Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

181 results about "Overlay network" patented technology

An overlay network is a computer network that is built on top of another network.

Precise synthesis-based graph mapping method

The invention discloses a graph mapping method based on precise synthesis, and the method comprises the steps: constructing a precise synthesis structure library based on NPN equivalence classes, and inputting the precise synthesis structure library into a Boolean network; k-Cut cutting enumeration is carried out on the input Boolean network, a truth table is calculated, cutting is matched with a structure in a precise comprehensive structure library through Boolean matching, and rapid search is realized in combination with NPN classification; the overlay network is generated through multi-round mapping optimization, logic sharing nodes are mined in combination with structural hash, and the multi-round mapping optimization comprises delay-oriented mapping, global area topological optimization and local accurate area optimization; and a new target network is generated based on the optimized overlay network, redundant nodes are removed, and final network construction is completed. According to the method, manual intervention is not needed through full-process automatic mapping and a redundancy removal mechanism, the labor cost of a technical mapping link in chip design is remarkably reduced, and the method is particularly suitable for efficient design of complex circuits and emerging majority of logic base technologies.
Owner:HANGZHOU JIUZHIXING SOFTWARE CO LTD

Ultra wide band direction finding information extraction method based on multi-input single-output delay overlay network

The invention discloses an ultra wide band direction finding information extraction method based on a multi-input single-output delay superposition network. The method comprises the following steps: acquiring an antenna receiving signal and an attitude transformation matrix of an antenna; processing an antenna receiving signal to obtain a time point of a first peak leading edge detection threshold value and pulse sequence data in a complex form; carrying out 64-time up-sampling processing on the pulse sequence data in the plural form, and drawing an amplitude-time curve and a phase-time curve; determining a peak value corresponding to the adjacent antenna according to the peak value leading edge time point; calculating the peak values corresponding to the adjacent antennas to obtain the time difference of arrival and the phase difference of the adjacent antennas; and ultra-wideband direction-finding information positioning is realized. According to the invention, group delay can be carried out on the ultra-wideband pulse signal by adopting the delay line with the given length, and the ultra-wideband direction-finding information positioning precision is improved. The ultra wide band direction finding information extraction method based on the multi-input single-output delay overlay network can be widely applied to the technical field of ultra wide band positioning.
Owner:FOSHAN UNIVERSITY +1

Scalable distribution of identification information with identification-based policies in overlay networks

A network controller in an overlay network maintains a total set of identification-based policies and identification mappings for online users of the network for distribution to notifications across network elements of the network. When a new user is online, the controller identifies a site of a network where the user is online, and determines an identification map and applicable policy for the user for distribution to network elements at the identified site. The controller assigns an index value to each identity and communicates the index with the corresponding identity map and policy to the network element. The network element encapsulates cross-site traffic with an index value corresponding to the sender, so that the receiver network element can obtain the index value from the encapsulated header format, query the controller for a corresponding identification map, and apply a policy to traffic determined as relevant based on the sender's identification map obtained from the controller.
Owner:PALO ALTO NETWORKS INC

Techniques for a key management service in an overlay network

Techniques are disclosed for implementing a key management service in a reduced footprint data center. A cryptographic service can execute at a computing device of the reduced footprint data center. The cryptographic service can generate a master encryption key and encrypt the master encryption key using a secure component of the computing device to produce an encrypted master encryption key. The encrypted master encryption key can be stored in a block storage volume communicatively connected to the computing device. The cryptographic service can transmit the master encryption key to a host region data center and receive a wrapped master encryption key. The cryptographic service can store the wrapped master encryption key in a database of the reduced footprint data center.
Owner:ORACLE INT CORP

VXLAN access authentication method and VTEP device

A VXLAN access authentication method includes: An authentication point device receives a VXLAN authentication packet, where the VXLAN authentication packet is a VXLAN packet. The VXLAN authentication packet includes a VXLAN header and an authentication request sent by a terminal, the VXLAN header includes a first VNI, and the authentication request includes an authentication credential. The authentication point device obtains permission of the terminal or a second VNI based on the authentication credential. The permission of the terminal corresponds to the second VNI. The authentication point device sends the permission of the terminal or the second VNI to a control point device, where the control point device is a device that encapsulates the authentication request into the VXLAN authentication packet. In this application, VXLAN access authentication is performed on an overlay network, so that configuration complexity can be reduced when a VXLAN access authentication mode is modified or created.
Owner:HUAWEI TECH CO LTD

Combining multiple detection algorithms into a confidence score for bot detection

A bot detection service associated with an overlay network operates to score traffic as a probability of being a bot, as opposed to returning a binary classification (i.e., bot or human). According to the approach herein, scoring is determined through probability estimates, wherein a score (the probability) is based on considering a set of detections concurrently. In one embodiment, all (or substantially all) triggered (current) threat detections contribute to the score. The preferred approach penalizes requests that fail all (or substantially all) combinations of detection algorithms. According to a further feature, an automated tuning (autotuning) is also applied, e.g., using real-time empirical statistical models, to adapt the measurement of false positive probability for one or more threat detection algorithms to suit customer traffic trends. The approach herein is also extensible to include any number of future threat detection algorithms.
Owner:AKAMAI TECHNOLOGIES INC

Policy builder for overlay networks

Embodiments are directed to managing communication over a network. Entities may be determined based on network traffic in an underlay network and classified based on characteristics of the entities, portions of the network traffic in the underlay network, or the like. Policies for an overlay network may be generated based on the classified entities or the portions of the network traffic. Policies may be deployed to gateways that may be associated with the entities such that the gateways facilitate access to the overlay network based on the policies. In response to determining other entities in the underlay network based on other network traffic in the overlay network and the network traffic in the underlay network, the one or more policies may be updated based on the other network traffic in the overlay network, the network traffic in the underlay network, or the one or more other entities.
Owner:TYCO FIRE & SECURITY GMBH

Network threat systematic protection method

PendingCN121966996ASecuring communicationSecurity operations centerData aggregator
The invention discloses a network threat systematic protection method, and belongs to the technical field of network security. According to the method, a unified policy center is constructed, and three layers of security policies of an overlay network, a terminal and an application are defined and issued in a unified manner; network admission control, terminal security management and API risk monitoring systems are deployed to execute strategies respectively; an intelligent linkage mechanism is established, and cross-system automatic co-processing is realized; centralized monitoring, data aggregation and visual analysis are carried out through the unified safety operation center, and support is provided for optimization; and continuously optimizing the strategy and the rule based on the operation data. According to the invention, the problems of isolation, strategy splitting and response lag of a protection system in the prior art are solved, and an active defense system with cooperative linkage and continuous evolution is constructed.
Owner:GUANGZHOU CHANGBENHENG NETWORK TECHNOLOGY CO LTD +1

System and method for application-based micro-segmentation

A system and method for controlling the handling of intra-VPC and inter-VPC communications is described. First, a destination of a communication is determined it resides within a first virtual private cloud network (VPC) of a source of the communication. If so, filtering communications between the destination and the source is controlled by native cloud constructs associated with a cloud service provider (CSP) underlay network for the first public cloud network. Otherwise, filtering communication between the destination and the source is controlled by a spoke gateway. The spoke gateway is part of a cloud overlay network configured to provide a communication path between the first virtual private cloud network and the second private cloud network and using micro-segmentation to set and manage security policies.
Owner:AVIATRIX SYSTEMS INC

Efficient multicast source roaming in an overlay network

A first network device operating as a tunnel endpoint in a tunnel fabric is provided. During operation, the first network device can receive, via a local port, a network join request to receive multicast traffic of a multicast group from a second network device. The first network device can store a multicast state for the multicast group in a data structure associated with the control plane. The multicast state can indicate that the network join request is received via a tunnel between the first and second network devices. The first network device can then determine whether a source of the multicast group is coupled to the first network device. If the source is coupled to the first network device, it can program a multicast forwarding entry corresponding to the multicast state in forwarding hardware and forward the multicast traffic to the second network device based on the multicast forwarding entry.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Host routed overlay with deterministic host learning and localized integrated routing and bridging

To provide systems, methods, and devices for improved routing operations in a network computing environment.SOLUTION: An architecture 400 for host routed overlay includes a virtual customer edge router (virtual CE router), a plurality of host virtual machines, and a routed uplink from the virtual customer edge router to one or more of a plurality of leaf nodes L1 to L4. The architecture is such that the virtual customer edge router provides localized integrated routing and bridging (IRB) service for the plurality of host virtual machines of the host routed overlay.SELECTED DRAWING: Figure 4
Owner:ARRCUS INC

High-concurrency message processing method and system

The invention relates to the technical field of distributed system architecture, and particularly provides a high-concurrency message processing method and system, and the method comprises the following steps: S1, carrying out the registration of a dynamic consumer group; s2, adopting a multi-stage retry strategy to carry out exception handling chain design; and S3, memory and performance optimization. Compared with the prior art, an independent message queue assembly does not need to be deployed, Redis infrastructure is reused, and the operation and maintenance overhead is reduced by 50% or above; a single node supports 100,000 + TPS, which is improved by 3-5 times compared with a traditional message queue; if the message loss rate is lower than 0.001%, the retry mechanism covers network jitter and service fault scenes; dynamic adjustment of the number of consumers and Redis Cluster fragmentation is supported, and the service elastic requirement is met.
Owner:INSPUR COMM TECH CO LTD

Techniques for a key management service in an overlay network

Techniques are disclosed for implementing a key management service in a reduced footprint data center. A cryptographic service can execute at a computing device of the reduced footprint data center. The cryptographic service can generate a master encryption key and encrypt the master encryption key using a secure component of the computing device to produce an encrypted master encryption key. The encrypted master encryption key can be stored in a block storage volume communicatively connected to the computing device. The cryptographic service can transmit the master encryption key to a host region data center and receive a wrapped master encryption key. The cryptographic service can store the wrapped master encryption key in a database of the reduced footprint data center.
Owner:ORACLE INT CORP

EVPN host routing bridging HRB and EVPN cloud native data center

The embodiment of the invention relates to EVPN host routing bridging (HRB) and an EVPN cloud native data center. Techniques are described for an EVPN host routing bridge (HRB) and an EVPN cloud native data center with a host routing bridge (HRB). A host computing device of a data center includes one or more containerized user-level applications. The cloud native virtual router is configured to be dynamically deployed by a datacenter application orchestration engine and operable in a user space of the host computing device. The processing circuitry is configured to execute the containerized user-level application and the cloud native virtual router. The cloud native virtual router includes a containerized routing protocol process configured to operate as a control plane, and a data plane for the containerized router. The data plane is configured to operate an Ethernet virtual private network (EVPN) encapsulated / deencapsulated data path of the overlay network for communicating layer 2 (L2) network traffic of the containerized user application over a switching fabric of the data center.
Owner:JUNIPER NETWORKS INC

Method and apparatus for configuration check of an overlay network

ActiveCN117614814BDomain namePathPing
The application discloses a kind of configuration checking method and device of overlapping network, it is related to computer network technical field, the method includes: obtaining the trouble shooting request of user on overlapping network;When determining that the IP address pair of trouble shooting is cloud load balancing device address, then execute the first checking operation of listener, domain name and URL path of cloud load balancing device;When determining that the IP address pair of trouble shooting is cloud server device address, then execute the second checking operation of security group configuration and port configuration of cloud server device;When determining that the IP address pair of trouble shooting is not cloud load balancing device address and is not cloud server device address, then according to the association between the trouble shooting position information and corresponding third checking operation, determine and execute the third checking operation corresponding to the trouble shooting position information;Generate the notification information with the check result of checking operation.This application is to improve the efficiency of configuration checking of overlapping network.
Owner:CHINA CONSTRUCTION BANK

Browser impersonator detection (BID) system

A bot detection service associated with an overlay network and configured as a centralized control plane, and a data plane that operates in an overlay network entity, e.g., an edge server. The control plane performs analytics continuously to generate a machine learning (ML) model, a set of device anomaly (DAN) patterns, and false positive (FP) tuning data. During a request processing workflow at the edge server, a request is received. A subset of detector rules triggered by the request are identified, optionally using the DAN patterns. The ML model is then applied to the subset to classify the request as a bot or human. When the request is classified as a bot, the FP tuning data is applied to determine whether to selectively override the classification as being a false positive. When the request is classified as a bot and not overridden, an action is taken, e.g., denying the request.
Owner:AKAMAI TECHNOLOGIES INC

Overlay network for real-time payment networks

Disclosed are various embodiments for facilitating payments between members of separate payment networks. A first instance of a supernetwork can receive a payment request from a source network hub connected to the first supernetwork instance and linked to a first payment network, the first payment request specifying an identifier for a recipient institution and an amount of the payment request. The first instance of the supernetwork can then query a participant status cache to identify a destination network hub linked to a second payment network associated with the recipient institution. Next, the first instance of the supernetwork can query a participant registry to identify a second supernetwork instance connected to the destination network hub. Finally, the first instance of the supernetwork can forward the payment request to a second global transaction router hosted by a second supernetwork instance connected to the destination network hub.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

A method for overlay network access control and password isolation based on user identity

The present application discloses a method for overlay network access control and password isolation based on user identity identification, comprising: deploying an asymmetric cryptographic system based on identification passwords on CPE devices, and using the identification passwords to design CPE device network identifications, device public and private keys, and user identifications; binding user identifications with access control policies and transmission encryption policies, and utilizing identity authentication services and policy services provided by infrastructure; applying user identifications to service access processes, and implementing two-level permission checks on CPEc devices and CPEs devices at the edge of the overlay network to achieve fine-grained access control for different user services; setting a zero-interaction service key generation mechanism based on the algorithmic characteristics of identification and public keys, and cooperating with the Encapsulating Security Payload Protocol to protect the confidentiality, integrity, and forward security of user service data, thereby achieving strong password-based security isolation of different user service data on the overlay network.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Zero trust data castle system with security operation methods for active response

The present disclosure relates to attack-tolerant storage system architecture with active response methods against different forms of storage intrusion for data at-rest, under-operation and in-motion as an integrated system design. System is built upon a Storage security controller (SG nodes), USC, overlay network of DTC nodes attached to SG nodes. System security modules are deployed across various geo locations in a Wide Area Network. USC extracts system, security and storage activity telemetry data from Secure Vaults, Storage Gateways and inter-site data transfer systems to orchestrate autonomous security Operations. SG nodes create SP fragments and store in SV nodes or move it across DTC nodes upon data operations. SG nodes are connected to SV nodes which are micro-segmented, data vaults with restricted network reachability. Kill-Data-Service methods and other Active Response security methods are triggered from SG nodes or at DTC nodes, as part of AR operations, orchestrated by USC.
Owner:CHACKO PETER

Overlay network ingress edge region selection

This disclosure relates to enhanced overlay network-based transport of traffic to and from customer branch office locations, facilitated through the use of the Internet-based overlay routing. A method of selecting an ingress edge region of the overlay network begins by mapping a service hostname to an IKEv2 destination of an outer IPsec tunnel associated with a first overlay network edge. An IKEv2 session is established from the first overlay network edge to the customer router. Upon tunnel establishment, a secondary lookup is performed to determine whether the first overlay network edge is an appropriate ingress region. Based on a response to the secondary lookup, a IKEv2 redirect is issued to a second overlay network edge. A new tunnel is then established from the second overlay network edge to the customer router. Thereafter, an additional lookup may also be performed to determine whether the second overlay network edge remains an appropriate ingress region.
Owner:AKAMAI TECHNOLOGIES INC

Methods, systems, and machine storage media for providing secure access to sandboxed user-defined functions

This application relates to secure network access from sandboxed applications. Methods, systems, and computer programs are proposed to enable any sandboxed user-defined function code to securely access the Internet via a cloud data platform. The cloud data platform receives remote procedure calls from user-defined functions (UDFs) executing within a sandboxed process. The UDF includes code associated with at least one operation to be performed. The cloud data platform provides an overlay network to establish a secure exit path for external access to the UDF. The cloud data platform enables the UDF executing within the sandboxed process to initiate network calls.
Owner:SNOWFLAKE INC

Secure blockchain routing technique

Systems and methods for providing secure blockchain routing using an extended blockchain protocol are described herein. In some embodiments, a blockchain routing node can join an overlay network comprising a plurality of blockchain routing nodes. The blockchain routing node can receive a plurality of forwarding tables from the plurality of blockchain routing nodes in accordance with an extended blockchain protocol. The blockchain routing node can determine a routing table for the overlay network based at least in part on the plurality of forwarding tables. In some embodiments, the blockchain routing node can route a payload message to a target blockchain routing node in the overlay network in accordance with the determined routing table.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

System and method for accessing k8s based on agent-based heterogeneous computing nodes

The application discloses a system and method for accessing K8s based on an agent, relates to the field of cloud native technology, and realizes the full-process automation of agent initialization registration, node queue allocation, hardware information collection and resource pre-inspection, node environment preparation, K8s cluster access, node label updating and post-validation by deploying an access agent Agent, combining a control plane module, a node controller module, a node access workflow module and a network access module to construct an integrated access architecture; the network environment difference is shielded by using Tailscale to construct an Overlay network, the container runtime and acceleration components are adaptively selected based on the hardware collection results, and the node access full-life cycle closed-loop management is realized through a state machine and a task queue. The application supports the unified automatic access of heterogeneous computing power such as multiple types of GPU, physical machine / virtual machine / edge PC / cloud node and the like, and improves the heterogeneous computing power resource scheduling efficiency.
Owner:TONGFANG YOUYUN (BEIJING) TECH CO LTD

Automatically directing custom compute operational flows through a heterogeneous overlay and cloud compute infrastructure

A heterogeneous overlay network and cloud compute infrastructure comprises different tiers of PoPs that are configurable to provide different amounts of cloud computing. To facilitate the programming (configuration) of compute and caching operations throughout the heterogeneous network, a control mechanism and methodology are provided for automatically directing the flow of custom compute and caching operations using configurable “operations chains.” A representative operation chain comprises a configuration file that specifies a traffic flow, and a set of operations and their relative ordering. A particular operation chain defines an initial operation that typically starts at a given edge machine in the heterogeneous network and then, as needed, one or more additional locations and their associated machines may then be used to facilitate processing of the operation chain.
Owner:AKAMAI TECHNOLOGIES INC

Network monitoring method and device, equipment and storage medium

The invention discloses a network monitoring method and device, equipment and a storage medium, and belongs to the field of network monitoring. The method comprises the following steps: acquiring topological information of a network; based on the topological information of the network, at least one detection path covering all or part of links in the network is generated, each detection path passes through at least one intermediate node, and a starting node and an ending node of the detection path are end nodes; for the at least one detection path, a starting node of the detection path is controlled to send a first detection message to a termination node of the detection path, the first detection message is used for collecting node information of a passed intermediate node, and the node information of the intermediate node is used for indicating the network condition of a link connected with the intermediate node; acquiring node information from an intermediate node and / or a termination node through which the first detection message passes; based on the node information, a network condition of at least one link through which the probe path passes in the network is monitored. According to the method, the network covered by the detection path can be monitored.
Owner:SHENZHEN TENCENT COMP SYST CO LTD

Network fault detection using a machine learning model

PendingUS20250286770A1TransmissionNetwork onEngineering
In some examples, a system receives a first representation of attributes associated with a network stack connected to an underlay network that couples a first system to a computing environment, where the network stack comprises a plurality of layers. The system receives a second representation of attributes associated with an overlay network provided over the underlay network. The system provides the first representation and the second representation to a machine learning model trained to detect a fault associated with communications between the first system and the computing environment. The machine learning model generates an output comprising a value representing a likelihood of a presence of the fault associated with the overlay layer or the underlay layer. Based on the output, the system initiates a remediation action to address the fault.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Mapping keys to a blockchain overlay network

A method of managing an overlay network overlaid on data-storage transactions of a blockchain, whereby data content of the overlay network is stored in payloads of the data-storage transactions and overlay-layer links are defined between the data-storage transactions. The method comprises identifying a graph structure of the overlay network, wherein nodes corresponds to different ones of the data-storage transactions and edges correspond to the links. Each node is associated with a respective first key for signing an input of a child data-storage transaction to authorise writing the child to the blockchain. The method further comprises using a child key derivation, CKD, function to determine a hierarchical set of second keys having the same graph structure as the overlay network, wherein the second keys enable an additional function other than signing inputs of the data-storage transactions.
Owner:NCHAIN LICENSING AG