Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

109 results about "Virtual network" patented technology

A virtual network is a computer network that consists, at least in part, of virtual network links. A virtual network link is a link that does not consist of a physical connection between two computing devices but is implemented using methods of network virtualization. The two most common forms of network virtualization are protocol-based virtual networks, and virtual networks that are based on virtual devices. In practice, both forms can be used in conjunction. Virtual LANs are logical local area networks based on physical LANs. A VLAN can be created by partitioning a physical LAN into multiple logical LANs using a VLAN ID. Alternatively, several physical LANs can function as a single logical LAN. The partitioned network can be on a single router, or multiple VLAN's can be on multiple routers just as multiple physical LAN's would be. A VLAN can be on a VPN. A virtual private network consists of multiple remote end-points joined by some sort of tunnel over another network, usually a third party network. Two such end points constitute a 'Point to Point Virtual Private Network'. Connecting more than two end points by putting in place a mesh of tunnels creates a 'Multipoint VPN'.

A method for security threat perception and detection of global network devices

ActiveCN121841825BInternet trafficAttack
This invention discloses a security threat perception and detection method for global network devices. It simultaneously collects three types of data: network traffic, behavior logs, and attack characteristics, forming multi-dimensional factual evidence. The method utilizes a firework algorithm to optimize the deployment of logical monitoring points (feature nodes) in the virtual network and calculates the dynamic intensity of threat propagation at each point, thereby constructing a node-level threat field that quantifies the spatial distribution of threats. Subsequently, peak, mean, and dispersion indicators are extracted, and behavioral load, threat polarization, and cumulative threat indicators are calculated from the raw data, forming a six-dimensional vector. This vector is input into a pre-trained global threat level classification model, outputting a discrete threat level. Finally, based on this level, firewall rules, intrusion detection feature libraries, and other protection strategies are dynamically adjusted to achieve automatic matching of security configuration and threat posture.
Owner:BEIJING SHANGZHANG INFORMATION TECHNOLOGY CO LTD

IP layer-oriented SSL VPN tunnel transmission method

The application discloses an SSL VPN tunnel transmission method for an IP layer, and relates to the technical field of network communication.The method constructs an IP virtual tunnel outside an SSL session, and directly encapsulates and transmits complete IP messages, thereby completely breaking through the limitation that a traditional SSL VPN only supports a Web proxy, and transparently passing through the tunnel for TCP services, UDP streaming media, ICMP network diagnostic messages, and the like, so that the method realizes remote access of the IP layer in a true sense, and a server adopts a south-north decoupling design, a virtual network port is used as a southward interface to communicate with a client tunnel, and the northward directly interacts with an intranet physical network card through a system routing table, without analyzing transport layer content, without maintaining a TCP connection state, and only performing IP layer transparent forwarding, so that the processing cost is greatly reduced, and the throughput performance is obviously improved.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Method, system, and storage medium of virtual network function placement for mapping service function chain requests in cloud network

PendingUS20260189496A1EngineeringCloud networking
A method of virtual network function (VNF) placement for mapping service function chain requests (SFCRs) includes, at the node mapping stage, receiving a SFCR including a plurality of virtual network function requests (VNFRs) from a user, ranking server nodes with initiated virtual machines (VMs) of a required type to obtain a first best-ranked server node, and placing a VNFR onto the first best-ranked server node; if the VNFR cannot be placed onto any server node in the server nodes with the initiated VMs, ranking server nodes without the initiated VMs of the required type to obtain a second best-ranked server node, initiating a new VM having a type same as the required type on the second best-ranked server node, and placing the VNFR onto the second best-ranked server node; and after placing the VNFR onto the first or second best-ranked server node, selecting a source node for video synchronization.
Owner:INTELLIGENT FUSION TECHNOLOGY INC

Chip and mainboard connection method and device, electronic equipment and storage medium

The application provides a chip and mainboard connection method and device, electronic equipment and a storage medium. The method comprises the following steps: acquiring connection records of a preset virtual network of the chip within a preset time period; acquiring running state information of the chip connected to the preset virtual network; determining an estimated network quality of the preset virtual network for to-be-communicated data according to the connection records, the to-be-communicated data and the running state information; determining a target virtual network for which the estimated network quality meets a preset condition; and establishing a data communication connection between the chip and the mainboard based on the target virtual network, for transmitting the to-be-communicated data. The stable connection between the chip and the mainboard is realized through the virtual network, which effectively avoids the problems of loose connection, poor contact and aging of the golden finger between the interfaces caused by direct connection of the hardware interfaces, and further causes signal transmission failure.
Owner:GUANGZHOU ZHUNJIE ELECTRONIC TECH CO LTD

A system framework and network architecture for edge virtual network functions

The application discloses a kind of edge virtual network function system framework and network architecture, its system framework includes: portal control center, service ability empowerment and dispatching middle station and multiple POP clusters;Wherein, portal control center is used to face user, operation and maintenance, operation and service provider provide unified entrance, include portal management, operation and maintenance alarm system, operation work order system, order and delivery management system and unified identity authentication system;Service ability empowerment and dispatching middle station are responsible for connection control module, API gateway, tenant management, service guarantee, identity authentication, multiple cluster resource scheduling strategy issue and third party interface unification;POP cluster is used to be responsible for service chain arrangement and the operation of NFV network function pool, in combination with monitoring and operation, resource scheduling and high-performance forwarding surface complete tenant business load.The application realizes controllable flow arrangement under the multi-tenant scenario, resource elastic allocation and performance guarantee, improves the flexibility, scalability and user experience of NaaS platform.
Owner:COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI

Software-defined multi-path virtual network

PCT designated stageWO2026109520A1TransmissionNetwork addressingEngineering
Disclosed is a method of communication in a software-defined network (SDN) that includes a central controller, and a plurality of client nodes managed by the central controller, wherein each client node runs an SDN client. The method includes transmitting a connection request from first to second client node, wherein the connection request includes address candidate groups (ACGs) of network interfaces assigned to first client node, and wherein an ACG of a network interface includes a plurality of network addresses assigned to said network interface; transmitting a response including ACGs of network interfaces assigned to second client node, to first client node, forming a plurality of network interface pairs, forming a plurality of address candidate pairs for each network interface pair based on ACGs of first and second nodes, wherein an address candidate pair include an address of a network interface of client node, and an address of a network interface of second client node; attempting to establish a connection between first and second client nodes over each address candidate pair; and initiating data exchange between first and second client nodes over connections established therein.
Owner:UNIV COLLEGE CORK NAT UNIV OF IRELAND CORK

Controller and network configuration method

The present disclosure relates to a controller and network configuration method. The controller comprises an orchestrator of a virtualized computing infrastructure, wherein the orchestrator is configured to: receive namespace specification data specifying a namespace, a first virtual network for the namespace, and a second virtual network for the namespace; receive virtual execution element specification data specifying a virtual execution element, wherein the virtual execution element specification data comprises a namespace object specifying a namespace of the virtual execution element; and send, based on the namespace specification data and the namespace object, one or more requests to a network controller of the virtualized computing infrastructure to create respective virtual network interfaces of the first virtual network and the second virtual network for the virtual execution element.
Owner:JUNIPER NETWORKS INC

A USB interface-based intelligent agent deployment device and method

PendingCN122450514AMass storagePhysical security
The application discloses a kind of intelligent agent deployment device and method based on USB interface.The device includes USB interface unit, processing unit, storage unit and memory unit.Processing unit independently runs a lightweight operating system and starts pre-installed intelligent agent service;After service initialization is completed, it is presented as a composite USB device to host through USB interface, including virtual network card interface and mass storage interface.Host is identified by standard USB device class driver free drive, and user can access intelligent agent service through browser, and read output file through resource manager.Memory unit is physically isolated from USB bus address domain through MMU in processing unit, and only shared buffer can be accessed by host.The application realizes hardware-level physical security isolation and free plug-and-play intelligent agent deployment.
Owner:BEIJING SANJIAHONG TECHNOLOGY CO LTD

A network security traffic feature compensation identification method based on a graph neural network

This invention discloses a network security traffic feature compensation and identification method based on graph neural networks. The method includes: acquiring network traffic data to be tested and extracting key attributes; constructing a dynamic heterogeneous graph based on the key attributes; performing feature compensation processing on the dynamic heterogeneous graph, mapping nodes to a three-dimensional coordinate space and compensating for missing feature dimensions; inputting the compensated dynamic heterogeneous graph into a graph neural network model to generate node state information; comparing the node state information with a sparse baseline to output an anomaly score; and generating a virtual network function management strategy based on the anomaly score and deploying it to the target node. This invention achieves traffic feature compensation through three-dimensional coordinate mapping and neighbor feature aggregation, combines graph neural networks and a sparse baseline for anomaly detection, and forms a closed-loop response through inference acceleration and automatic VNF deployment, thereby improving the accuracy and real-time performance of network security detection.
Owner:XIANYANG NORMAL UNIV

Emulating mobile devices

Apparatuses, systems, and techniques to perform a digital simulation of a wireless network. In at least one embodiment, a processor generates a virtual network simulation and combine user equipment of said virtual network simulation into virtual cells in order to cause at least one of two or more mobile device emulation programs to be selected based, at least in part, on two or more distinct physical resource block parameters corresponding to said two or more mobile devices.
Owner:NVIDIA CORP

Systems and methods for adaptive weighting of machine learning models

PendingUS20260203134A1PersonalizationAdaptive weighting
Methods, systems, and computer-readable media for generating a personalized virtual network. The method acquires a request for a service associated with a user and their preferences. The method then identifies one or more conditions of the user and their propensities based on a first set of machine learning models using stored past information of the user. The method next identifies a second set of machine learning models and evaluates the weightage of each model based on the determined propensities of the conditions. The evaluated weights are applied to the second set of models to generate a personalized virtual network for the user.
Owner:INCLUDED HEALTH INC

A virtual switch deployment, testing method and apparatus

ActiveCN121239653BTransmissionVirtual switchNetwork topology
This application relates to a method and apparatus for deploying and testing virtual switches. The method includes: acquiring network topology information of an embedded platform to be deployed; wherein the network topology information includes a first binding relationship between virtual network ports and virtual switches, and a second binding relationship between the virtual switches and the Ethernet interfaces of the device under test; deploying virtual network ports in the software area and virtual switches in the logical area of ​​the embedded platform to be deployed, based on the number of virtual network ports and virtual switches in the network topology information; binding the deployed virtual network ports and virtual switches according to the first binding relationship, and binding the Ethernet interfaces and deployed virtual switches according to the second binding relationship. This method can reduce the space occupied by virtual switches.
Owner:CHENGDU CELIS TECH CO LTD

Packet flow control in a header of a packet

PendingUS20260197271A1TelecommunicationsSubstrate network
Techniques for controlling packet flows are described. In an example, a packet is sent on a virtual network. The packet's header includes scoping data that indicates a network boundary within which the packet is permitted and / or prohibited to flow. A network virtualization device of a substrate network receives the packet. The network virtualization device determines the scoping data from the header and, based on network configuration information, determines the forward flow of the packet. If the forward flow falls within a permitted network boundary indicated by the scoping data, the network virtualization device sends the packet forward. Otherwise, the packet is dropped.
Owner:ORACLE INT CORP

Method, device and equipment for dynamically isolating and allocating virtual network address and storage medium

PendingCN122093362Aachieve isolationfix the leakTransmissionResource informationThe Internet
This application discloses a method, apparatus, device, and storage medium for dynamic isolation and allocation of virtual network addresses, relating to the field of virtual internet technology. The method includes receiving resource request information from a user, determining the currently allocated target virtual network address, and then determining the target network access zone where the target virtual network address resides; obtaining the target tenant identifier corresponding to the target network access zone; and accessing resource information under the target tenant associated with the target tenant identifier through the resource request information. By establishing the correspondence between the target virtual network address, the target network access zone, and the target tenant identifier, the method solves the problems of missing tenant isolation and inefficient fault recovery in related technologies, thereby achieving technical effects such as improved fault recovery efficiency, reduced data leakage risk, and enhanced data security.
Owner:JINAN INSPUR DATA TECH CO LTD

Communication method and device for paas component management end and virtual machine agent

ActiveCN115185637BPrivate networkIp address
The application provides a communication method and device of a PaaS component management end and a virtual machine agent, wherein the method comprises the following steps: creating a plurality of host ports in a private network corresponding to the PaaS component, the number of the host ports being the same as the number of control nodes; constructing a virtual network card on a br-int bridge of each control node by using an Open vSwitch, the information of the virtual network card being associated with the information of the corresponding host port; dynamically obtaining an IP address corresponding to the virtual network card from a DHCP service provided by a neutron; and creating a virtual IP of a private network plane based on keepalived, which is used for responding to an RPC request of the PaaS component management end by an agent in the virtual machine. The application utilizes the Open vSwich technology, realizes the two-layer communication between the PaaS component management end and the virtual machine agent, and breaks through the dependence of the PaaS component on the virtual machine external network and the physical machine network planning.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Virtual network fault diagnosis method and device

PendingCN122348896AData packPathPing
The application provides a virtual network fault diagnosis method and device, relates to the technical field of cloud computing and computer networks, and comprises the following steps: acquiring failure request metadata associated with a network fault; constructing at least one probe data packet according to the failure request metadata, and setting a diagnosis mark in the probe data packet; injecting the probe data packet carrying the diagnosis mark into a network from a network position corresponding to source network position information; intercepting the probe data packet carrying the diagnosis mark at at least one forwarding device on the way of the probe data packet, and generating corresponding event records; aggregating the event records with the same probe identifier, and reconstructing an actual forwarding path of the probe data packet according to sequence indication information; and determining a fault type and a fault position of the network fault based on the event records in the reconstructed actual forwarding path. Through the method provided by the application, on-demand triggering, non-intrusive and port-level-precision virtual network fault diagnosis are realized.
Owner:TSINGHUA UNIVERSITY

Flat network construction method and device, electronic equipment and storage medium

The application provides a flat network construction method and device, electronic equipment and storage medium. The method is applied to a container management system, and the container management system comprises a container control module and a container construction module. The method comprises the following steps: acquiring a virtual network card component through the container control module; confirming a storage address of the virtual network card component by using the container control module; constructing a container group through the container construction module, and confirming a network interface of a flat network corresponding to the container group; and adding the storage address to a configuration file of the container group through the network interface by using the container construction module, so as to complete construction of the flat network. The application completes construction of a flat network of a container group without deleting an original network card of the container group, so that the container group realizes direct connection and intercommunication of a network in a scheduling framework through a network interface of the flat network.
Owner:CHINA LIFE INSURANCE CO LTD

Distributed lock management message transmission method and device, and double-node server

The present specification provides a distributed lock management message transmission method and device and a two-node server. The method comprises: establishing a connection with a cross-node in a two-node server by using a non-transparent bridge (NTB) virtual network card, the NTB virtual network card being a network card virtually formed by an NTB, and the connection being based on a PCIe channel; and transmitting a distributed lock manager (DLM) message to the cross-node by using the NTB virtual network card through the connection.
Owner:NEW H3C CLOUD TECH CO LTD

Utilizing virtualization to isolate applications while providing API access

Utilizing virtualization to isolate applications while providing API access is implemented by validating an application package for execution of an application in a vehicle computing environment, creating a virtualized environment in the vehicle computing environment, the virtualized environment dedicated to execution of the application, connecting, to a private virtual network unique to the application, the virtualized environment and at least one vehicle service API executed in a native environment of the vehicle computing environment, and deploying the application package into the virtualized environment.
Owner:TOYOTA JIDOSHA KK

An information processing method and apparatus, a network device, and a storage medium

Embodiments of the present application disclose an information processing method and device, network equipment and a storage medium. The method comprises: a network function virtualization orchestrator (NFVO) determining a first operation to be performed based on a first information record table and a second information record table; the first information record table is used to record first related information of each policy created in a resource pool and association relationship information of each policy and a corresponding network element instance; the second information record table is used to record second related information of each network element instance in the resource pool; the first operation is used to manage the association relationship of the policy and the corresponding network element instance of the policy in the resource pool; the first information record table is generated based on an obtained policy file, and the second information record table is generated based on a change operation of the network element instance; a first type of configuration parameter corresponding to the first operation is sent to a virtual network function manager (VNFM) through a first type of interface corresponding to the first operation; wherein the first type of configuration parameter is used for the VNFM to perform the first operation.
Owner:CHINA MOBILE COMM LTD RES INST +1

A multicast traffic forwarding apparatus, method, device and medium

ActiveCN119052196BNetworks interconnectionEngineeringConnection management
The present application relates to the technical field of cloud platform, and particularly relates to a multicast traffic forwarding device, method, equipment and medium, a multicast control module communicates with a second virtual network card and a fourth virtual network card respectively, and is used for configuring a bridge establishment and a connection management process to a first forwarding virtual machine and a second forwarding virtual machine, so as to establish a communication tunnel. The first forwarding virtual machine transmits multicast traffic based on a first virtual network card and a first device deployed in a virtual private cloud network. The communication tunnel is used to realize the transmission of multicast traffic between the first forwarding virtual machine and the second forwarding virtual machine. The second forwarding virtual machine realizes the transmission of multicast traffic between the first forwarding virtual machine through the communication tunnel; and transmits multicast traffic based on a third virtual network card and a cloud platform core switch. The cloud platform core switch transmits multicast traffic with a second device outside the cloud platform. Two forwarding virtual machines are deployed on the cloud platform, and the routing and forwarding of multicast traffic in the cloud and outside the cloud are realized.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Simulation network kubernetes controller for dynamic network topology partitioning

PendingCN122268767ATransmissionDynamic network topologyEngineering
A simulated network Kubernetes controller for dynamic network topology partitioning includes: a DQN-based network topology partitioning module, a Pod scheduling module, and a rolling upgrade-based Pod migration module. The DQN-based network topology partitioning module performs graph partitioning based on user-submitted network topology information to obtain the distribution of virtual network components on physical machines. The Pod scheduling module performs scheduling calculations based on the virtual network component information that needs to be modified during algorithm verification to obtain the results of the virtual network components to be migrated. The Pod migration module performs Pod migration based on the calculated list of virtual network components to obtain the modified network topology distribution. This invention implements a Kubernetes controller based on the KubeBuilder framework for actual scheduling. It is used to achieve overall system load balancing when verifying network resource scheduling algorithms in large-scale dynamic topology scenarios on a cloud-native simulated network platform.
Owner:SHANGHAI JIAOTONG UNIV

Cat.1 module-based virtual private network and networking method thereof

ActiveCN121056210BEnd-to-end encryptionPrivate network
This invention discloses a virtual private network (VPN) based on Cat.1 modules and its networking method, aiming to solve the technical bottlenecks of existing LTE VPN solutions, such as high cost, narrow equipment compatibility, insufficient security, and poor deployment flexibility. This invention deeply integrates L2TP and VPN protocol stacks into the Cat.1 module hardware and firmware, constructing a "VPN server - Cat.1 module - client device" networking architecture. First, system initialization is completed, and L2TP dialing parameters are set through either batch configuration using AT commands or visual configuration via a web page. Then, the Cat.1 module actively initiates dialing to the VPN server, establishing an end-to-end encrypted L2TP tunnel through dual verification of device IMEI and user identity. Finally, relying on interfaces such as USB, WIFI, and RJ45, the virtual network is shared with various types of clients, including embedded devices and sensors. This invention does not rely on operator private network APN resources, reduces equipment hardware costs, shortens deployment cycles, and improves the economy, adaptability, and security of virtual networking.
Owner:ZHEJIANG LIERDA INTERNET OF THINGS TECH

Data transmission method and apparatus, electronic device, and storage medium

ActiveCN118474058Bavoid incompleteRealize data transmissionTransmissionData packTransmission technology
Embodiments of the present application provide a data transmission method and device, electronic equipment and storage medium, belonging to the technical field of data transmission. The method is applied to a sending end, and the sending end includes a virtual network card sending layer and an application sending layer. The method includes: obtaining candidate sending data of the application sending layer; the candidate sending data includes a candidate transmission mode and candidate transmission data; if the candidate transmission mode is a transparent transmission mode, the candidate transmission data is formatted and encapsulated to obtain formatted transmission data; the formatted transmission data is written into a candidate virtual network card sending buffer of the virtual network card sending layer through a candidate application sending buffer, a write pointer and a candidate write address of the application sending layer to obtain a selected virtual network card sending buffer; and data of the selected virtual network card sending buffer is sent to a receiving end through a virtual network card interface, so that the receiving end receives data sent by the sending end to obtain application layer receiving data. The embodiments of the present application can ensure the integrity of data in the data transmission process.
Owner:广州视晟科技有限公司

Broadcast, Unknown Unicast, and Link-Local Multicast Traffic Support Using Locator / Identifier Separation Protocol and Protocol Independent Multicast-Source-Specific Multicast

Systems, devices, and methods support network traffic, for example, Broadcast, unknown Unicast, and link-local Multicast (BUM) traffic, in an overlay by utilizing Protocol Independent Multicast (PIM)-Source-Specific Multicast (SSM) in an underlay, while removing dependency on PIM-Any Source Multicast (ASM). A mapping system receives a mapping registration message and / or a mapping request message of a candidate device configured with a virtual network instance, for example, a Layer 2 Virtual Network Instance (L2VNI) implemented with layer 2 flooding. In response to receiving the mapping registration message, the mapping system transmits a mapping notification message to one or more member devices of an underlay group associated with the L2VNI. The mapping notification message indicates that the candidate device has joined the underlay group. In response to receiving the mapping request message, the mapping system transmits, to the candidate device, a list indicating that the member device(s) intends to transmit the network traffic.
Owner:CISCO TECHNOLOGY INC

Graphical interface content acquisition method, apparatus, device, medium, and product

The application provides a method, device, equipment, medium and product for acquiring graphical interface content. The method comprises the following steps: acquiring a graphical job script sent by a management node; determining whether a computing node supports a virtual network computing (VNC) service according to installation package information and configuration file information corresponding to the computing node; starting the VNC service if the computing node supports the VNC service; executing the graphical job script to obtain a graphical job result, and performing rendering processing on the graphical job result to obtain graphical interface content; and sending the graphical interface content to a terminal device through the VNC service, so that the terminal device displays the graphical interface content through a VNC client. The method provided by the application improves the acquisition rate of the graphical interface content.
Owner:DAWNING INT INFORMATION IND CO LTD

Time synchronization system and method based on virtual-real joint simulation of TDMA system wireless network

ActiveCN116405104BImprove time synchronization accuracyReduce transmission delayTime informationNetworked system
The application provides a time synchronization system and method based on a TDMA system wireless network virtual-real joint simulation, which comprises a physical network and a virtual network simulation system, time synchronization between multiple physical nodes of the physical network is completed through radio frequency signals, and wireless communication of the TDMA system is adopted; one of the physical nodes is a gateway node, the gateway node is provided with a first interface and a second interface, the first interface is used for generating a time slot pulse signal, and the second interface is used for generating a time slot numerical signal; the virtual network simulation system communicates with the physical network, and the virtual physical network system is provided with a third interface for receiving the time slot pulse signal and a fourth interface for receiving the time slot numerical signal; wherein the time slot pulse signal carries synchronization interrupt information, the time slot numerical signal carries time slot time information, and the virtual network simulation system realizes time synchronization with the physical network through the time slot pulse signal and the time slot numerical signal. The application has high time synchronization precision and low resource consumption.
Owner:THE 20TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORP

Network slice registrar virtual network function

A method of communicating over a plurality of network slices concurrently. The method comprises building a distributed ledger by a network slice registrar function (NSRF) application executing on a computer, where the distributed ledger records an association between a first network slice allocated to a user equipment (UE) and a second network slice allocated to the UE, providing information about the association of the UE to the first network slice and the second network slice by the NSRF application to a network slice selector function (NSSF), establishing a first communication link between the UE and a first call end point via the first network slice by a first user plane function (UPF) and establishing a second communication link between the UE and a second call end point via the second network slice by a second UPF based on the information provided by the NSRF application to the NSSF.
Owner:T MOBILE INNOVATIONS LLC