Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

688 results about "Virtual network" patented technology

A virtual network is a computer network that consists, at least in part, of virtual network links. A virtual network link is a link that does not consist of a physical connection between two computing devices but is implemented using methods of network virtualization. The two most common forms of network virtualization are protocol-based virtual networks, and virtual networks that are based on virtual devices. In practice, both forms can be used in conjunction. Virtual LANs are logical local area networks based on physical LANs. A VLAN can be created by partitioning a physical LAN into multiple logical LANs using a VLAN ID. Alternatively, several physical LANs can function as a single logical LAN. The partitioned network can be on a single router, or multiple VLAN's can be on multiple routers just as multiple physical LAN's would be. A VLAN can be on a VPN. A virtual private network consists of multiple remote end-points joined by some sort of tunnel over another network, usually a third party network. Two such end points constitute a 'Point to Point Virtual Private Network'. Connecting more than two end points by putting in place a mesh of tunnels creates a 'Multipoint VPN'.

System and Method for Improving Cybersecurity of a Network

A system and method for mitigating cyber-attacks against a target network comprising interconnected note that is implemented by Open Systems Interconnection (OSI) layers monitors the target network for detecting vulnerabilities across one or more OIS layers. a virtual network comprising a virtualized representation of the target network where the virtual network includes one or more virtual nodes that are annotated with identified vulnerabilities of one or more corresponding nods of the target network. A reference database can be configured to store records of known cyber-attacks and their corresponding mitigations where cyber-attacks on the virtual network are simulated based on records of known cyber-attacks and successful cyber-attacks. An AI engine can be configured to generate one or more mitigation actions based on simulation of the cyber-attacks before implementing the one or more mitigation actions to the target network.
Owner:THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SEC OF HOMELAND SECURITY

Integrated gateway service

In general, techniques are described for a SDN architecture system that implements an integrated gateway service. In an example, network controller comprises processing circuitry and memory and is configured to: configure a virtual network in a cluster of nodes of a compute infrastructure, the cluster of nodes managed in part by the network controller; receive a manifest for a gateway service instance that abstracts a transit gateway resource configurable in a plurality of different types of compute infrastructures, wherein the manifest specifies an intended state of a transit gateway object of the gateway service instance; and reconcile the intended state of the transit gateway object for the gateway service instance by sending configuration data, generated based on the transit gateway object, to an interface for the compute infrastructure to configure a transit gateway to forward network packets between a compute infrastructure node of the compute infrastructure and the virtual network.
Owner:JUNIPER NETWORKS INC

Virtual network card implementation method based on shared memory, electronic equipment and medium

The invention relates to a virtual network card implementation method based on a shared memory, an electronic device and a medium, which take the shared memory as a core communication carrier, construct a low-overhead data transmission basis, and efficiently implement a producer-consumer model in combination with the cyclic storage characteristic of an annular buffer area and the lock-free synchronization mechanism of atomic operation. Through partition design and atomic operation of the annular buffer area, continuity and exclusiveness of data access are guaranteed, and performance loss of a traditional lock mechanism is avoided; meanwhile, on the basis of the IPI interrupt capacity of the universal interrupt controller, cross-core synchronous notification is achieved through MPIDR accurate routing, interrupt wakeup waiting tasks are triggered through hardware, low-efficiency polling is replaced, and high-frequency data interaction scenes such as virtual network equipment are perfectly adapted. Compared with the prior art, the method has the advantages of efficient, safe and reliable network communication and the like.
Owner:CASCO SIGNAL LTD

Custom configuration of cloud-based multi-network-segment gateways

In response to a programmatic request, configuration information representing a multi-network-segment gateway established on behalf of a customer is stored at a networking service. In response to another programmatic request, a communication session is established between a route signaling node of the gateway and a routing information source located at a customer premise. In response to additional programmatic input, the networking service stores an indication that the gateway is to be used to transfer packets between a cloud-side virtual network and a customer-side virtual network. The routing information exchanged in the session pertains to the cloud-side and customer-side virtual network, and is used to transfer data packets between the two virtual networks.
Owner:AMAZON TECH INC

Distributed Source Network Address Translation (SNAT) Enabled LEAF

PendingUS20250323866A1TransmissionDistributed sourceDistributed Computing Environment
Various methods and processing systems for the effective management of network traffic and facilitating data forwarding within distributed computing environments. Network components may be configured to amalgamate the Border Gateway Protocol (BGP) with Source Network Address Translation (SNAT) or network address port translation (NAPT) technologies to facilitate dynamic notification of network address accessibility and use port index identifiers to augment the precision and resilience of routing. A distributed SNAT / NAPT virtual network function (VNF) or cloud-native network function (CNF) may collaborate with LEAF switches or server aggregation devices to refine data transmission via adaptable address mapping and forwarding and enhance network scalability and resilience.
Owner:CHARTER COMM OPERATING LLC

Secure unidirectional network access using consumer-configured limited-access endpoints

ActiveUS20250310300A1Data switching networksSecuring communicationUnidirectional networkCloud computing
A virtual gateway for transmission of packets from a service provider virtual network to a service consumer virtual network of a user is established at a cloud computing environment. A limited-access endpoint is created in the service consumer virtual network, with security settings provided by the user which enable transmission of packets from a service implemented at the service provider virtual network to resources within the service consumer virtual network. A packet directed to a resource in the service consumer virtual network is received at the gateway from the service. If the security settings permit delivery of packets via the endpoint to the resource, the packet is transmitted to the resource.
Owner:AMAZON TECH INC

Container-based parallel computing system

A container-based parallel computing system for executing high-performance computing (HPC) applications. The system leverages container technology to package the applications executed at the nodes in a cluster. To load and execute a job in the parallel computing system, containers are deployed in a cluster that include all the application resources and configuration information that the particular HPC application needs to execute. An event-driven batch scheduler may be used to dynamically allocate resources for executing multi-node jobs in the container-based parallel computing system, handling the coordination of resource allocation for the customer. The scheduler insures that jobs begin executing as fast as possible, and handles failure conditions such as partial scaling. Virtual network interfaces are attached to the containers that allow the containers to connect to and communicate with other containers in the cluster directly through the network interfaces of host machines using IP addresses provided by the virtual network interfaces.
Owner:AMAZON TECH INC

Power Internet of Things service scheduling method and device based on SDN and NFV, and medium

The invention discloses an electric power Internet of Things service scheduling method and device based on an SDN and an NFV, and a medium, and belongs to the field of virtual networks, and the method comprises the steps: receiving an electric power Internet of Things service request issued by a cloud network cooperative management platform through an SDN controller, and matching a corresponding VNF combination for the electric power Internet of Things service request; based on the control domain network topology structure, performing first path planning for the VNF combination through a weighted shortest path algorithm to obtain a first deployment path; constructing an optimization objective function of the first deployment path based on the dynamically adjusted time delay weight factor and load weight factor, and performing global optimization on the first deployment path based on the optimization objective function to obtain a second deployment path; and generating a deployment instruction based on the second deployment path, and issuing the deployment instruction to each corresponding physical node through the NFVO to perform VNF instance deployment so as to complete power Internet of Things service scheduling. Therefore, by implementing the method and the system, accurate scheduling of various services of the power internet of things can be completed according to the time delay requirement.
Owner:POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD

Method and apparatus for traffic scheduling implementation, device, storage medium, and program product

The present disclosure provides a method of traffic scheduling implementation, including: receiving a domain name resolution request sent by a first business application on a first terminal device, and performing domain name resolution on the domain name resolution request to determine a to-be-resolved domain name; if the to-be-resolved domain name is a target domain name, determining, from a preset network segment, a first virtual network address corresponding to the to-be-resolved domain name, and using the first virtual network address as a first traffic destination address corresponding to the to-be-resolved domain name, where the preset network segment includes a plurality of virtual network addresses; and sending the first traffic destination address to the first business application on the first terminal device, to cause the first business application to perform data transmission based on the first traffic destination address.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Quarantine control network in a 5G RAN for coordinated multi-layer resiliency of network slice resources

A system is disclosed for quarantining and recovery of a network after an outage or in advance of a potential outage. Unaffected network slices are isolated and recovery is initiated by quarantine physical and virtual network functions. An AI model is trained based on recent events detected by sensors disposed throughout the network to determine whether to quarantine network slices, move services to unaffected network slices, or initiate recovery. Once the network is stabilized, resources that are specifically allocated for recovery and services are released and the traffic moved back to the recovered network slices.
Owner:INTEL CORP

Controller-based traffic filtering and address modification

In communication with components of a cloud platform, namely a software-defined network constructed to overlay at least one public cloud network, a controller features a virtual processor and a data store. The data store includes network address translation (NAT) processing logic configured to determine whether a control plane message from tenant resources is associated with a network address overlapping condition, which represents a first network address included in the control plane message overlaps a network address range relied upon by either (a) at least one of the components of the cloud platform or (b) a component associated with other tenant resources. The NAT processing logic is further configured to alter routing data stores that maintain routing information for each of the components of the cloud platform to substitute the first network address with a first virtual network address for subsequent data message routing.
Owner:AVIATRIX SYSTEMS INC

Systems and methods for implementing a zero trust model in connection with 5G networks

Methods and systems are provided for assigning one or more Virtual Network Function (VNF) instances, or slices, to devices, and for monitoring each change of state associated with the slices. Embodiments include applying an Advanced Security Control (ASC) protocol to verify devices for each request for access to a slice, to establish a zero trust measurement with respect to a network, such as a 5G network. In embodiments, a blockchain is associated with each slice and stored in a distributed ledger, for example to allow rapid access to network slice and device information if a slice will be re-instantiated.
Owner:T MOBILE INNOVATIONS LLC

Large model authentication and authorization system and method based on remote networking

The invention relates to the technical field of digital data processing, and discloses a large model authentication and authorization system and method based on remote networking, and the method comprises the steps: analyzing a networking request, obtaining an ID, determining the legitimacy of a large model of remote networking in a terminal lightweight agent rule, and carrying out the authentication and authorization of the large model. An encrypted virtual network tunnel is established between a user / application end and a large model service providing end, and all calling requests are transmitted through the tunnel, so that the leakage risk probability of an API transmission path is reduced, an attacker is prevented from abusing a model service, and economic loss or data leakage is reduced. Autonomous management of the user identity is realized by using the ID, judging the type of the ID, decentralizing the identity (DID) or similar technologies, and the storage and verification of an authorization strategy are carried out by combining a distributed account book technology.
Owner:HANGZHOU MEITENG TECH CO LTD

Unmanned aerial vehicle base station trajectory and virtual network function collaborative optimization method based on model predictive control

The invention discloses an unmanned aerial vehicle base station trajectory and virtual network function collaborative optimization method based on model prediction control, and belongs to the field of unmanned aerial vehicle mobile network and service quality optimization. Firstly, a utility-driven ABS track and service quality coupling framework is provided, the relationship between the ABS position and the user service quality is quantified, and a decision basis is provided for track optimization. A rapid evaluation module for online VNF arrangement and resource allocation is introduced, service delays under different deployment strategies are accurately estimated, and key input is provided for an RDT model and trajectory optimization. And a closed-loop adaptive optimization and cooperation mechanism is constructed: through an ABS trajectory adaptive optimization module based on model prediction control, the unmanned aerial vehicle can prospectively plan and adjust the flight trajectory so as to maximize the average communication rate of the user. For a multi-ABS scene, a distributed model predictive control and conflict resolution mechanism based on a virtual token is provided, so that a plurality of ABSs can effectively avoid conflicts and carry out cooperative services while optimizing own service quality.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Network Service Stitching for Cloud Native Network Functions and Virtual Network Functions

Systems and methods for generating and configuring network service packages includes multiple clusters for executing cloud native network functions and virtual network functions. A method includes receiving a request to generate a network service package comprising a first cluster and a second cluster. The method includes generating a dependency within the network service package such that the second cluster depends upon the first cluster. The method includes automatically configuring a first router associated with the first cluster and a second router associated with the second router such that the first router and the second router can route traffic to each other.
Owner:RAKUTEN SYMPHONY INC

Method for sharing data network and electronic device

A method for sharing a data network and an electronic device are provided. The method includes: converting a first data packet satisfied with a first protocol format and sent by a first virtual network card into the first data packet satisfied with a second protocol format based on a preset application-layer protocol; sending the first data packet satisfied with the second protocol format to a second terminal through a Bluetooth network, and receiving a second data packet satisfied with the second protocol format and returned by the second terminal; and converting the second data packet satisfied with the second protocol format into the second data packet satisfied with the first protocol format, and transmitting the second data packet satisfied with the first protocol format to the first virtual network card, based on the preset application-layer protocol.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Packet flow in a cloud infrastructure based on cached and non-cached configuration information

ActiveUS12592877B2Networks interconnectionData packSubstrate network
Techniques for managing the distribution of configuration information that supports the flow of packets in a cloud environment are described. In an example, a virtual network interface card (VNIC) hosted on a network virtualization device NVD receives a first packet from a compute instance associated with the VNIC. The VNIC determines that flow information to send the first packet on a virtual network is unavailable from a memory of the NVD. The VNIC sends, via the NVD, the first packet to a network interface service, where the network interface service maintains configuration information to send packets on the substrate network and is configured to send the first packet on the substrate network based on the configuration information. The NVD receives the flow information from the network interface service, where the flow information is a subset of the configuration information. The NVD stores the flow information in the memory.
Owner:ORACLE INT CORP

ServiceMesh-based multi-cluster hot debugging method

The invention discloses a multi-cluster hot debugging method based on Service Mesh, and belongs to the technical field of cloud native software development. Through a debugging instruction, a multi-cluster intelligent routing gateway establishes a unified and logically isolated debugging session and a virtual network environment for a developer terminal and a plurality of target Kubernetes clusters; the gateway dynamically allocates a local port for a debugging task from a global resource pool, and instructs a target cluster to create a Pod; the gateway serves as a center node, performs cross-cluster routing conflict detection, generates a globally consistent dynamic routing rule and issues the dynamic routing rule to a target cluster; and finally, forwarding the online traffic matched with the rule to an appointed port of a developer local machine through a proxy Pod and a gateway. Through a centralized intelligent coordination architecture, various conflicts in a multi-cluster environment are fundamentally avoided, and the debugging efficiency, stability and automation level are remarkably improved.
Owner:SHANGHAI ZHENYUN INFORMATION TECH CO LTD

Method and system for managing CPU power states for heterogeneous virtualised workloads

A method manages virtual network function components (VNFCs) in a compute infrastructure of a virtualized environment. The method includes performing, by an orchestrator system of the virtualized environment, power state-based resource pooling in the compute infrastructure based on central processing unit (CPU) power state management policies; and scheduling, by a scheduler, virtual CPUs (vCPUs) of the VNFCs on physical cores of appropriate resource pools whose CPU power states match with power profile characteristics of the vCPUs.
Owner:NEC LAB EURO GMBH

Method for realizing point-to-point communication between nodes in mobile cellular network

The invention discloses a method for realizing point-to-point communication between nodes in a mobile cellular network. The method specifically comprises the following steps of: creating a virtual network card on each terminal device, distributing a virtual IP (Internet Protocol) address, and establishing a service gateway for grid topology management and data forwarding. Each node is connected with the service gateway through a network to form a grid topological structure, the nodes send data packets to the service gateway through the virtual network card, the service gateway searches the corresponding node connection according to the target virtual IP address of the data packets and forwards the data packets, and the target node receives the data packets and transmits the data packets to the local network protocol stack for processing through the virtual network card. The invention further provides an identity authentication mechanism based on the secret key and the certificate, and communication safety is guaranteed. The virtual private network constructed by the scheme of the invention breaks through the limitation that nodes in a cellular network only have dynamic virtual IPs and do not have public network IPs, improves the communication efficiency, reduces the energy consumption, and enhances the network topology adaptability.
Owner:HANGZHOU LIANCHENG DIGITAL TECH CO LTD

Firmware upgrading system and method and electronic equipment

The invention discloses a firmware upgrading system and method and electronic equipment, and relates to the technical field of computers, a target interface in a firmware upgrading end is configured as virtual network equipment, so that a host end identifies the target interface as network equipment such as a network card, and the host end upgrades the firmware according to a network address of the virtual network equipment. A target communication interface is loaded and configured locally, the target communication interface is connected with a virtual network device through a direct connection communication link, and then a firmware upgrading file is sent to the virtual network device through the target communication interface and the direct connection communication link. The transmission of the firmware upgrading file between the host end and the firmware upgrading end does not need to be forwarded by other nodes, so that the reliability of the transmission process is ensured, and the maintainability of the server is improved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

NFV infrastructure system based on extended container infrastructure

An NFV infrastructure system based on a container infrastructure includes a master node configured to distribute and manage a virtual network function (VNF) which is an individual network function according to a request by an administrator; and a worker node of an extended container infrastructure structure which allocates the distributed VNF to a VM based infrastructure or a container based infrastructure, wherein a resource model between the master node and the worker node is a resource model which is the same as a resource model according to the request by the administrator.
Owner:FOUND OF SOONGSIL UNIV IND COOP

System and method for a global virtual network

Systems and methods for connecting devices via a virtual global network are disclosed. In one embodiment the network system may comprise a first device in communication with a first endpoint device and a second device in communication with a second endpoint device. The first and second devices may be connected with a communication path. The communication path may comprise one or more intermediate tunnels connecting each endpoint device to one or more intermediate access point servers and one or more control servers.
Owner:UMBRA TECH LTD +1

Outbound private link framework

To provide outbound private link support for a multi-tenant data system with tenant isolation, a separate, dedicated virtual network is provided, referred to as private link (PL) virtual network. The PL virtual network may host a plurality of host interface endpoints and resource endpoints. A core virtual network and the PL virtual network may be peered together to work in conjunction. The private endpoints in the PL virtual network may then be connected to external systems using a private link without exposure to the public internet.
Owner:SNOWFLAKE INC

Ethernet virtual private network debugging using intent graph data

A system includes a storage device configured to store intent graph data associated with a plurality of virtual networks and a plurality of network devices and processing circuitry in communication with the storage device. The intent graph data identifies a subset of the plurality of virtual networks associated with each network device. The processing circuitry is configured to determine whether the intent graph data indicates a first network device and a second network device are configured for a common virtual network, in response to determining that the graph indicates the first network device and the second network device are configured for the common virtual network, determine a network anomaly based on a comparison of first endpoint information obtained from the first network device and second endpoint information obtained from the second network device, and output an indication of the network anomaly.
Owner:JUNIPER NETWORKS INC

Data plane separation in networks to reuse virtual network addresses

Systems and methods herein are for one or more processing units that can communicate in a network using a subnet manager (SM) that includes a mapping of one virtual network address to two or more physical ports, where the one virtual network address may be associated with different switches of different data planes, and where data may be communicated concurrently and separately using the one virtual network address and using the two or more physical ports.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Geological disaster intelligent monitoring and early warning method and system based on multi-source data fusion

The invention relates to the technical field of remote monitoring, and discloses a geological disaster intelligent monitoring and early warning method and system based on multi-source data fusion, and the method comprises the steps: building a three-dimensional monitoring sensor network of geological disaster hidden danger points, so as to collect the multi-source heterogeneous monitoring data of the geological disaster hidden danger points, the multi-level features of the multi-source heterogeneous monitoring data are extracted, the multi-level features comprise earth surface deformation features, deep mechanical features, environmental response features and visual representation features, and disaster feature fusion vectors of the geological disaster hidden danger points are generated; constructing a causal directed graph of the multi-source heterogeneous monitoring data to generate causal contribution degree vectors of the geological disaster hidden danger points; analyzing the disaster instability probability of the geological disaster hidden danger point by using a preset reality-virtual network; and in combination with the disaster instability probability, analyzing the comprehensive early warning level of the geological disaster hidden danger point. According to the invention, the reliability of early warning of geological disaster hidden danger points can be improved.
Owner:CSCEC GEOTECHNICAL ENG (SHENZHEN) CO LTD

Layer-2 networking storm control in a virtualized cloud environment

Techniques are described for communications in an L2 virtual network. In an example, the L2 virtual network includes a plurality of L2 compute instances hosted on a set of host machines and a plurality of L2 virtual network interfaces and L2 virtual switches hosted on a set of network virtualization devices. An L2 virtual network interface emulates an L2 port of the L2 virtual network. Storm control information applicable to the L2 port is sent to a network virtualization device that hosts the L2 virtual network interface.
Owner:ORACLE INT CORP

Port mapping method and device for sharing elastic public network IP by multiple private clouds

The embodiment of the invention relates to the technical field of virtual network resource scheduling, and provides a port mapping method and device for multiple private clouds to share an elastic public network IP, and the method comprises the steps: creating multiple private clouds in a Cloud platform, and configuring and sharing one elastic public network IP for the multiple private clouds; an ARP pickup flow table of the elastic public network IP is configured on a gateway node of the elastic public network IP through a breip network bridge of the Cloud pods platform, the ARP pickup flow table is used for guiding a data center network to guide the flow accessing the elastic public network IP to the gateway node of the elastic public network IP, the gateway node is a node deployed in a centralized manner on the Cloud pods platform, and the flow of the elastic public network IP is guided by the data center network to the gateway node of the elastic public network IP. The public network flow processing module is used for uniformly processing public network flow of all private clouds sharing an elastic public network IP; and configuring a network address translation rule on the breip network bridge, and mapping a specified port of the elastic public network IP to an intranet IP of the target virtual machine in the corresponding private cloud and a port of the corresponding service. An elastic public network IP is shared in a virtual machine service scene of multiple tenants and multiple private clouds.
Owner:ZHONGKE ZIDONG TAICHU (BEIJING) TECH CO LTD