Patents
Literature
Patsnap Copilot is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Patsnap Copilot

214 results about "Packet matching" patented technology

Network system, controller, and network control method

A network system includes appliances provided in a network; a switch provided in the network; and a controller connected to the appliances and the switch. The switch contains a flow table. Entries in the flow table each specify an action to be performed on a packet matching with a matching condition. Upon receiving a packet, the switch refers to the flow table and performs the action specified by matching one of the entries which matches the received packet, on the received packet. A first appliance of the appliances performs a first packet process on a packet belonging to an existing flow, when being selected as an active appliance. When the active appliance is switched from the first appliance to a second appliance of the appliances, the controller performs a switching process after performing a shortcut process. In the shortcut process, the controller instructs the switch to set a first entry into the flow table, the first entry specifying that the first packet process is to be performed on a packet belonging to the existing flow. In the switching process, the controller instructs the switch to set a second entry into the flow table, the second entry specifying that a packet which is addressed to the active appliance and belongs to a new flow other than the existing flow is to be transferred to the second appliance.
Owner:NEC CORP

Physical device and virtual network communication method and system based on SDN (Software Defined Network)

The invention discloses a physical device and virtual network communication method and system based on an SDN (Software Defined Network). The communication method comprises the following steps that physical device nodes are registered, and virtual node information is synchronized; physical devices which access for the first time are authenticated, thereby enabling the physical devices to access data; a controller issues flow tables to a physical network SDN switch and a virtual network switch and instructs a communication process of the physical devices and virtual machines; the physical devices send request data packets, wherein destination IP addresses and destination MAC addresses are the virtual machines; the physical network SDN switch receives the request data packets from the physical devices, matches the flow tables, packages the request data packets into VXLAN (Virtual Extensible Local Area Network) tunnels and forwards packaged data packets to the virtual network SDN switch corresponding to the virtual machines; and the virtual network SDN switch receives the packaged data packets through utilization of the VXLAN tunnels, matches the flow tables and forwards the request data packets to corresponding interfaces of the virtual machines. According to the method and the system, the physical devices and the virtual machines are located in the same subnetwork, and the access of the physical devices to layer 2 and layer 3 networks through utilization of a virtual network is supported.
Owner:JIANGSU FUTURE NETWORKS INNOVATION

A data processing method and network equipment

The embodiment of the invention provides a data processing method and network equipment, is applied to the technical field of communication, and aims to solve the problem of contradiction between statistical accuracy determination and statistical real-time performance of IPFIX flow monitoring analysis. Specifically, the method is applied to network equipment, and comprises the following steps: receiving a first data packet in a target data stream; Determining a first flow table entry according to the IP quintuple of the first data packet, the first flow table entry being a flow table entry matched with the first data packet, the aging duration of the first flow table entry being a first aging duration corresponding to the first service type, and the service type of the target data flow being the first service type; And accumulating the target parameters in the first aging duration according to the first flow table entry, the target parameters being parameters used for indicating the number of data packets in the target data flow in the target flow statistical information. The scheme is specifically applied to the process of determining the aging duration corresponding to the service type of the data stream before the network equipment reports the traffic statistical information of the data stream to the management equipment.
Owner:MAIPU COMM TECH CO LTD

Internet of things environment large data-based information safety monitoring and managing method and system

The present invention provides an internet of things environment large data-based information safety monitoring and managing method and system. The method comprises the steps of configuring the filtering rules, and establishing the mapping relation of the condition and the rule RULE_ID in a Hash table corresponding to each rule; analyzing the data packets uploaded by a plurality of environment monitoring devices, and extracting a plurality of keywords of the data in the data packets; generating each keyword into a Hash, and searching the Hash tables of the corresponding keywords to obtain thesearch result corresponding to the keywords; after all keywords are searched, obtaining a plurality of RULE_ID bitmaps, and carrying out the AND operation on the plurality of RULE_ID bitmaps to obtainthe final results matching the whole data packets; determining a final matching rule, and then outputting the corresponding data messages according to the filtering rules. According to the present invention, a cloud processing technology is utilized in a cloud data center to filter the environment index data, the performances of a multi-core processor are utilized fully, the real-time data filtering of high performance is realized, and the data safety is guaranteed.
Owner:SICHUAN MIANYANG TAIKOO SOFTWARE

SDN-based security service chain system and data packet matching and forwarding method

The invention discloses a SDN-based security service chain system. The system comprises a control plane, flow classification nodes, service nodes and a service chain. The control plane mainly comprises core control components of the SDN service chain that are a SDN controller and an OpenFlow 1.3 switch. The SDN controller creates a service chain according to user requirements and deploys service logics of each service node on the service chain. The controller sends the characteristics of user messages that need to be processed in the service chain to the OpenFlow 1.3 switch. The OpenFlow 1.3 switch introduces data messages into the service chain according to the corresponding message characteristics. The invention also discloses a packet matching and forwarding method of the SDN-based security service chain system. The network service chain is constructed and deployed based on SDN technology, and the linkage between network visualization and service chain is realized through the feedback of information. Therefore, in the case of massive data and multi-service nodes, the method has high data forwarding efficiency and low processing time to improve network monitoring efficiency. Theinvention designs a SDN-based service chain architecture and provides a matching and forwarding process of the service chain data packets based on the architecture.
Owner:TIANJIN CHENGJIAN UNIV +1

Methods and devices for configuring and issuing Open Flow items

The present application provides a method and an apparatus for configuring and delivering a flow table entry. The method comprises: a switch sending, to a controller, a request message for requesting delivering a flow table entry, the request message carrying a to-be-forwarded data packet; after the controller receives the request message, the controller generating all flow table entries matching the to-be-forwarded data packet, and returning, to the switch, a response message carrying all the flow table entries matching the to-be-forwarded data packet; after then switch receives the response message, the switch extracting all the flow table entries matching the to-be-forwarded data packet from the response message; and aggregating all the extracted flow table entries into flow table entries of a hardware layer, and when the switch supports the flow table entries of the hardware layer, the switch configuring the flow table entries of the hardware layer into a flow table of the hardware layer. The method and the apparatus for configuring and delivering a flow table entry in the present application can shorten the time of configuring flow table entries of a hardware layer into a flow table of the hardware layer, can shorten the delay of forwarding the data packets, and can reduce the number of lost packets of the data packets.
Owner:HUAWEI TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products