Patents
Literature
Patsnap Copilot is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Patsnap Copilot

34 results about "Stateful firewall" patented technology

In computing, a stateful firewall is a network firewall that tracks the operating state and characteristics of network connections traversing it. The firewall is configured to distinguish legitimate packets for different types of connections. Only packets matching a known active connection are allowed to pass the firewall.

Method and apparatus for implementing and managing distributed virtual switches in several hosts and physical forwarding elements

ActiveUS8966035B2Readily, securely, and efficiently communicate with each otherDigital computer detailsData switching by path configurationData centerVirtual switch
In general, the present invention relates to a virtual platform in which one or more distributed virtual switches can be created for use in virtual networking. According to some aspects, the distributed virtual switch according to the invention provides the ability for virtual and physical machines to more readily, securely, and efficiently communicate with each other even if they are not located on the same physical host and / or in the same subnet or VLAN. According other aspects, the distributed virtual switches of the invention can support integration with traditional IP networks and support sophisticated IP technologies including NAT functionality, stateful firewalling, and notifying the IP network of workload migration. According to further aspects, the virtual platform of the invention creates one or more distributed virtual switches which may be allocated to a tenant, application, or other entity requiring isolation and / or independent configuration state. According to still further aspects, the virtual platform of the invention manages and / or uses VLAN or tunnels (e.g, GRE) to create a distributed virtual switch for a network while working with existing switches and routers in the network. The present invention finds utility in both enterprise networks, datacenters and other facilities.
Owner:NICIRA

Implementation method of software-defined firewall system

The invention discloses an implementation method of a software-defined firewall system, which belongs to the technical field of computer networks. The method comprises the following steps: establishing connection between an OpenFlow switch and an SDN controller, and receiving a table-miss flow table entry and an initial flow table entry; sending the data packet by the OpenFlow switch to the SDN controller; performing state detection filtering on the TCP data packet by a state detection filtering module in the SDN controller through combinations with the firewall rule and the state of the datapacket, and maintaining a state connection table; and performing packet filtering on the stateless IP protocol data packet by a packet filtering module in the SDN controller according to a firewall rule, and issuing a flow table entry to the OpenFlow switch to guide subsequent data packet processing. According to the method, stateless packet filtering and stateful state detection filtering can berespectively carried out on data packets of different protocol types, the state firewall function is achieved, the operand of the SDN controller is reduced by issuing the flow table item in the packetfiltering process, in addition, an OpenFlow protocol does not need to be modified when state detection filtering is achieved, and higher universality is achieved.
Owner:ZHEJIANG UNIV

Edge internet-of-things proxy basic service security management system

PendingCN114726576AStrengthen the security effect of basic servicesImprove securitySecuring communicationCommunication interfaceData terminal
The invention relates to an edge internet-of-things proxy basic service security management system, which comprises a communication interface management module used for controlling the start and stop states of various communication interfaces and monitoring the communication states of the various communication interfaces in real time; the firewall strategy management module is used for monitoring the state of the firewall in real time and controlling the start-stop state of the firewall; the security chip encryption module is used for encrypting transmission data and storage data; the terminal authentication module is used for carrying out identity authentication and authorized access on the terminal equipment in a remote user dialing authentication mode; the operation and maintenance safety management module is used for being connected with an operation and maintenance terminal through a CONSOLE interface, wherein the operation and maintenance terminal is authenticated in a remote user dial-up authentication mode and then is accessed to an upper-layer internet-of-things operation center; the secure storage module is used for encrypting and storing the database data; and the external security access module is used for connecting the upper layer Internet of Things operation center and the message bus to realize subscription and forwarding of the theme data.
Owner:SHANDONG LUNENG SOFTWARE TECH

Method and device for realizing high-performance state firewall

PendingCN113765858AImprove throughputImprove the ability to process packetsData switching networksData packData stream
The invention provides a method and a device for realizing a high-performance state firewall. The device comprises a data packet processing module VPP, a routing module, a firewall policy module and a flow state module. The data packet processing module (VPP) is configured to receive transmission data from a network interface. And the routing module queries routing information and forwards data. And the firewall policy module is used for matching a firewall policy issued by a user, and performing security policy matching on the data flow of the session established for the first time according to an IP address, a protocol and a port number. And the flow state module is used for creating a flow session for the data flow successfully passing through the firewall policy, carrying out flow state detection on the flow in which the session is established, refreshing the flow table when the firewall policy is changed and the route is changed, periodically checking the flow table, and deleting the flow of which the state is not updated in a life cycle from the flow table. By reducing the repeated query matching of the firewall security policy table and the query of the routing table, the data packet processing capability of the VPP is improved, the throughput rate of the firewall is improved, and the data forwarding performance of the firewall is effectively improved.
Owner:中创为(成都)量子通信技术有限公司
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products