Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Middlebox" patented technology

A middlebox or network appliance is a computer networking device that transforms, inspects, filters, or otherwise manipulates traffic for purposes other than packet forwarding. Common examples of middleboxes include firewalls, which filter unwanted or malicious traffic, and network address translators, which modify packets' source and destination addresses. Dedicated middlebox hardware is widely deployed in enterprise networks to improve network security and performance, however, even home network routers often have integrated firewall, NAT, or other middlebox functionality. The widespread deployment of middleboxes and other network appliances has resulted in some challenges and criticism due to poor interaction with higher layer protocols.

Middlebox visibility for post quantum KEM

Some embodiments are directed to a communication system comprising a one or more clients, a server and a middlebox. The middlebox may access to the multiple short-term server private keys of the server. The middlebox may recover a shared key that is negotiated between server and client by decapsulating encapsulation data using a stored client public key and a server private key from the key storage.
Owner:KONINKLIJKE PHILIPS NV

Distributed unit architecture for performing handover between distributed units in a VRAN

The present disclosure relates to systems, methods, and computer-readable media for increasing resiliency in distributed units of a virtual radio access network (vRAN) of a telecommunications network (e.g., a 5G telecommunications network), particularly when performing a planned handover operation between the distributed units. The examples described herein specifically relate to implementing an inter-distributed unit handover between distributed units that are serviced by the same radio unit. In some examples, this handover is initiated by a middlebox entity that is positioned between the distributed units and a centralized unit. In some instances, features of the middlebox entity are implemented within the framework of a centralized unit. By allowing a quick handover as described herein, the distributed units can provide uninterrupted service to a UE while allowing the distributed units to perform various upgrades or modifications to the distributed unit without service interruptions.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Method for identifying and managing QUIC connections for middleboxes

Techniques are described for managing QUIC connections. The techniques include identifying a first QUIC connection between a first and second device. Determining, from the connection, a first IP address and port number of the first device, a second IP address and port number of the second device, and a first CID. Storing an association between the first and second IP addresses, port numbers and first CID. Identifying a second QUIC connection between the first device and another device. Identifying, from the second connection, the first IP address and port number, a second CID, and a third IP address and port number. Determining if two of the following are met: the second IP address corresponds to the third IP address, the second port number corresponds to the third port number, the second CID corresponds to the first CID, if two are met, the first and second QUIC connections are the same.
Owner:CISCO TECHNOLOGY INC

Employing a middlebox to provide connectivity features for a radio access network

This document relates to techniques for providing connectivity features in a radio access network. For instance, the disclosed techniques can employ a middlebox to process fronthaul traffic relating to communications between distributed units and radio units of a radio access network. The processing can provide various connectivity features, such a distributed antenna system connectivity feature, a distributed multiple-input and multiple-output connectivity feature, and / or a radio unit sharing feature that involves sharing of a particular radio unit among two or more distributed units. The processing can also provide an application programming interface for accessing scheduling information, signal quality measurements, buffer status, random access attempts, and / or network load relating to the fronthaul traffic.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Autotuning optimal keepalive intervals for secure sessions

ActiveUS12375448B2Securing communicationKeepaliveNetwork on
Techniques for auto tuning keepalive packets intervals to an optimal interval are described. A remote secure session between a client device and a server over a network is established. A determination is made to identify an optimal keepalive interval for sending packets to keep the remote secure session alive over the network, the optimal keepalive interval defining an amount of time between sending of packets that keep a connection open through middleboxes in the network. Keepalive test probes are transmitted by the client device and to the server at different time intervals. An optimal keepalive interval is determined based at least in part on the keepalive test probes transmitted at the different intervals. The client device transmits information indicating the optimal keepalive interval to the server. Finally, the client device transmits keepalive packets according to the optimal keepalive interval.
Owner:CISCO TECHNOLOGY INC

Middlebox security in a wireless network

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a network entity may receive, from a security service device, a middlebox security policy, wherein the middlebox security policy is associated with a user equipment (UE) and a service device, and wherein the middlebox security policy indicates a set of authorization policies relating to one or more of the UE or the service device. The network entity may receive a communication on a communication link between the UE and the service device. The network entity may transmit the communication in accordance with the middlebox security policy. Numerous other aspects are described.
Owner:QUALCOMM INC

Vehicle-mounted terminal trusted data generation and signature gating method and device and storage medium

The invention discloses a vehicle-mounted data credible generation method and device and a storage medium. And the vehicle-mounted terminal collects power supply voltage in the time window and generates physical side characteristics, collects vehicle bus data to generate logic side characteristics and performs time alignment, and calculates consistency measurement to obtain a judgment result. Generating an abstract from the data block to be reported according to the normalized code, and binding the abstract with the window identifier, the monotonic counter reference information and the measurement rule version identifier; when it is judged that a preset condition is met, a security component (security unit / trusted execution environment) executes a signature or an authentication code on the abstract to generate a state verification voucher; and if not, outputting a failure reason code and optionally generating an abnormal audit voucher capable of being verified. In some embodiments, a lightweight digital twinning model or predictive model is executed within a security component, physical / logical side observability measurements at the next moment are predicted based on load-related characteristics, and gating is performed on predicted residuals to identify smart simulator attacks. According to the scheme, playback, injection and middle box playback are inhibited, and the authenticity and proof performance of the afterloading OBD scene data are improved.
Owner:郝彦博

Migrating virtual machines while performing middlebox service operations at a PNIC

Some embodiments provide a novel method for migrating virtual machines (VMs) from a first host computer to a second host computer. The first host computer is connected to a physical network interface card (PNIC) that performs middlebox service operations for flows associated with the VMs. At the PNIC, the method receives a notification that a VM is to be migrated from the first to the second host computer. The method configures an embedded hardware switch of the PNIC to forward a set of flows associated with the VM to a firewall of the PNIC. The embedded hardware switch was initially programmed to process the set of flows instead of the firewall. The method synchronizes flow cache information regarding the set of flows from the embedded hardware switch to the firewall. The method processes the set of flows at the firewall until the VM is migrated to the second host computer.
Owner:VMWARE INC

Hybrid post-quantum TLS migration with binder-enforced resumption

A system and method for secure transport resumption during post-quantum migration. A server negotiates a handshake and issues a session ticket embedding scope metadata that identifies a key-exchange class (e.g., hybrid post-quantum and classical, or classical), and may include a schema version, service-identity scope, policy flags, a rollout epoch, and a site identifier. On a subsequent connection the client presents the ticket with a resumption binder. The server selects an expected binder class from the scope metadata, verifies the binder using a pre-shared key derived for the selected class, and accepts or refuses resumption accordingly. Binding resumption to the negotiated class mitigates cross-class replay and downgrade while remaining compatible with classical endpoints and middleboxes. Optional embodiments include certificate-transparency enforcement via policy flags, point-of-presence scoping, epoch-based rollout and rollback, and hardware-security-module-gated key activation with quorum approval and attestation. The approach enables black-box verifiability and incremental, standards-conformant deployment.
Owner:VON LIECHTENSTEIN MAXIMILIAN RALPH PETER

Facilitating distributed SNAT service

PendingUS20250233843A1Network connectionsDistributed sourceNetwork on
Some embodiments of the invention provide novel methods for facilitating a distributed SNAT (dSNAT) middlebox service operation for a first network at a host computer in the first network on which the dSNAT middlebox service operation is performed and a gateway device between the first network and a second network. The novel methods enable dSNAT that provides stateful SNAT at multiple host computers, thus avoiding the bottleneck problem associated with providing stateful SNAT at gateways and also significantly reduces the need to redirect packets received at the wrong host by using a capacity of off-the-shelf gateway devices to perform 1Pv6 encapsulation for 1Pv4 packets and assigning locally unique 1Pv6 addresses to each host executing a dSNAT middlebox service instance that are used by the gateway device.
Owner:VMWARE INC

A 5G service cell handover information opening method and device based on edge computing

The present invention provides a method and apparatus for opening 5G service cell handover information based on edge computing, which offloads the sensing task of the user equipment to switch base stations to an edge server, multiplexes the data packet header of the user equipment to the application server based on RawSocket, enables the reserved bit to indicate the handover event by using the same data packet header as the general data packet, directly opens the sensing result to the application server, can be sensed by both the network transport layer and the application layer at the same time, realizes a low-overhead network information reporting mechanism based on the middle box and cross-layer information sharing, and enables the application server transport layer and the application layer to quickly react to the user equipment switching base stations.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Middlebox security in a wireless network

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a network entity may receive, from a security service device, a middlebox security policy, wherein the middlebox security policy is associated with a user equipment (UE) and a service device, and wherein the middlebox security policy indicates a set of authorization policies relating to one or more of the UE or the service device. The network entity may receive a communication on a communication link between the UE and the service device. The network entity may transmit the communication in accordance with the middlebox security policy. Numerous other aspects are described.
Owner:QUALCOMM INC

Virtual machine (VM) migration with smart network interface cards (NICs)

Some embodiments provide a novel method of migrating a particular virtual machine (VM) from a first host computer to a second host computer. The first host computer of some embodiments has a physical network interface card (PNIC) that performs at least one of network forwarding operations and middlebox service operations for the particular VM. The first host computer sends, to the PNIC of the first host computer, a request for state information relating to at least one of network forwarding operations and middlebox service operations that the PNIC performs for the particular VM. The first host computer receives the state information from the PNIC. The first host computer provides the state information received from the PNIC to the second host computer as part of a data migration that is performed to migrate the particular VM from the first host computer to the second host computer.
Owner:VMWARE INC

Live workload migration for hardware offload capable NICs using RDMA

Some embodiments of the invention provide a method of migrating a virtual machine (VM) from a first host computer to a second host computer, the first host computer having a first PNIC, the second host computer having a second PNIC, the first and second PNICs for performing at least one of network forwarding operations and middlebox service operations for the VM. At an RDMA client executing on a set of one or more processors of the second PNIC, the method receives a notification from the second host computer indicating a data migration that is performed to migrate the particular VM from the first host computer to the second host computer has started. Based on the notification, at the RDMA client, the method directs an RDMA server executing on the first PNIC to provide networking state data associated with at least one of network forwarding operations and middlebox service operations that the first PNIC performs for the VM. The provided networking state data resides in a memory of the first PNIC that is accessible to the RDMA server.
Owner:VMWARE INC

Middlebox security in a wireless network

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a network entity may receive, from a security service device, a middlebox security policy, wherein the middlebox security policy is associated with a user equipment (UE) and a service device, and wherein the middlebox security policy indicates a set of authorization policies relating to one or more of the UE or the service device. The network entity may receive a communication on a communication link between the UE and the service device. The network entity may transmit the communication in accordance with the middlebox security policy. Numerous other aspects are described.
Owner:QUALCOMM INC

Facilitating distributed snat services

ActiveCN116158064BTransmissionOff the shelfNetwork on
Some embodiments of the invention provide novel methods for facilitating distributed SNAT (dSNAT) middlebox service operations of a first network at a host computer in the first network and at a gateway device between the first network and a second network on which middlebox service operations are performed. The novel methods enable dSNAT of stateful middlebox services to be provided at multiple host computers, thus avoiding the bottleneck problem associated with providing stateful middlebox services at gateways, and also significantly reduce the need for redirection of packets received at the wrong host by using the capabilities of off-the-shelf gateway devices to perform IPv6 encapsulation of IPv4 packets and assign locally unique IPv6 addresses to each host executing a dSNAT middlebox service instance used by the performing gateway device.
Owner:VMWARE INC

Receiver-side scalable congestion control

A middlebox is inserted downstream from a bottleneck and a marking node is inserted upstream from the bottleneck. When a non-TCP message is received at the middlebox, the middlebox sends a message to the marking node to mark messages being downloaded as enabled for a particular protocol and marked to reflect an expedited forwarding (e.g., DCSP 45). When a node having the bottleneck receives the message having the ECT(1) marking, if there is congestion, the ECT(1) marking is changed to Congestion Experienced (CE). The middlebox reacts to the marking by controlling the sender to follow a scalable congestion controller response curve achieved by (1) NonTCP QB flows are controlled by delaying acknowledgments and selectively dropping messages and (2) TCP flows are controlled by overwriting the receive window in acknowledgments. Alternatively, TCP flows where the server supports L4S can be controlled by echoing congestion via ‘Accurate ECN’.
Owner:NETDUMA SOFTWARE LTD

Providing modular network services through distributed elastic middleboxes

A distributed platform is provided for developing and deploying complex, resilient, highly available, multi-tenant network services. The network service system includes an in-network key / value store that implements a distributed flow table (DFT), the DFT including nodes organized into a chain. Each node in the chain includes a modular middlebox that is linked to at least one other modular middlebox in the chain to implement network service functions for data packets based on a specification table to generate flow table entries. The DFT scales horizontally and maintains consistent connection state between replicas. A stateless forwarding layer performs data packet forwarding decisions for established connections and bounces data packets for transmission. A management node converts network services described in a declarative programming language into the specification table for distribution to the modular middleboxes in the nodes of the DFT.
Owner:HUAWEI TECH CO LTD

A service-aware based NFV network routing method and device

PendingCN122372496ALoad assessment is close to realityReduce the impact of solvingPathPingEngineering
This invention discloses a service-aware NFV network routing method and apparatus, belonging to the field of communication network and network function virtualization technology. After acquiring network topology, link load / bandwidth, node intermediate box processing capacity and space resources, and flow request information, the method determines the dependencies of required intermediate boxes and configures a traffic change rate ratio for each intermediate box type. Under the constraint of dependency, the partial-order service set is converted into a full-order service chain based on the ratio. Then, based on the full-order service chain, the shortest path calculation is performed in stages to jointly determine the routing path and intermediate box service location. When the processing capacity of existing instances is insufficient, new instances are started based on the remaining space. Finally, the SDN controller issues flow tables to realize forwarding. This invention can effectively reduce end-to-end latency and packet loss rate, improve flow success rate, and achieve network load balancing.
Owner:ZHEJIANG GONGSHANG UNIVERSITY