Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

51 results about "Network virtualization" patented technology

In computing, network virtualization or network virtualisation is the process of combining hardware and software network resources and network functionality into a single, software-based administrative entity, a virtual network. Network virtualization involves platform virtualization, often combined with resource virtualization.

Server hybrid deployment and management system based on virtualization technology

The invention relates to the technical field of computer server resource management and network virtualization, and particularly discloses a server hybrid deployment and management system based on a virtualization technology, which comprises a uniform resource abstraction layer, a global resource sensing and modeling unit, a strategy-driven intelligent arrangement engine and a heterogeneous resource execution adapter. The uniform resource abstraction layer performs standardized abstraction on a physical server, a virtual machine and a container; the global resource sensing and modeling unit integrates the resource data and constructs a global resource model; a strategy-driven intelligent arrangement engine performs multi-objective optimization solution based on strategies and constraints to generate a scheduling scheme; the heterogeneous resource execution adapter translates the scheme into bottom executable atomic operations. According to the invention, unified management and intelligent cooperative scheduling of heterogeneous computing resources are realized, and the resource utilization efficiency and the system automation level are improved.
Owner:SHANGHAI PUSAI INTELLIGENT TECHNOLOGY CO LTD

Multi-modal network dynamic loading and management system and method based on modal virtualization

The invention relates to a multi-modal network dynamic loading and management system and method based on modal virtualization, and belongs to the technical field of network system structures and virtualization. By constructing a modal virtualization layer and a modal description language analysis mechanism, the limitation that traditional network virtualization is only oriented to a single protocol stack is broken through, unified packaging and isolation of multiple network modalities such as IP, TSN, ICN and custom protocols are achieved, the dual-modal state snapshot and traffic mirroring technology is utilized, and the network modality is improved. The problem of service interruption in the online switching process of the network modes is solved; and further in combination with a vectorized heterogeneous resource elastic scheduling model, global optimal configuration and on-demand mapping of the CPU, the GPU, the FPGA and the P4 programmable switching chip are realized.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

Multi-segment SD-WAN through cloud DC transit nodes

A method implemented by a first cloud gateway (GW). The method includes receiving, from a first customer premises edge device (CPE) over a software defined wide area network (SD-WAN) path, a data packet including an outer layer internet protocol (IP) header and a generic network virtualization encapsulation (GENEVE) header. The GENEVE header includes one or more sub-type length values (TLVs). The method also includes extracting a destination address from the one or more sub TLVs within the GENEVE header. And the method further comprises the steps of updating the destination IP address in the outer-layer IP header to the extracted destination address, and forwarding the data packet to a second CPE according to the updated destination IP address.
Owner:HUAWEI TECH CO LTD

Techniques for processing network flows

Improved network traffic flow processing techniques are described. In a network device providing multiple processing planes, each processing plane comprising multiple processing units, techniques are described that take advantage of flow affinity / locality principles such that the same processing component of a processing plane, which previously performed processing for a network flow, is used for performing subsequent processing for the same network flow. This enables faster processing of network traffic flows by the network device. In certain implementations, the techniques described herein can be implemented in a network virtualization device (NVD) that is configured to perform network virtualization functions.
Owner:ORACLE INT CORP

Layer-2 networking storm control in a virtualized cloud environment

Techniques are described for communications in an L2 virtual network. In an example, the L2 virtual network includes a plurality of L2 compute instances hosted on a set of host machines and a plurality of L2 virtual network interfaces and L2 virtual switches hosted on a set of network virtualization devices. An L2 virtual network interface emulates an L2 port of the L2 virtual network. Storm control information applicable to the L2 port is sent to a network virtualization device that hosts the L2 virtual network interface.
Owner:ORACLE INT CORP

Network virtualization for remotely controlling robotic-assisted medical procedures

Disclosed systems, apparatuses, and methods enable remotely controlling robotic-assisted medical systems, such as robotic-assisted surgery systems, for performing remote robotic-assisted medical procedures. Disclosed approaches provide a secure, efficient, and dynamically-created virtual network for connecting physician consoles and robotic-assisted medical systems. Disclosed approaches improve efficiency, security, scalability, and reliability of remote robotic-assisted medical procedures.
Owner:SOVATO HEALTH INC

End-to-end network encryption from a customer on-premises network to a customer virtual cloud network using customer managed keys

Systems and methods for encrypting data between a customer and a virtual cloud network (VCN) for end-to-end encryption, where the customer manages the encryption keys.SOLUTION: The network head end device, VCN Head End 704, accepts the first key provisioned by the customer, receives the first data packet sent from the customer's device, and decrypts the first data packet using the first key to obtain the information. The network virtualization device 624 receives the information from the network head-end device, confirms that the information is to be sent to the virtual machine in the virtual cloud network, confirms that data in the virtual cloud network is to be encrypted, encrypts the information using the second key to generate a second data packet, and routes the second data packet to the virtual machine in the virtual cloud network 312.SELECTED DRAWING: Figure 7
Owner:ORACLE INT CORP

An intelligent network card, cloud server and traffic forwarding method

The application discloses an intelligent network card, a cloud server and a traffic forwarding method. The intelligent network card comprises a network virtualization component and a physical network card, a symmetric hash module and a plurality of groups of data flow forwarding queues connected with the symmetric hash module; a plurality of software CPUs are arranged on the network virtualization component; the data flow forwarding queues are arranged to correspond to unique software CPUs; the symmetric hash module is used for being connected with the physical network card and a virtual machine in communication respectively, performing symmetric hash operation on five-tuple information of a forward data flow sent by the virtual machine and five-tuple information of a reverse data flow sent by the physical network card respectively, sending the forward and reverse data flows belonging to a same session to data flow forwarding queues corresponding to operation results, and enabling the forward and reverse data flows belonging to the same session to be forwarded by software CPUs corresponding to the data flow forwarding queues. The application removes session cross-CPU lock overhead and core-to-core communication overhead, and greatly improves new connection performance.
Owner:ALIBABA (CHINA) CO LTD

Network virtualization resource management method and system

The invention discloses a network virtualization resource management method and system, and relates to the technical field of intelligent resource management, and the method comprises the steps: initializing an AoL virtual queue, dynamically updating the queue through a Lyapunov drift method, dividing scene feature groups in combination with an ODSS algorithm, fusing prediction results of multiple models, correcting deviation through a Lyapunov-ODSS objective function, and refining the prediction results according to priorities. And an OPT-JR multi-objective function is defined, and an optimal resource allocation vector is solved by using an NSGA-II algorithm. According to the method, the Lyapunov drift theory is introduced to carry out resource regulation and control, the ODSS feature screening algorithm is combined to carry out feature selection, the robustness and real-time performance of resource management are improved, multiple models are fused to carry out collaborative prediction, the precision and stability of resource demand prediction are improved, and the utilization efficiency and intelligent scheduling of resources in a virtualized network are realized.
Owner:HENAN INFORMATION CONSULTATION DESIGN & RES

A three-site mutual backup method under a commercial secret network virtualization architecture

PendingCN122340118AComplete dataStation
This invention relates to a three-site mutual backup method under a commercial encrypted network virtualization architecture, belonging to the field of network communication technology. It addresses the technical problems of existing cross-regional and cross-network segment communication schemes, including insufficient interconnection security, adaptability, data backup efficiency, fault switching response speed, hardware architecture cost-effectiveness, and incomplete scenario coverage. The method includes the following steps: master station backup generation; parallel off-site replication; breakpoint resumption and anomaly recovery; local storage and version retention at branch stations; fault switching and local recovery. The three-site mutual backup method under the commercial encrypted network virtualization architecture of this invention offers: superior interconnection security and adaptability, more efficient and complete data backup, low-impact automated fault switching, a more reasonable and cost-controllable hardware architecture, higher detection accuracy, and stronger scalability.
Owner:CHANGCHUN INST OF OPTICS FINE MECHANICS & PHYSICS CHINESE ACAD OF SCI

Link-level network virtualization architecture for large-scale network function virtualization applications

A virtualized network function (VNF) of a network function virtualization (NFV) link level architecture includes a management plane function (MPF) to map a logical interface as a virtual interface in a control plane function (CPF) of the VNF. The MPF maps a logical resource of the NFV virtualization link level architecture as a shadow resource on one or more data plane functions (DPFs) of the VNF, wherein a virtual link is formed by the logical interface, the shadow resource, and the virtual interface. One of the DPFs receives a packet over the virtual link from a switch and classifies a type of the packet. In response to the packet type being a data packet, the DPF aggregates the packet with other data packets to form aggregated data packets and sends the aggregated data packets to the switch.
Owner:FORTINET INC

A mechanism for providing customer VCN network encryption using customer-managed keys in network virtualization devices.

ActiveJP7860999B2
To allow a customer to control network keys in a virtual cloud network, a network interface card such as a smart NIC is used to provide encryption such as a network encryption virtual function (NEVF) for virtual machines. The NEVF includes a memory device (e.g., SRAM) and a crypto processor (e.g., a crypto core). The memory device stores an encryption key. The crypto processor encrypts data to and from the virtual machines in the virtual cloud network using the encryption key. A key management service can be used to securely transfer the encryption key to the NEVF. Having one NEVF per virtual machine can allow a customer to manage encryption keys for the virtual cloud network.
Owner:ORACLE INT CORP

Dynamic IP routing in a cloud environment

The present disclosure provides dynamic routing for data flows to a customer network hosted in the cloud. A plurality of compute instances may share a common virtual IP address. Each of the plurality of compute instances may advertise information to a respective network virtualization device (NVD). The information may include the IP address, cost, and / or active / standby status of the compute instance. The NVD may then provide the information to the control plane of a virtual cloud network (VCN), which may aggregate the information from the plurality of compute instances and generate a forwarding table, which may be sent to the NVDs. These techniques may allow a customer to automatically remove a compute instance whose service host has failed. These techniques may also allow a customer to add compute instances and to route data flows according to an active-standby operation, an equal cost active-active operation, or an unequal cost active-active operation.
Owner:ORACLE INT CORP

Device, method and system for virtualizing a network

To provide a network device, method and system for virtualizing a network.SOLUTION: A network device 500 comprises a physical transceiver port for transferring data at a predetermined fixed data rate and a virtual circuit, wherein the virtual circuit receives a request to transfer an incoming data stream at a non-predetermined data rate and establishes a virtual port. The virtual port includes a FIFO buffer that operates as a token bucket that is periodically filled with tokens and emptied when full, selects from the physical transceiver ports a physical transceiver port having a total predetermined fixed data rate that is higher than the non-predetermined data rate, and when the token bucket of the virtual port is full, forwards the output data stream to the selected physical transceiver port to forward all tokens from the token bucket to the physical transceiver port at the predetermined fixed data rate.SELECTED DRAWING: Figure 5
Owner:PRIMEWAN LTD

Auto-healing control in consideration of type of network problem

A network management apparatus includes at least one processor. The processor is configured to execute a reception process of receiving a signal supplied when a problem is detected in any of a plurality of logical networks in a network virtualization environment, and a first determination process of determining not to perform auto-healing in a case in which a problem is detected in a first logical network that is configured for platform monitoring and a problem is not detected in a second logical network that is configured for application monitoring.
Owner:RAKUTEN MOBILE INC

Ad hoc network simulation method based on network virtualization

The invention discloses an ad hoc network simulation method based on network virtualization, belongs to the technical field of computer communication, and aims to solve the problems of insufficient compatibility, inflexible link control and weak topology time-varying simulation capability of traditional ad hoc network simulation. The core of the system is that a simulation architecture comprising a simulation configuration module, a service application module, a communication node module, an analog channel module and a data acquisition module is constructed, service application and a real equipment protocol stack are packaged through a container virtualization technology, and a real product and an upper-layer service application software protocol are supported to be directly deployed without transplantation. The system is compatible with a two-layer Ethernet and a three-layer IP protocol, integrates a communication link electromagnetic propagation model, is combined with OpenvSwitch and TC tools, is matched with a software defined network technology to control link quality and network topology time-varying characteristics, is adaptive to static and dynamic topology scenes, improves simulation authenticity and flexibility, and provides reliable support for ad hoc network testing.
Owner:THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION

Approval automation for change in network virtualization environment

A processor acquires a current change request of a network virtualization environment, and automatically rejects the current change request if a determination criterion that satisfies a value of a comparison item in the current change request is not detected in a determination criterion management database. If the determination criterion that satisfies the value of the comparison item is detected, the processor searches for a past change record that satisfies the determination criterion (execution result of the past change of the same type). If the execution result of the past change is not detected, the processor automatically rejects the current change request. If the execution result of the past change is detected, the processor automatically approves the current change request when a predetermined condition related to the execution result of the past change is satisfied, but automatically rejects the current change request when the predetermined condition is not satisfied.
Owner:RAKUTEN MOBILE INC

Multi-segments sd-wan via cloud dcs transit nodes

A method implemented by a first cloud gateway (GW). The method includes receiving, from a first customer premises edge (CPE) on a Software-Defined Wide Area Network (SD-WAN) path, a packet comprising an outer Internet Protocol (IP) header and a generic network virtualization encapsulation (GENEVE) header. The GENEVE header includes one or more sub-type length values (TLVs). The method further includes extracting a destination address from the one or more sub-TLVs within the GENEVE header. The method also includes updating a destination IP address in the outer IP header with the extracted destination address and forwarding the packet to the second CPE based on the updated IP destination address.
Owner:HUAWEI TECH CO LTD

Wideband and narrowband converged communication system and method based on 5G and PDT

The invention provides a wide-narrow band converged communication system and method based on 5G and PDT, and relates to the technical field of network virtualization communication. Wide-narrow band communication situation awareness is executed through a wide-narrow band communication situation awareness module; performing communication network signaling bearer determination and communication network service interruption evaluation in sequence to obtain a corresponding service interruption evaluation result; the broadband and narrowband converged communication coordination module is used for executing broadband and narrowband communication network coordination based on the service interruption evaluation result after the broadband and narrowband communication situation awareness module obtains the service interruption evaluation result so as to obtain a communication network coordination result; and the broadband-narrowband communication effect analysis module is used for executing broadband-narrowband communication effect analysis based on the communication network cooperation result after the broadband-narrowband converged communication cooperation module obtains the communication network cooperation result and judging whether a broadband-narrowband communication effect qualification prompt is sent to a preset person or not, and finally the overall broadband-narrowband communication effect is poor.
Owner:ZHONGRUI COMM PLANNING & DESIGN

Security protection system and method for container cloud RDMA network

A safety protection system of a container cloud RDMA network comprises a host machine and a global GID manager, and the host machine distributes a VF virtual function interface for each RDMA container newly applied and created; the virtual GID is configured on a VF virtual function interface, the physical GID is configured on a host machine, and the physical GID is used for actual network transmission; and when communication is established between the containers, the global GID manager maps the virtual GIDs of the containers to physical GIDs, and sends data packets transmitted between the containers to a physical network card on a host machine for transmission. RDMA network virtualization is completed through a virtual and physical double global identifier strategy, virtual network information of tenants is configured on virtual functions of physical network cards of the tenants, so that the tenants can transparently use standard RDMA interfaces to access physical network card resources, the high-performance advantage of RDMA is kept, and the service life of the tenants is prolonged. And necessary network isolation and security protection capabilities are realized.
Owner:HUNAN UNIV

Layer-2 networking using access control lists in a virtualized cloud environment

Techniques are described for communications in an L2 virtual network. In an example, the L2 virtual network includes a plurality of L2 compute instances hosted on a set of host machines and a plurality of L2 virtual network interfaces and L2 virtual switches hosted on a set of network virtualization devices. An L2 virtual network interface emulates an L2 port of the L2 virtual network. Access control list (ACL) information applicable to the L2 port is sent to a network virtualization device that hosts the L2 virtual network interface.
Owner:ORACLE INT CORP

Group-based policy encoding for network virtualization overlays

ActiveUS12592882B2Networks interconnectionMultiprotocol Label SwitchingPrivate network
A first network device of a first data center may encode a source tenant system interface (TSI) group identifier into a tag protocol identifier and a group-based policy identifier, and may encode the tag protocol identifier and the group-based policy identifier into a virtual extensible local area network (VXLAN) packet with the source TSI group identifier, where the source TSI group identifier is not included in a header of the VXLAN packet. The first network device may provide the VXLAN packet, with the source TSI group identifier, to a second network device of a second data center, via an Ethernet virtual private network (EVPN) multiprotocol label switching (MPLS) network.
Owner:JUNIPER NETWORKS INC

Predictive policy enforcement using encapsulated metadata

Methods are provided for predictive policy enforcement using encapsulated metadata. The methods involve obtaining a packet of an encapsulated traffic flow that is transported in a software-defined wide area network (SD-WAN) or in a cloud network. The packet includes a network virtualization tunneling header with an appended service plane protocol header and a payload. The methods further involve extracting, from the appended service plane protocol header, without performing deep packet inspection, enriched metadata that includes fields for one or more attributes related to a source of the packet or a destination of the packet, determining at least one network policy based on the enriched metadata, and applying, to the packet, the at least one network policy that relates to gathering analytics and / or transporting the encapsulated traffic flow to the destination.
Owner:CISCO TECHNOLOGY INC

Distributed edge computer room computing power integration method and system based on DPU

ActiveCN121957830AEfficient training processImprove training efficiencyProgram initiation/switchingResource allocationResource poolResource virtualization
The invention provides a distributed edge machine room computing power integration method and system based on a DPU, and relates to the field of processors, and the method comprises the steps: transmitting parameter copy management data and consistency control function data to a DPU layer corresponding to a DPU card deployed in an edge machine room, and obtaining a target DPU layer; constructing a hardware hierarchical communication topology combining aggregation in the machine room and cross-machine room controlled transmission in the target DPU layer to obtain a target DPU, and executing bandwidth sensing, QoS scheduling, cross-machine room parameter coordination and traffic shaping control through the target DPU; the gradient processing and parameter synchronous control logic data corresponding to the edge machine room are transmitted to a target DPU, and hardware-level unloading and cross-machine-room intelligent scheduling are carried out through the target DPU; gPU resource virtualization and network virtualization control are carried out through the target DPU, so that the multiple edge machine rooms form a unified training resource pool logically, and a distributed edge machine room computing power integration result is obtained.
Owner:YIHUA TECHNOLOGY (BEIJING) CO LTD +1

Network virtualization for remotely controlling robotic-assisted medical procedures

Disclosed systems, apparatuses, and methods enable remotely controlling robotic-assisted medical systems, such as robotic-assisted surgery systems, for performing remote robotic-assisted medical procedures. Disclosed approaches provide a secure, efficient, and dynamically-created virtual network for connecting physician consoles and robotic-assisted medical systems. Disclosed approaches improve efficiency, security, scalability, and reliability of remote robotic-assisted medical procedures.
Owner:SOVATO HEALTH INC

Communication method and device for outside and virtual machine, and storage medium

The invention discloses a method and equipment for communication between the outside and a virtual machine, and a storage medium, and relates to the field of network virtualization. The method comprises the following steps: creating a unique private network for each node; creating a virtual router for each node and associating the virtual router with an external network; setting a corresponding forwarding rule for the virtual machine under the node according to an external process needing to access the virtual machine; and according to the life event of the virtual machine, dynamically generating or releasing the target network address translation rule on the virtual router according to the forwarding rule of the virtual machine. According to the method, the target network address translation rule is dynamically generated for the virtual router according to the life event of the virtual machine, so that normal access of the outside to the application program of the virtual machine is realized under the condition of saving operation and maintenance means.
Owner:WUHAN OPENKER COMPUTING

Delay-tolerant constrained online convex optimization

A method and network node configured to perform wireless network virtualization to allocate resources of an infrastructure provider (InP) among a plurality of service providers (SPs) are provided. According to one aspect, a method in a network node includes, in each of a plurality of successive time slots in a time interval, T: receiving precoding feedback information from each SP, allocating a virtual transmit power to each cell served by an SP based at least in part on the received precoding feedback information and determining a precoding matrix for each SP. The method also includes minimizing a loss function based at least in part on the received precoding feedback information received in multiple previous time slots.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Cross-virtual routing forwarding proxy control method and device, and storage medium

The invention discloses a cross-virtual routing forwarding proxy control method and device and a storage medium, and relates to the technical field of network virtualization and proxy services, and the method comprises the steps: expanding proxy binding instruction grammar of network proxy software according to a preset virtual routing forwarding name parameter, and obtaining a target proxy binding instruction; according to the target agent binding instruction, a structural body of the network agent software is expanded, and an expanded structural body is generated; after a virtual route forwarding name corresponding to the target agent binding instruction is extracted, the virtual route forwarding name is stored in an extended local upstream configuration structural body, and a target local upstream configuration structural body is obtained; and after establishing a function creation socket, binding the socket with a target virtual routing forwarding name instance in the target local upstream configuration structural body to realize a cross-virtual routing forwarding proxy. Through the cross-virtual routing forwarding agent, the problem of poor efficiency of the cross-virtual routing agent is solved, and the implementation process of the cross-virtual routing forwarding agent is optimized.
Owner:深圳市三旺通信股份有限公司

IPv6 network slice isolation and anomaly detection method based on hierarchical encryption

The invention discloses an IPv6 network slice isolation and anomaly detection method based on hierarchical encryption, and the method comprises the steps: carrying out the fragmentation processing of an IPv6 network based on network virtualization, and generating all network slices; distributing an independent IPv6 address field for each network slice, and constructing an isolation routing rule; encrypting the data packets in each network slice by adopting a hierarchical encryption mechanism, wherein the encryption level is dynamically determined by the security level corresponding to the network slice; constructing a distributed state list on each node device of the current IPv6 network, and keeping real-time synchronization of the state list content of each node device based on a metadata consistency protocol; and according to a real-time state self-checking result of each node device recorded in the state list, judging whether each node device has a fault, and triggering an encryption strategy re-negotiation or isolation action of the corresponding network slice. According to the invention, the communication encryption of the corresponding level is executed on the data packet in each network slice.
Owner:阳城国际发电有限责任公司