Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5 results about "Middlebox" patented technology

A middlebox or network appliance is a computer networking device that transforms, inspects, filters, or otherwise manipulates traffic for purposes other than packet forwarding. Common examples of middleboxes include firewalls, which filter unwanted or malicious traffic, and network address translators, which modify packets' source and destination addresses. Dedicated middlebox hardware is widely deployed in enterprise networks to improve network security and performance, however, even home network routers often have integrated firewall, NAT, or other middlebox functionality. The widespread deployment of middleboxes and other network appliances has resulted in some challenges and criticism due to poor interaction with higher layer protocols.

Middlebox security in a wireless network

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a network entity may receive, from a security service device, a middlebox security policy, wherein the middlebox security policy is associated with a user equipment (UE) and a service device, and wherein the middlebox security policy indicates a set of authorization policies relating to one or more of the UE or the service device. The network entity may receive a communication on a communication link between the UE and the service device. The network entity may transmit the communication in accordance with the middlebox security policy. Numerous other aspects are described.
Owner:QUALCOMM INC

Virtual machine (VM) migration with smart network interface cards (NICs)

Some embodiments provide a novel method of migrating a particular virtual machine (VM) from a first host computer to a second host computer. The first host computer of some embodiments has a physical network interface card (PNIC) that performs at least one of network forwarding operations and middlebox service operations for the particular VM. The first host computer sends, to the PNIC of the first host computer, a request for state information relating to at least one of network forwarding operations and middlebox service operations that the PNIC performs for the particular VM. The first host computer receives the state information from the PNIC. The first host computer provides the state information received from the PNIC to the second host computer as part of a data migration that is performed to migrate the particular VM from the first host computer to the second host computer.
Owner:VMWARE INC

Facilitating distributed snat services

ActiveCN116158064BTransmissionOff the shelfNetwork on
Some embodiments of the invention provide novel methods for facilitating distributed SNAT (dSNAT) middlebox service operations of a first network at a host computer in the first network and at a gateway device between the first network and a second network on which middlebox service operations are performed. The novel methods enable dSNAT of stateful middlebox services to be provided at multiple host computers, thus avoiding the bottleneck problem associated with providing stateful middlebox services at gateways, and also significantly reduce the need for redirection of packets received at the wrong host by using the capabilities of off-the-shelf gateway devices to perform IPv6 encapsulation of IPv4 packets and assign locally unique IPv6 addresses to each host executing a dSNAT middlebox service instance used by the performing gateway device.
Owner:VMWARE INC

A service-aware based NFV network routing method and device

PendingCN122372496ALoad assessment is close to realityReduce the impact of solvingPathPingEngineering
This invention discloses a service-aware NFV network routing method and apparatus, belonging to the field of communication network and network function virtualization technology. After acquiring network topology, link load / bandwidth, node intermediate box processing capacity and space resources, and flow request information, the method determines the dependencies of required intermediate boxes and configures a traffic change rate ratio for each intermediate box type. Under the constraint of dependency, the partial-order service set is converted into a full-order service chain based on the ratio. Then, based on the full-order service chain, the shortest path calculation is performed in stages to jointly determine the routing path and intermediate box service location. When the processing capacity of existing instances is insufficient, new instances are started based on the remaining space. Finally, the SDN controller issues flow tables to realize forwarding. This invention can effectively reduce end-to-end latency and packet loss rate, improve flow success rate, and achieve network load balancing.
Owner:ZHEJIANG GONGSHANG UNIVERSITY