient to fully process the packet 350, which may require access to processing information (e.g., the segments 360c-n) within the encrypted portion of the packet.

[0032] The flow control logic 320 may determine which segment or segments of the packet 350 need to be decrypted in order to determine the processing information 380. For example, the flow control logic 320 may include and / or may access operation information 315 configured to indicate which segment or segments to decrypt, such as based on information in the outer layer, the packet type, the firmware, the policy, and the like. In some embodiments, the type of the packet may include the communication protocol for the packet. For example, an Ethernet protocol packet may include certain segments known to include processing information, while a Multiprotocol Label Switching (MPLS) or Layer 2.5 packet may include the same segments or other segments containing processing information.

[0033] The flow control logic 320 may use or otherwise access the cryptographic logic 330 to decrypt a portion of the packet 350 to access the processing information. For example, the flow control logic 320 may determine that the segment 360c ("flow control segment") needs to be decrypted. The cryptographic logic 330 may decrypt the segment 360c of the packet 350 to generate a partially decrypted packet 352 with a decrypted internal segment 370. According to various embodiments, the flow control logic 320 may access the processing information from the internal segment 370 to process the partially decrypted packet 352 (or in some embodiments, the original packet 350). In some embodiments, the flow control segment may include discrete segments of a data unit, such as a header or a payload. In some embodiments, the flow control segment may include a specified length (e.g., number of bits) of a portion of a data unit. For example, the flow control segment may include the first x bytes of a portion of an encrypted segment.

[0034] Figure 4 An example of an operating environment 400 that may represent some embodiments is shown. As Figure 4 shown, the operating environment 400 may include a device 405 having a processing circuit (not shown) that, according to various embodiments, is operable to access and / or execute the flow control logic 420 and / or the cryptographic logic 430 to perform data unit processing. Although Figure 4 only one device is depicted, the operations performed by the device 405 may be performed by multiple devices. For example, a first device (e.g., a server) may perform encryption, and a second device (e.g., a networking device, a gateway, a router, a middlebox, etc.) may perform flow control decryption. In some embodiments, the device 405 may be or may be substantially similar to the device 205 and / or 305 or the node 110a-n.

[0035] A packet 425 may be generated, which includes various segments, such as an IP header 422, an extended header 424, an internal header 426, a transport header 428, and / or a payload 440. At least a portion of the packet 425 may be encrypted using an encryption protocol. In some embodiments, the packet 425 may include various external extended headers 460. For example, the packet 425 may be a Multiprotocol Label Switching (MPLS) or a Layer 2.5 packet, a QinQ or an IEEE 802.11ad packet, a packet with a Network Service Header (NSH), and / or a similar packet with an external extended header 460. In some embodiments, the external extended header 460 may include various information, such as priority information, QoS information, and / or similar information. In some embodiments, the external extended header 460 may be before or in front of the IP header 422.

[0036] In an exemplary embodiment, the packet 425 may undergo ESP IPSec encryption to become an encrypted packet 435, which includes an ESP header 450 and an encrypted portion 452 (e.g., an encrypted payload 440 and encrypted headers such as an extension header 424, an inner header 426, a transport header 428). In some embodiments, the packet 435 may be generated at a first computing device and sent via a network (e.g., network 105 or 270) to a second computing device (e.g., a network device such as device 205) for processing. In some embodiments, certain headers may be retained and unencrypted in the encrypted packet 435 (“retained headers”), such as the IP header 422 and / or the outer extension header 460.

[0037] The flow control logic 420 may determine that at least a portion of the processing information is within the inner header 426, and the remaining encrypted portions of the encrypted packet 435 are not necessary for the flow control processing of the encrypted packet 435. In some embodiments, the flow control logic 420 may determine the location of the processing information based on the hardware / software instructions of the flow control logic 420 or the hardware / software instructions accessible by the flow control logic 420. For example, the flow control logic 420 may be programmed or otherwise configured to decrypt the inner header 426 of the encrypted packet for the processing information. In various embodiments, the flow control logic 420 may obtain information from the outer layer of the encrypted packet (“outer layer information”) and may use this information to determine the segments of the encrypted packet to be decrypted. For example, the IP header 422 and / or the ESP header of the encrypted packet 435 may include outer layer information indicating that the processing information is located within the inner header 426.

[0038] The flow control logic 420 may perform a flow control decryption process, for example, via the cryptographic logic 430, to partially decrypt the encrypted packet 435 to generate a partially decrypted packet 445. As Figure 4 shown, the partially decrypted packet 445 may cause the inner packet 426 to be decrypted, while other portions of the encrypted portion 452 may remain encrypted as the encrypted portion 470 (or the remaining portion of the encrypted portion 470). According to some embodiments, the flow control logic 420 may access the processing information of the inner header 426 to process the partially decrypted packet 445.

[0039] In some embodiments, the flow control logic 420 may decrypt more, fewer, or different portions of the encrypted packet 435 based on the specific processing information required to process the encrypted packet 435. For example, in various embodiments, the flow control logic 420 may operate to perform a first processing operation (e.g., packet prioritization) that requires only the processing information (e.g., the inner header 426) from the first portion of the encrypted portion 452. Accordingly, only the first portion (e.g., the inner header 426) may be decrypted to partially generate the decrypted packet 445. In another example, the flow control logic 420 may operate to perform a second processing operation that requires information from a second portion of the encrypted portion 452, such as the transport header 428. Accordingly, only the second portion (e.g., the transport header 428) may be decrypted to generate the partially decrypted packet 445. In another example, the flow control logic 420 may operate to perform the first and second processing operations, and accordingly, the flow control logic 420 may decrypt both the first and second portions to generate the partially decrypted packet 445. In some embodiments, a portion of the processing information may be included in one or more reserved headers, such as the IP header 422 and / or the outer extension header 460. In various embodiments, the processing information or outer layer information in the reserved headers may be combined with the processing information (or other decrypted portions of the partially decrypted packet 445) within the inner IP header 426 to provide information or instructions for processing the partially decrypted packet. For example, the extension header 460 may include priority information that may be combined with the processing information of the inner IP header 426 for priority determination.

[0040] A set of logic flows are included herein that represent exemplary methods for performing novel aspects of the disclosed architecture. While, for purposes of simplifying the description, one or more of the methods shown herein are shown and described as a series of acts, those skilled in the art will understand and appreciate that these methods are not limited by the order of the acts. Accordingly, some acts may occur in a different order and / or concurrently with other acts shown and described herein. For example, those skilled in the art will understand and appreciate that the methods may alternatively be represented as a series of interrelated states or events, such as in a state diagram. Additionally, not all acts shown in the methods may be required for a novel implementation.

[0041] The logic flows may be implemented in software, firmware, and / or hardware. In software and firmware embodiments, the logic flows may be implemented by computer-executable instructions stored on a non-transitory computer-readable medium or machine-readable medium (e.g., optical, magnetic, or semiconductor storage). The embodiments are not limited to this context.

[0042] Figure 5An embodiment of a logical flow 500 is shown. The logical flow 500 may represent some or all of the operations performed by one or more embodiments described herein, such as operations performed by one or more of the devices 205, 305, and / or 405. For example, the logical flow 500 may generally include operations for a device such as a networking device (e.g., a middlebox) to determine processing information for an encrypted packet.

[0043] At block 502, the logical flow 500 may access an encrypted data unit. For example, the flow control logic 320 may receive an encrypted data unit 350 in the form of an encrypted packet. At block 504, the logical flow 500 may process the outer layer of the data unit. For example, the flow control logic 320 may process the outer non-encrypted layer of the encrypted packet 350, such as an IP header, an encryption header (e.g., a header added to the encrypted packet 350 during the encryption process, such as the ESP header 450 of the encrypted packet 435, etc.).

[0044] At block 506, the logical flow 500 may determine a flow control segment. In some embodiments, the flow control segment may include a segment of the encrypted data unit that includes processing information. In various embodiments, the processing of the outer layer of the encrypted data packet may provide operational information, such as the packet type, encryption type, QoS, etc. that the flow control logic 320 may use to determine the flow control segment. In an exemplary embodiment, the flow control logic 320 may be programmed or otherwise configured to determine certain flow control segments, such as an inner header, a segment with DSCP information, etc. In various embodiments, the flow control segment may change dynamically based on conditions such as resource requirements. For example, the flow control logic 320 may provide certain processing operations based on (e.g., from an operator, application, and / or the like) resource demands, bandwidth, instructions, etc. In one example, the flow control logic 320 may perform a first processing operation under certain resource conditions (e.g., based on thresholds of processor performance, processor utilization, data traffic, bandwidth, etc.), which requires the decryption of the first header of each encrypted packet. The flow control logic 320 may perform a first processing operation and a second processing operation under different conditions, which requires the decryption of the first header of each encrypted packet and a specific number of bytes of its payload.

[0045] At block 508, the logical flow 500 may decrypt the flow control segment. For example, the flow control logic 320 may decrypt the flow control segment (e.g., segment 360c of the encrypted packet 350) (or use the encryption logic 330 to decrypt) to generate an unencrypted inner segment 370 of the partially decrypted packet 352. At block 510, the logical flow 500 may determine the processing information. For example, the flow control logic 320 may access the processing information 380 from the decrypted inner segment 370.

[0046] Figure 6 An embodiment of a logical flow 600 is shown. The logical flow 600 may represent some or all of the operations performed by one or more of the embodiments described herein, such as operations performed by one or more of the apparatuses 205, 305, and / or 405. For example, the logical flow 600 may generally include operations for an apparatus such as a networking device (e.g., a middlebox) to process a partially decrypted packet.

[0047] At block 602, the logical flow 600 may access processing information. For example, the flow control logic 320 may receive or otherwise access the processing information 380 of the partially decrypted packet 352 (e.g., obtained using the process described in the logical flow 500 of Figure 5 ). At block 604, the logical flow 600 may perform a processing operation on the partially decrypted data unit based on the processing information. For example, the flow control logic 320 may perform various processing operations on the partially decrypted packet 352 based on the processing information 380 (e.g., the internal header information of the partially decrypted packet 352), such as certain classification operations. Non-limiting examples of processing operations may include non-compliant data unit classification, priority classification, transmission classification, policy-based processing, routing, QoS processing, etc.

[0048] At block 606, the logical flow 600 may determine whether the partially decrypted data unit is a non-compliant data unit. For example, the flow control logic 320 may use the processing information 380 of the partially decrypted packet 352 to determine whether the packet 350 (and / or the partially decrypted packet 352) is a non-compliant packet based on one or more compliance criteria. Non-limiting examples of compliance criteria may include compliance with communication specifications destined for a congested node or network, token depth, bandwidth capacity, exceeding a defined limit (e.g., a burst limit), compliance with packet segments (e.g., headers), etc., compliance with encryption protocols, corrupted data, packet size, packet source, etc. In some embodiments, the compliance criteria may include any type of criteria known in the art for determining whether a packet is a non-compliant packet that can be operated on according to various embodiments. At block 606, if the logical flow 600 determines that the data unit is a non-compliant data unit, the logical flow 600 may perform non-compliant data unit processing at block 608. For example, the flow control logic 320 may discard the partially decrypted packet 352 of the non-compliant data part and / or increment the count of non-compliant packets.

[0049] At block 606, if the logic flow 600 determines that the data unit is not a non-conforming data unit, then at block 610, the logic flow 600 may determine whether the data unit is a high-priority data unit. For example, the flow control logic 320 may analyze the processing information 380 of the partially decrypted packet 352 to classify the partially decrypted packet 352 based on the priority information of the processing information 380. At block 610, if the logic flow 600 determines that the data unit is a high-priority data unit, then at block 612, the logic flow 600 may perform high-priority processing. For example, the high-priority data unit may be immediately sent (or placed in a queue) for processing (e.g., to an accelerometer or other processing device, circuit, logic, etc.) rather than being blocked behind low-priority data units or non-conforming data units as in traditional systems. If at block 610 the logic flow 600 determines that the data unit is not a high-priority data unit, then at block 614 the logic flow 600 may perform low-priority processing. For example, the low-priority data unit may be sent and processed at a lower priority or placed behind higher-priority data units in a queue.

[0050] At block 616, the logic flow 600 may perform full data decryption. For example, the flow control logic 320 may fully decrypt the partially decrypted packet 352 (e.g., decrypt the segment 360n) to generate a fully decrypted packet. At block 618, the logic flow 600 may provide the decrypted data unit to the destination. For example, the data unit processing logic 220 may send the decrypted data unit via the network interface 260a-n to the network 270 and thus to the final destination node 280a-n (which may travel via one or more intermediate nodes 280a-n).

[0051] Figure 7 An example of a storage medium 700 is shown. The storage medium 700 may include an article of manufacture. In some examples, the storage medium 700 may include any non-transitory computer-readable medium or machine-readable medium, such as optical, magnetic, or semiconductor memory. The storage medium 700 may store various types of computer-executable instructions, such as instructions for implementing the logic flow 500 and / or the logic flow 600. Examples of computer-readable or machine-readable storage media may include any tangible medium capable of storing electronic data, including volatile memory or non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, etc. Examples of computer-executable instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, object-oriented code, visual code, etc. The examples are not limited to this context.

[0052] Figure 8A block diagram of an exemplary communication architecture 800 suitable for implementing the various embodiments described above is shown. The communication architecture 800 includes various common communication elements such as transmitters, receivers, transceivers, radios, network interfaces, baseband processors, antennas, amplifiers, filters, power supplies, etc. However, the embodiments are not limited to the implementation of the communication architecture 800.

[0053] As Figure 8 shown, the communication architecture 800 includes one or more clients 802 and a server 804. The clients 802 and the server 804 are operatively connected to one or more respective client data storage devices 808 and server data storage devices 810, and the server data storage device 810 can be used to store information local to each of the clients 802 and the server 804, such as cookies and / or associated context information. Any one of the clients 802 and / or the server 804 can implement one or more of the apparatuses 205, 305, and / or 405 and / or the logic flows 500 and / or 600, the storage medium 900, and / or the computing architecture 900.

[0054] The clients 802 and the server 804 can transmit information to each other using the communication framework 806. The communication framework 806 can implement any well-known communication technologies and protocols. The communication framework 806 can be implemented as a packet-switched network (e.g., a public network such as the Internet, a private network such as an enterprise intranet, etc.), a circuit-switched network (e.g., a public switched telephone network), or a combination of a packet-switched network and a circuit-switched network (with appropriate gateways and converters).

[0055] The communication framework 806 can implement various network interfaces that are arranged to receive, communicate with, and connect to a communication network. The network interfaces can be regarded as a specialized form of input / output interfaces. The network interfaces can adopt connection protocols including but not limited to direct connection, Ethernet (e.g., thick, thin, twisted pair 10 / 100 / 1000Base T, etc.), Token Ring, wireless network interfaces, cellular network interfaces, IEEE 802.lla - x network interfaces, IEEE 802.16 network interfaces, IEEE 802.20 network interfaces, etc. Additionally, multiple network interfaces can be used to interface with various communication network types. For example, multiple network interfaces can be employed to allow communication over broadcast, multicast, and unicast networks. If processing requirements dictate greater speed and capacity, a distributed network controller architecture can similarly be adopted to centralize, load balance, and otherwise increase the communication bandwidth required by clients 802 and servers 804. The communication network can be any one and a combination of wired and / or wireless networks, including but not limited to direct interconnection, secure custom connections, private networks (e.g., enterprise intranets), public networks (e.g., the Internet), personal area networks (PAN), local area networks (LAN), metropolitan area networks (MAN), operational mission as a node on the Internet (OMNI), wide area networks (WAN), wireless networks, cellular networks, and other communication networks.

[0056] Figure 9 An embodiment of an exemplary computing architecture 900 suitable for implementing the various embodiments described above is shown. In various embodiments, the computing architecture 900 can be included or implemented as part of an electronic device. In some embodiments, the computing architecture 900 can represent, for example, devices 205, 305, and / or 405. The embodiments are not limited to this context.

[0057] As used in this application, the terms "system" and "component" and "module" are intended to refer to computer-related entities, whether hardware, a combination of hardware and software, software, or software in execution, examples of which are provided by the exemplary computing architecture 900. For example, a component can be, but is not limited to, a process running on a processor, a processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable file, an executing thread, a program, and / or a computer. For instance, an application running on a server and the server can both be components. One or more components can reside within a process and / or an executing thread, and a component can be located on one computer and / or distributed between two or more computers. Additionally, components can be communicatively coupled to each other via various types of communication media to coordinate operations. The coordination can involve one-way or two-way information exchange. For example, a component can transmit information in the form of signals transmitted via a communication medium. The information can be implemented as signals assigned to various signal lines. In such an assignment, each message is a signal. However, alternative embodiments can instead employ data messages. Such data messages can be sent via various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.

[0058] The computing architecture 900 includes various common computing elements, such as one or more processors, multi-core processors, co-processors, memory units, chip sets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, embodiments are not limited to the implementation of the computing architecture 900.

[0059] As Figure 9 shown, the computing architecture 900 includes a processing unit 904, a system memory 906, and a system bus 908. The processing unit 904 can be any of a variety of commercially available processors, including but not limited to and processors; application, embedded, and security processors; and and processors; IBM and Cell processors; Core(2) and processors; and similar processors. Dual microprocessors, multi-core processors, and other multi-processor architectures can also be used as the processing unit 904.

[0060] The system bus 908 provides an interface for system components to the processing unit 904, and the system components include but are not limited to the system memory 906. The system bus 908 can be any one of several types of bus structures, which can be further interconnected to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using various commercial bus architectures. The interface adapter can be connected to the system bus 908 through a slot architecture. Example slot architectures can include but are not limited to Accelerated Graphics Port (AGP), Card Bus, (Extended) Industry Standard Architecture ((E)ISA), Micro Channel Architecture (MCA), NuBus, Peripheral Component Interconnect (Extended) (PCI(X)), PCI Express, Personal Computer Memory Card International Association (PCMCIA), etc.

[0061] The system memory 906 can include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, polymer memory such as ferroelectric polymer memory, bidirectional memory, phase change or ferroelectric memory, silicon oxide-nitride-oxide-silicon (SONOS) memory, magnetic or optical cards, device arrays such as redundant array of independent disks (RAID) drives, solid-state memory devices (e.g., USB memory, solid-state drive (SSD)), and any other type of storage media suitable for storing information. In Figure 9 In the illustrated embodiment, the system memory 906 can include non-volatile memory 910 and / or volatile memory 912. The basic input / output system (BIOS) can be stored in the non-volatile memory 910.

[0062] The computer 902 can include various types of computer-readable storage media in the form of one or more low-speed memory units, including an internal (or external) hard disk drive (HDD) 914, a magnetic floppy disk drive (FDD) 916 for reading from or writing to a removable magnetic floppy disk 918, and an optical disk drive 920 for reading from or writing to a removable optical disk 922 (e.g., CD-ROM or DVD). The HDD 914, FDD 916, and optical disk drive 920 can be connected to the system bus 908 through an HDD interface 924, an FDD interface 926, and an optical disk drive interface 928, respectively. The HDD interface 924 for external drive implementation can include at least one or both of Universal Serial Bus (USB) and IEEE 1384 interface technologies.

[0063] The drive and associated computer-readable media provide volatile and / or non-volatile storage of data, data structures, computer-executable instructions, and the like. For example, many program modules can be stored in the drive and memory units 910, 912, including an operating system 930, one or more application programs 932, other program modules 934, and program data 936. In one embodiment, one or more application programs 932, other program modules 934, and program data 936 can include, for example, various applications and / or components of computing nodes 150, 405, 505, and / or 605 and server node 150.

[0064] The user can input commands and information into the computer 902 through one or more wired / wireless input devices (e.g., a keyboard 938 and an indicating device such as a mouse 940). Other input devices can include a microphone, an infrared (IR) remote control, a radio frequency (RF) remote control, a gamepad, a stylus, a card reader, a dongle, a fingerprint reader, a glove, a graphics tablet, a joystick, a keyboard, a retina reader, a touch screen (e.g., capacitive, resistive, etc.), a trackball, a touchpad, a sensor, a stylus pen, etc. These and other input devices are typically connected to the processing unit 904 through an input device interface 942 coupled to the system bus 908, but can be connected through other interfaces, such as a parallel port, an IEEE 1384 serial port, a game port, a USB port, an IR interface, etc.

[0065] A monitor 944 or other type of display device is also connected to the system bus 908 through an interface such as a video adapter 946. The monitor 944 can be inside or outside the computer 902. In addition to the monitor 944, the computer typically also includes other peripheral output devices, such as speakers, printers, etc.

[0066] The computer 902 can operate in a network environment using a logical connection via wired and / or wireless communication with one or more remote computers (e.g., remote computer 948). The remote computer 948 can be a workstation, a server computer, a router, a personal computer, a portable computer, a microprocessor-based entertainment device, a peer device, or other common network nodes, and typically includes many or all of the elements described with respect to the computer 902, but for the sake of brevity, only the memory / storage device 950 is shown. The depicted logical connections include wired / wireless connections to a local area network (LAN) 952 and / or a larger network (e.g., a wide area network (WAN) 954). Such LAN and WAN networking environments are common in offices and companies and facilitate enterprise-wide computer networks, such as intranets, all of which can be connected to a global communication network, such as the Internet.

[0067] When used in a LAN networking environment, computer 902 is connected to LAN 952 through a wired and / or wireless communication network interface or adapter 956. Adapter 956 can facilitate wired and / or wireless communication to LAN 952, and may also include a wireless access point disposed thereon for communicating with the wireless functions of adapter 956.

[0068] When used in a WAN networking environment, computer 902 may include a modem 958, or be connected to a communication server on WAN 954, or have other units for establishing communication through WAN 954 (such as through the Internet). Modem 958 can be internal or external and a wired and / or wireless device, and is connected to system bus 908 via input device interface 942. In a network environment, program modules described relative to computer 902 or portions thereof may be stored in remote memory / storage device 950. It can be understood that the network connections shown are exemplary, and other means for establishing communication links between computers may be used.

[0069] Computer 902 is operable to communicate with wired and wireless devices or entities using the IEEE 802 standard series, such as wireless devices operably set up in wireless communication (e.g., IEEE 802.16 air modulation technology). This includes at least Wi-Fi (or Wireless Fidelity), WiMax, and Bluetooth TM wireless technologies. Thus, the communication can be a predefined structure like a traditional network, or just an ad-hoc communication between at least two devices. Wi-Fi networks use radio technologies called IEEE802.11x (a, b, g, n, etc.) to provide secure, reliable, and fast wireless connections. Wi-Fi networks can be used to connect computers to each other, to the Internet, and to wired networks (using IEEE 802.3 related media and functions).

[0070] One or more aspects of at least one embodiment can be implemented by representative instructions stored on a machine-readable medium, which represent various logics within a processor and, when read by a machine, cause the machine to fabricate the logic that executes the techniques described herein. Such a representation, known as an "IP core," can be stored on a tangible machine-readable medium and provided to various customers or manufacturing facilities to be loaded into the manufacturing machines that actually fabricate the logic or processor. Some embodiments can be implemented, for example, using a machine-readable medium or article that can store instructions or a set of instructions that, if executed by a machine, can cause the machine to perform the methods and / or operations according to the embodiments. Such a machine can include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and can be implemented using any suitable combination of hardware and / or software. The machine-readable medium or article can include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium, and / or storage unit, such as, for example, memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disk, floppy disk, compact disc read-only memory (CD-ROM), recordable compact disc (CD-R), rewritable compact disc (CD-RW), optical disc, magnetic medium, magneto-optical medium, removable memory card or disk, various types of digital versatile discs (DVDs), magnetic tape, cassette tape, etc. The instructions can include any suitable type of code implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc.

[0071] The following includes non-limiting example embodiments:

[0072] Example I is a device for networking, including: at least one memory, a logic, at least a part of which is included in hardware coupled to the at least one memory, the logic for accessing an encrypted packet having an encrypted portion, determining at least one flow control segment of the encrypted portion, decrypting the at least one flow control segment to produce a partially decrypted packet, the partially decrypted packet including the decrypted at least one flow control segment and the remaining encrypted portion, the remaining portion including the portion of the grouped encryption that does not include the decrypted at least one flow control segment, accessing the processing information in the decrypted at least one flow control segment, and processing the partially decrypted packet based on the processing information.

[0073] Example 2 is the device of Example 1, wherein the encrypted packet is encrypted according to the Internet Protocol Security (IP Sec) protocol.

[0074] Example 3 is the apparatus of Example 1, where the encrypted packet is encrypted according to the Encapsulating Security Payload (ESP) protocol of Internet Protocol Security (IPSec).

[0075] Example 4 is the apparatus of Example 1, where the logic is used to determine at least one flow control segment based on the type of the encrypted packet.

[0076] Example 5 is the apparatus of Example 1, where the logic is used to determine at least one flow control segment based on the type of the encrypted packet, and the type includes the communication protocol for the encrypted packet.

[0077] Example 6 is the apparatus of Example 1, where the at least one flow control segment includes a header.

[0078] Example 7 is the apparatus of Example 1, where the at least one flow control segment includes an inner header.

[0079] Example 8 is the apparatus of Example 1, where the at least one flow control segment includes an encrypted portion of a specified length.

[0080] Example 9 is the apparatus of Example 1, where the at least one flow control segment includes a specified number of bits of the encrypted portion.

[0081] Example 10 is the apparatus of Example 1, where the encrypted packet includes an unencrypted portion, and the unencrypted portion includes an Internet Protocol (IP) header.

[0082] Example 11 is the apparatus of Example 1, where the encrypted packet includes an unencrypted portion, and the unencrypted portion includes an Internet Protocol (IP) header and at least one outer extension header.

[0083] Example 12 is the apparatus of Example 1, where the logic is used to determine processing information from the unencrypted portion of the encrypted packet, and the unencrypted portion includes at least one of an Internet Protocol (IP) header and at least one outer extension header.

[0084] Example 13 is the apparatus of Example 1, where the processing information includes Differentiated Services Code Point (DSCP) information.

[0085] Example 14 is the apparatus of Example 1, where the logic is used to classify a partially decrypted packet based on the processing information.

[0086] Example 15 is the apparatus of Example 1, where the logic is used to determine whether a partially decrypted packet is a non-conforming packet based on the processing information.

[0087] Example 16 is the apparatus of Example 1, where the logic is used to determine the priority of a partially decrypted packet based on the processing information.

[0088] Example 17 is the apparatus of Example 1, and the logic is for decrypting the remainder of a partially decrypted packet to produce a decrypted packet.

[0089] Example 18 is the apparatus of Example 1, and the logic is for decrypting the remainder of a partially decrypted packet to produce a decrypted packet and sending the decrypted packet.

[0090] Example 19 is a system, including an apparatus according to any one of Examples 1-18, and at least one network interface.

[0091] Example 20 is a method for networking, including: at least one memory, a logic, at least a portion of the logic being included in hardware coupled to the at least one memory, the logic being for accessing an encrypted packet having an encrypted portion, determining at least one flow control segment of the encrypted portion, decrypting the at least one flow control segment to produce a partially decrypted packet, the partially decrypted packet including the decrypted at least one flow control segment and the encrypted remainder, the remainder including a portion of the encrypted packet that does not include the decrypted at least one flow control segment, accessing processing information in the decrypted at least one flow control segment, and processing the partially decrypted packet according to the processing information.

[0092] Example 21 is the method of Example 20, wherein the encrypted packet is encrypted according to the Internet Protocol Security (IP Sec) protocol.

[0093] Example 22 is the method of Example 20, wherein the encrypted packet is encrypted according to the Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol.

[0094] Example 23 is the method of Example 20, including determining at least one flow control segment based on the type of the encrypted packet.

[0095] Example 24 is the method of Example 20, including determining at least one flow control segment based on the type of the encrypted packet, the type including a communication protocol for the encrypted packet.

[0096] Example 25 is the method of Example 20, wherein the at least one flow control segment includes a header.

[0097] Example 26 is the method of Example 20, wherein the at least one flow control segment includes an inner header.

[0098] Example 27 is the method of Example 20, wherein the at least one flow control segment includes an encrypted portion of a specified length.

[0099] Example 28 is the method of Example 20, wherein the at least one flow control segment includes a specified number of bits of the encrypted portion.

[0100] Example 29 is the method of Example 20, where the encrypted packet includes an unencrypted portion that includes an Internet Protocol (IP) header.

[0101] Example 30 is the method of Example 20, where the encrypted packet includes an unencrypted portion that includes an Internet Protocol (IP) header and at least one outer extension header.

[0102] Example 31 is the method of Example 20, including: determining processing information from the unencrypted portion of the encrypted packet, where the unencrypted portion includes at least one of an Internet Protocol (IP) header and at least one outer extension header.

[0103] Example 32 is the method of Example 20, where the processing information includes Differentiated Services Code Point (DSCP) information.

[0104] Example 33 is the method of Example 20, including classifying the partially decrypted packet based on the processing information.

[0105] Example 34 is the method of Example 20, including determining whether the partially decrypted packet is a non-conforming packet based on the processing information.

[0106] Example 35 is the method of Example 20, including determining the priority of the partially decrypted packet based on the processing information.

[0107] Example 36 is the method of Example 20, including decrypting the remainder of the partially decrypted packet to generate a decrypted packet.

[0108] Example 37 is the method of Example 20, including decrypting the remainder of the partially decrypted packet to generate a decrypted packet and sending the decrypted packet.

[0109] Example 38 is a computer-readable storage medium that stores computer-executable instructions for execution by a processing circuit of a computing device. The computer-executable instructions, when executed, cause the computing device to access an encrypted packet having an encrypted portion, determine at least one flow control segment of the encrypted portion, decrypt at least one flow control segment to generate a partially decrypted packet that includes the decrypted at least one flow control segment and the encrypted remainder, where the remainder includes a portion of the encrypted packet that does not include the decrypted at least one flow control segment, access processing information in the decrypted at least one flow control segment, and process the partially decrypted packet based on the processing information.

[0110] Example 39 is the computer-readable storage medium of Example 38, where the encrypted packet is encrypted according to the Internet Protocol Security (IPSec) protocol.

[0111] Example 40 is a computer-readable storage medium of Example 38, and the encrypted packet is encrypted according to the Encapsulating Security Payload (ESP) protocol of Internet Protocol Security (IPSec).

[0112] Example 41 is a computer-readable storage medium of Example 38, and the computer-executable instructions, when executed, cause the computing device to determine at least one flow control segment based on the type of the encrypted packet.

[0113] Example 42 is a computer-readable storage medium of Example 38, and the computer-executable instructions, when executed, cause the computing device to determine at least one flow control segment based on the type of the encrypted packet, where the type includes the communication protocol for the encrypted packet.

[0114] Example 43 is a computer-readable storage medium of Example 38, and the at least one flow control segment includes a header.

[0115] Example 44 is a computer-readable storage medium of Example 38, and the at least one flow control segment includes an inner header.

[0116] Example 45 is a computer-readable storage medium of Example 38, and the at least one flow control segment includes an encrypted portion of a specified length.

[0117] Example 46 is a computer-readable storage medium of Example 38, and the at least one flow control segment includes a specified number of bits of the encrypted portion.

[0118] Example 47 is a computer-readable storage medium of Example 38, and the encrypted packet includes an unencrypted portion, and the unencrypted portion includes an Internet Protocol (IP) header.

[0119] Example 48 is a computer-readable storage medium of Example 38, and the encrypted packet includes an unencrypted portion, and the unencrypted portion includes an Internet Protocol (IP) header and at least one outer extension header.

[0120] Example 49 is a computer-readable storage medium of Example 38, and the computer-executable instructions, when executed, cause the computing device to determine processing information from the unencrypted portion of the encrypted packet, where the unencrypted portion includes at least one of an Internet Protocol (IP) header and at least one outer extension header.

[0121] Example 50 is a computer-readable storage medium of Example 38, and the processing information includes Differentiated Services Code Point (DSCP) information.

[0122] Example 51 is a computer-readable storage medium of Example 38, and the computer-executable instructions, when executed, cause the computing device to classify a partially decrypted packet based on the processing information.

[0123] Example 52 is a computer-readable storage medium of Example 38, and the computer-executable instructions, when executed, cause a computing device to determine whether a partially decrypted packet is a non-conforming packet based on processing information.

[0124] Example 53 is a computer-readable storage medium of Example 38, and the computer-executable instructions, when executed, cause a computing device to determine the priority of a partially decrypted packet based on processing information.

[0125] Example 54 is a computer-readable storage medium of Example 38, and the computer-executable instructions, when executed, cause a computing device to decrypt the remaining part of the partially decrypted packet to generate a decrypted packet.

[0126] Example 55 is a computer-readable storage medium of Example 38, and the computer-executable instructions, when executed, cause a computing device to decrypt the remaining part of the partially decrypted packet to generate a decrypted packet and send the decrypted packet.

[0127] Example 56 is a device for networking, including: a flow control segment determination unit for accessing an encrypted packet having an encrypted part and determining at least one flow control segment of the encrypted part; a partial decryption unit for decrypting the at least one flow control segment to generate a partially decrypted packet, the partially decrypted packet including the decrypted at least one flow control segment and the encrypted remaining part, the remaining part including a part of the encrypted packet that does not include the decrypted at least one flow control segment; and a flow control processing unit for accessing processing information in the decrypted at least one flow control segment and processing the partially decrypted packet according to the processing information.

[0128] Example 57 is the device of Example 56, and the encrypted packet is encrypted according to the Internet Protocol Security (IP Sec) protocol.

[0129] Example 58 is the device of Example 56, and the encrypted packet is encrypted according to the Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol.

[0130] Example 59 is the device of Example 56, and the flow control segment determination unit determines at least one flow control segment based on the type of the encrypted packet.

[0131] Example 60 is the device of Example 56, and the flow control segment determination unit determines at least one flow control segment based on the type of the encrypted packet, and the type includes the communication protocol for the encrypted packet.

[0132] Example 61 is the device of Example 56, and the at least one flow control segment includes a header.

[0133] Example 62 is the device of Example 56, and the at least one flow control segment includes an inner header.

[0134] Example 63 is the apparatus of Example 56, wherein the at least one flow control section includes an encrypted portion of a specified length.

[0135] Example 64 is the apparatus of Example 56, wherein the at least one flow control section includes a specified number of bits of an encrypted portion.

[0136] Example 65 is the apparatus of Example 56, wherein the encrypted packet includes an unencrypted portion, and the unencrypted portion includes an Internet Protocol (IP) header.

[0137] Example 66 is the apparatus of Example 56, wherein the encrypted packet includes an unencrypted portion, and the unencrypted portion includes an Internet Protocol (IP) header and at least one outer extension header.

[0138] Example 67 is the apparatus of Example 56, wherein the flow control processing unit is configured to determine processing information from the unencrypted portion of the encrypted packet, and the unencrypted portion includes at least one of an Internet Protocol (IP) header and at least one outer extension header.

[0139] Example 68 is the apparatus of Example 56, wherein the processing information includes Differentiated Services Code Point (DSCP) information.

[0140] Example 69 is the apparatus of Example 56, wherein the flow control processing unit classifies the partially decrypted packet based on the processing information.

[0141] Example 70 is the apparatus of Example 56, wherein the flow control processing unit determines whether the partially decrypted packet is a non-conforming packet based on the processing information.

[0142] Example 71 is the apparatus of Example 56, wherein the flow control processing unit determines the priority of the partially decrypted packet based on the processing information.

[0143] Example 72 is the apparatus of Example 56, wherein the flow control processing unit decrypts the remaining portion of the partially decrypted packet to generate a decrypted packet.

[0144] Example 73 is the apparatus of Example 56, wherein the flow control processing unit decrypts the remaining portion of the partially decrypted packet to generate a decrypted packet and transmits the decrypted packet.

[0145] Example 74 is a system, comprising the apparatus according to any one of claims 56 - 73, and at least one network interface.

[0146] It should be noted that the methods described herein need not be performed in the order described or in any particular order. Additionally, the various activities described with respect to the methods identified herein can be performed in a serial or parallel manner.

[0147] Although specific embodiments have been illustrated and described herein, it should be understood that any arrangement calculated to achieve the same purpose may be substituted for the specific embodiments shown. The present disclosure is intended to cover any and all adaptations or variations of various embodiments. It should be understood that the above description has been made in an illustrative manner, and not a restrictive one. After reading the above description, combinations of the above embodiments and other embodiments not specifically described herein will be apparent to those skilled in the art. Accordingly, the scope of various embodiments includes any other applications of the above compositions, structures and methods.

[0148] It should be emphasized that the abstract of the disclosure is provided to comply with 37 C.F.R.§1.112(b), which requires an abstract that will allow the reader to quickly ascertain the essence of the technical disclosure. It should be understood that the abstract is not used to interpret or limit the scope or meaning of the claims. Further, in the foregoing detailed description, it can be seen that for the purpose of simplifying the present disclosure, various features are combined in a single embodiment. This method of disclosure should not be interpreted as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as reflected in the following claims, the subject matter of the invention lies in less than all of the features of the disclosed embodiments. Accordingly, the following claims are incorporated into the detailed description, where each claim stands on its own as a separate preferred embodiment. In the appended claims, the terms "including" and "in which" are used as the plain-English equivalents of the respective terms "comprising" and "wherein". Further, the terms "first", "second", "third", etc. are used merely as labels, and are not intended to impose numerical requirements on their objects.

[0149] Although the subject matter has been described in language specific to structural features and / or methodological acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the above specific features and acts are disclosed as example forms of implementing the claims.

Claims

1. An apparatus for flow control packet processing, comprising: at least one memory; logic, at least a portion of which is included in hardware coupled to the at least one memory, the logic for: accessing an encrypted packet having an encrypted portion, determining at least one flow control segment of the encrypted portion based at least in part on at least one of: the type of the encrypted packet, the encrypted portion of a specified length, an unencrypted portion included in the encrypted packet, decrypting the at least one flow control segment to generate a partially decrypted packet, the partially decrypted packet including the decrypted at least one flow control segment and the remaining encrypted portion, the remaining portion including the portion of the encrypted packet that does not include the decrypted at least one flow control segment, accessing processing information in the decrypted at least one flow control segment, and processing the partially decrypted packet according to the processing information.

2. The apparatus according to claim 1, wherein the encrypted packet is encrypted according to the Internet Protocol Security (IPSec) protocol.

3. The apparatus according to claim 1, wherein the encrypted packet is encrypted according to the Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol.

4. The apparatus according to claim 1, wherein the at least one flow control segment includes a header.

5. The apparatus according to claim 1, wherein the at least one flow control segment includes an inner header.

6. The apparatus according to any one of claims 1 to 5, wherein the unencrypted portion includes an Internet Protocol (IP) header and at least one outer extension header.

7. The apparatus according to any one of claims 1 to 5, wherein the processing information includes Differentiated Services Code Point (DSCP) information.

8. The apparatus according to any one of claims 1 to 5, wherein the logic is for classifying the partially decrypted packet based on the processing information.

9. The apparatus according to any one of claims 1 to 5, wherein the logic is for determining whether the partially decrypted packet is a non-conforming packet based on the processing information.

10. The apparatus according to any one of claims 1 to 5, wherein the logic is for determining the priority of the partially decrypted packet based on the processing information.

11. The apparatus according to any one of claims 1 to 5, wherein the logic for: decrypting the remaining portion of the partially decrypted packet to generate a decrypted packet, and transmitting the decrypted packet.

12. A method for flow control packet processing, comprising: accessing an encrypted packet having an encrypted portion, determining at least one flow control segment of the encrypted portion based at least in part on at least one of: the type of the encrypted packet, the encrypted portion of a specified length, an unencrypted portion included in the encrypted packet, decrypting the at least one flow control segment to generate a partially decrypted packet, the partially decrypted packet including the decrypted at least one flow control segment and the remaining encrypted portion, the remaining portion including the portion of the encrypted packet that does not include the decrypted at least one flow control segment, Access the processing information in the at least one decrypted flow control section, and Process the partially decrypted packet according to the processing information.

13. The method according to claim 12, wherein the encrypted packet is encrypted according to the Internet Protocol Security (IPSec) protocol.

14. The method according to claim 12, wherein the encrypted packet is encrypted according to the Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol.

15. The method according to claim 12, wherein the at least one flow control section includes a header.

16. The method according to claim 12, wherein the at least one flow control section includes an inner header.

17. The method according to any one of claims 12 to 16, wherein the unencrypted portion includes an Internet Protocol (IP) header and at least one outer extension header.

18. The method according to any one of claims 12 to 16, wherein the processing information includes Differentiated Services Code Point (DSCP) information.

19. The method according to any one of claims 12 to 16, including classifying the partially decrypted packet based on the processing information.

20. The method according to any one of claims 12 to 16, including determining whether the partially decrypted packet is a non-conforming packet based on the processing information.

21. The method according to any one of claims 12 to 16, including determining the priority of the partially decrypted packet based on the processing information.

22. A non-transitory computer-readable storage medium storing instructions that, when run by a computing device, enable the computing device to perform the method according to any one of claims 12 - 21.

23. A computer program product storing a computer program that, when executed by a processor, causes the processor to perform the method according to any one of claims 12 - 21.

Citation Information

Patent Citations

  • Transport relay in communications network

    WO2017148509A1