Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

88 results about "Virtual switch" patented technology

A virtual switch is a software program that allows one virtual machine (VM) to communicate with another.

Configuration method and device of access control list, electronic equipment and storage medium

The invention provides an access control list configuration method and device, electronic equipment and a storage medium, and relates to the technical field of servers, and the method comprises the steps: collecting subnet information in a target containerization cluster, a configured access control list rule and security threat features in network traffic; the information is subjected to fusion analysis based on a predefined security policy so as to generate an access control list rule set containing different priorities, and then the rules are synchronized to a cluster virtual switch kernel according to the priorities so as to realize hierarchical control and dynamic protection of network traffic. The problems that a large-scale dynamic network environment is difficult to deal with, the automation level is low and malicious traffic cannot be efficiently intercepted due to the fact that manual configuration and static rule maintenance are relied on and deep integration of a containerized cluster network structure is lacked can be solved. The technical effects of improving the automation level of containerized cluster network management, enhancing the adaptability to a dynamic network environment, and realizing efficient interception of malicious traffic to guarantee network security are achieved.
Owner:JINAN INSPUR DATA TECH CO LTD

Network load balancing method, computer program product, equipment and medium

The invention discloses a network load balancing method, a computer program product, equipment and a medium, relates to the technical field of data centers, is applied to a virtual switch of a data center, and obtains to-be-sent data; packaging the to-be-sent data to obtain initial packaged data; in the quintuple, determining an item to be transformed; in the initial encapsulation data, transforming a value corresponding to a to-be-transformed item in the outer layer message to obtain target encapsulation data; performing hash operation based on the quintuple of the target encapsulation data to obtain a hash value; and transmitting the target encapsulation data according to a transmission path corresponding to the hash value. The method and the device have the beneficial effects that different transmission paths can be used for transmitting the target encapsulation data, and finally, different to-be-sent data of the same stream are transmitted through different transmission paths, so that the occupation of a single transmission path by the data of the same stream is avoided, load balancing between the transmission paths is realized, and the transmission efficiency is improved. The network load balancing capability of the data center is improved; and the universality is good.
Owner:JINAN INSPUR DATA TECH CO LTD +1

Layer-2 networking storm control in a virtualized cloud environment

Techniques are described for communications in an L2 virtual network. In an example, the L2 virtual network includes a plurality of L2 compute instances hosted on a set of host machines and a plurality of L2 virtual network interfaces and L2 virtual switches hosted on a set of network virtualization devices. An L2 virtual network interface emulates an L2 port of the L2 virtual network. Storm control information applicable to the L2 port is sent to a network virtualization device that hosts the L2 virtual network interface.
Owner:ORACLE INT CORP

A software defined network system

The application discloses a software defined network system, which comprises a BGP proxy component, an SDN controller, a plurality of gateway devices not supporting a BGP protocol and computer nodes; the BGP proxy component is used for establishing a BGP session with the SDN controller and announcing routing information of the plurality of gateway devices to the SDN controller through the BGP session; the SDN controller is used for generating node-side data plane configuration information based on the received routing information and delivering the node-side data plane configuration information to the computer nodes; and the computer nodes are used for configuring a forwarding table and / or tunnel encapsulation parameters of a virtual switch on the nodes according to the received node-side data plane configuration information. The application reduces the complexity of networking.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Power supply probe with polarity safeguard

A system and method provides for safeguarded selection of a polarity for selected application of power or ground to a test circuit via a circuit tester test probe. A positive polarity selection switch is aligned with a negative polarity selection switch on a probe surface. A virtual switch indicia is shown on a probe display with an actuation axis of the virtual switch oriented to correspond to relative alignment of the polarity switches. Pressing the positive polarity switch places the virtual switch in a first position indicating a positive probe polarity selection and pressing the negative polarity switch places the virtual switch in a second position indicating a negative probe polarity selection. Additional polarity selection indicia are generated to reinforce user recognition of a selected polarity to avoid circuit or probe damage.
Owner:INNOVA ELECTRONICS CORP

Cloud tenant bearing scale optimization method and device, equipment, medium and product

The invention relates to the technical field of cloud computing, in particular to a cloud tenant bearing scale optimization method and device, equipment, a medium and a product, and the method comprises the steps: recognizing a sender and an access purpose of an access request, and determining a data flow direction corresponding to the access request; in response to the condition that the sender is the virtual machine, address conversion and message encapsulation are performed on the access request through the virtual switch, and the encapsulated access request is sent to the cloud gateway; and in response to the fact that the sender is the Underlay network or the public network, the cloud gateway is determined based on the sender, the cloud gateway confirms the virtual private cloud based on the access purpose, the access request is subjected to message packaging, and the access request is sent to the virtual switch. According to the technical scheme of the invention, the original address translation is sunk to the virtual switches corresponding to the virtual private clouds from the cloud gateway for processing according to the data in the cloud-out direction and the cloud-in direction, so that the memory space occupied by the NAT table items can be released, the detailed routing capacity of the virtual machines is improved, and the expansion of the cloud tenant scale borne by the cloud data center is facilitated.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Packet processing method, device and storage medium

Embodiments of the present application provide a message processing method and device, and a storage medium. A virtual switch in a network device can obtain event notification information from the network device, and determine at least one data queue containing a to-be-sent message from data queues of the network device according to the event notification information. Then, the virtual switch can access the at least one data queue to obtain the to-be-sent message, and send the to-be-sent message to a destination address. In this implementation, the virtual switch only needs to access the data queue containing the to-be-sent message, and does not need to access all data queues one by one, which greatly reduces the processing delay of the message.
Owner:ALIBABA (CHINA) CO LTD

A gateway configuration method and apparatus

This application relates to the field of network communication technology, and in particular to a gateway configuration method and apparatus. The method is applied to an OVS virtual switch, and includes: receiving the MAC address of a newly created virtual machine and custom gateway information specified for the virtual machine from the controller; receiving a DHCP request message sent by a target virtual machine, and obtaining the MAC address information of the target virtual machine carried in a specified field of the DHCP request message; if it is determined that target custom gateway information corresponding to the MAC address of the target virtual machine is maintained locally, then sending the target custom gateway information in a DHCP response message to the target virtual machine, so that the target virtual machine performs gateway configuration based on the target custom gateway information.
Owner:NEW H3C TECH CO LTD

Message transmission method and apparatus

ActiveCN119835217BPathPingTelecommunications
This application discloses a message transmission method and apparatus. The method includes: receiving a first message at the tunnel port of a virtual switch, wherein the tunnel port corresponds to at least one target tunnel, the target tunnel corresponds to multiple transmission paths, and the transmission paths connect a target client and a service agent module; determining the target transmission direction of the first message based on the transmission direction tag information carried by the first message; and determining a target transmission path among the transmission paths based on the target transmission direction.
Owner:LENOVO (BEIJING) LTD

FAST NPAL (NETWORK PIPELINE ABSTRACTION LAYER) LINK RESTORING

Technologies for creating an optimized and accelerated network pipeline using a virtual switch and a Network Pipeline Abstraction Layer (NPAL) for rapid link recovery are described. The virtual switch can monitor the link availability of each of several links to a destination, where the multiple links are specified in an initial set of identifiers. The virtual switch can detect a link failure of the first of the multiple links. The NPAL can remove the first link identifier associated with the first link from the initial set of link identifiers to obtain a modified set of link identifiers. The NPAL can cause a routing table within the NPAL to be updated to remove the first link identifier.The acceleration hardware engine can process network traffic data using the network pipeline and distribute the network traffic data only to the remaining of the multiple links.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Microservice architecture-oriented network security detection method and device

The embodiment of the invention provides a micro-service architecture-oriented network security detection method and device. The method comprises the following steps of: respectively acquiring communication flow between virtual machines and a network activity track of a container through a virtual switch port mirror image and a log interface of a container platform; constructing a dynamic baseline model containing a legal communication matrix, a protocol white list and a traffic threshold; comparing the acquired data with the dynamic baseline model by adopting a real-time stream processing technology, and detecting an abnormal behavior of the container or the virtual machine; and executing response measures of different levels according to the seriousness of the abnormal behavior threat. According to the scheme, internal attack behaviors such as container escape and transverse penetration can be effectively identified and coped with.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Containers-Based Forensics for Persistent and Stateless Containers

Comprehensive systems and methods for conducting digital forensics and incident response in containerized computing environments. The system converts stateless containers into persistent containers to prevent automatic termination during forensic investigations. It quarantines the containers using virtual switches and firewalls, captures detailed forensic data including snapshots of all filesystem layers, kernel syscalls, and process data, and mirrors network traffic for secure analysis. The system retrieves logs and artifacts from current and previous nodes, correlates and compares this data using machine learning algorithms, and securely duplicates all artifacts to immutable storage. Automated orchestration ensures consistent execution of forensic processes, and the system reverts containers to their original stateless state post-investigation. A detailed audit log and secure archival of all forensic data are maintained for future reference or legal compliance. The invention addresses the unique challenges of securing and analyzing data in dynamic, distributed containerized environments.
Owner:BANK OF AMERICA CORP

Integrated communication system and method based on new generation communication private network

PendingCN122340165APrivate communicationTelecommunications link
This invention discloses an integrated communication system and method based on a next-generation private communication network. The system includes an access network unit, an internal core network unit, and a virtual switch, all deployed on the same hardware processing board and sharing the same operating system kernel. The access network unit establishes a connection with the external core network unit through a first communication interface to form an external communication link. The access network unit connects to the virtual switch through a pre-configured second communication interface, and the internal core network unit connects to the virtual switch through a pre-configured third communication interface. Data forwarding via the virtual switch forms an internal communication link between the access network unit and the internal core network unit. This communication system, firstly, reduces assembly costs and overall hardware costs by using a shared single board and kernel, improving the resource utilization of a single board and making network construction simpler and more efficient; secondly, the two links do not interfere with each other, ensuring the security of internal and external data transmission.
Owner:CHINA MOBILE GRP GUANGDONG CO LTD +2

Nested virtualization with enhanced network connectivity and hardware offloading

A method is disclosed for managing network communication in a virtual machine hosting computer system with nested child partitions. The method involves loading a network driver in a level-one child partition and creating a virtual switch within the level-one child partition. The virtual switch establishes a synthetic data path between a synthetic network adapter offered by a root partition and a network driver in a level-two child partition. A network interface controller (NIC) switch capability is exposed to the virtual switch, and a peripheral component interconnect express (PCIe) virtual function offered by the root partition is passed from the level-one child partition to the level-two child partition, enabling the level-two child partition to take advantage of the PCIe virtual function.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Virtual machine running monitoring method, monitoring system and monitoring device

ActiveCN115729668BImplement isolation functionimprove securityComputer hardwareMonitoring system
A virtual machine operation monitoring system comprises a central monitoring system, a cloud platform, a virtual switch and a virtual machine, the central monitoring system is connected with the cloud platform, the cloud platform is connected with the virtual switch, and the virtual switch is connected with the virtual machine; the central monitoring system sends an acquisition instruction to the cloud platform; the cloud platform forwards the acquisition instruction to the virtual switch; the virtual switch sends the acquisition instruction to the virtual machine; the virtual machine queries operation information based on the acquisition instruction and sends the operation information to the virtual switch; the virtual switch forwards the operation information to the cloud platform; the cloud platform forwards the operation information to the central monitoring system; and the central monitoring system monitors and manages the operation information. The virtual machine and the virtual switch are connected, the network isolation function is realized, and the safety of signal transmission is improved. The application also comprises a virtual machine operation monitoring method and a virtual machine operation monitoring device.
Owner:FULIAN PRESION ELECTRONICS (TIANJIN) CO LTD

A method for testing performance of a virtual switch facing a computing cluster

PendingCN122093288ADeployment controlIncrease reachTransmissionTest performancePathPing
This invention relates to the technical field of cloud computing, and in particular provides a performance testing method for virtual switches in computing clusters. The method includes creating virtual machines on multiple physical nodes of the computing cluster; deploying a transceiver on the virtual machine of at least one physical node, and a forwarding program on the virtual machines of the remaining physical nodes; controlling the transceiver and the forwarding program to perform a loop forwarding test, so that packets are forwarded by the forwarding program and then returned to the transceiver; recording performance parameters during the loop forwarding test for performance problem analysis. The forwarding program of this invention generates a corresponding forwarding mapping table based on the traffic path and model, and forwards packets according to the mapping table, forming multiple ring flows to achieve ring network forwarding capability across multiple nodes, thereby improving the coverage of virtual switch testing.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

A virtual switch deployment, testing method and apparatus

This application relates to a method and apparatus for deploying and testing virtual switches. The method includes: acquiring network topology information of an embedded platform to be deployed; wherein the network topology information includes a first binding relationship between virtual network ports and virtual switches, and a second binding relationship between the virtual switches and the Ethernet interfaces of the device under test; deploying virtual network ports in the software area and virtual switches in the logical area of ​​the embedded platform to be deployed, based on the number of virtual network ports and virtual switches in the network topology information; binding the deployed virtual network ports and virtual switches according to the first binding relationship, and binding the Ethernet interfaces and deployed virtual switches according to the second binding relationship. This method can reduce the space occupied by virtual switches.
Owner:CHENGDU CELIS TECH CO LTD

A control method and device of a vehicle, a vehicle body controller and a vehicle

Embodiments of the present application provide a vehicle control method and device, a vehicle body controller and a vehicle. The vehicle control method and device, the vehicle body controller and the vehicle realize the vehicle power-off and the turning-on of the hazard warning light at the same time by multiplexing the hazard warning light switch, which simplifies the operation process and improves the safety. On the other hand, the vehicle control method and device, the vehicle body controller and the vehicle do not need to add an additional power-off button, which reduces the production cost. At the same time, the vehicle control method and device, the vehicle body controller and the vehicle do not need to rely on the virtual switch in the vehicle display screen, thereby improving the reliability of the vehicle power-off. The vehicle control method comprises: detecting a pressing operation on the hazard warning light switch when the vehicle is in the ON gear; if the pressing time of the pressing operation is not less than a first set threshold or the pressing frequency of the pressing operation is not less than a second set threshold, obtaining the real-time vehicle speed; if the real-time vehicle speed represents that the vehicle is in a running state, controlling the low-voltage electrical equipment in the vehicle to power off, and controlling the hazard warning light to enter a working state.
Owner:SAIC GM WULING AUTOMOBILE CO LTD

Wireless network management system micro-service architecture and containerization implementation method

The invention discloses a micro-service architecture and containerization implementation method of a wireless network management system, which belongs to the field of network management, and comprises the following steps of: 1, carrying out containerization deployment on network functions: splitting the network functions into a plurality of micro-services and carrying out containerization deployment on the micro-services, unified abstraction and dynamic management are carried out on network resources by adopting a containerized virtual switch and a network controller; step 2, dynamic clustering management and dynamic network access and exit management: performing dynamic clustering management on a micro-service cluster, performing dynamic clustering on network nodes, and optimizing service deployment topology and communication paths according to node positions, link quality and load information; and carrying out dynamic network access and exit management on the nodes and the micro-service instances, so that the configuration, recovery and topology of network resources are adaptively adjusted. According to the invention, the elastic management, automatic deployment and dynamic capacity expansion and contraction capabilities of network functions in the cloud native environment are improved.
Owner:10TH RES INST OF CETC

Message processing method, programmable network card device, physical server, and storage medium

Embodiments of the present disclosure provide a message processing method, a programmable network card device, a physical server, and a storage medium. In the embodiments of the present disclosure, a virtual switch in software form is deployed on the programmable network card device, and a message parsing acceleration module and a hardware message queue providing message parsing service for the virtual switch are implemented on the programmable network card device based on programmable hardware. The embodiments of the present disclosure can greatly reduce the message parsing cost of the virtual switch and achieve high message forwarding performance. At the same time, all operations except parsing of the header information of the message are performed by the virtual switch in software form, which can meet flexible application requirements and ensure rapid iteration and evolution of the application requirements.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

Data processing method and device, program product and storage medium

The invention provides a data processing method and device, a program product and a storage medium. The method comprises the steps that first information of a first software flow table is obtained, a first stub object corresponding to the first software flow table is created according to the first information, the first software flow table is unloaded into a first hardware flow table, and the first stub object is maintained in a virtual switch in an SoC in a DPU; after the first stub object is created, the first software flow table is written into a first file, and the first file is a file in an SoC file system in a DPU.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Dpu-based network path alive detection method, worker node, device and medium

The application relates to a DPU-based network path alive detection method, a working node, equipment and a medium, in particular to the network processing technical field. The method is applied to a working node, the working node comprises a container group, a first container network interface (CNI) plug-in and a DPU network card comprising a virtual switch, and the working node further comprises a second CNI plug-in; the method comprises the following steps: when the container group is running, sending container group information and corresponding virtual function (VF) network port information to the second CNI plug-in through the first CNI plug-in; configuring a single-arm echo message according to the container group information through the second CNI plug-in, and sending the single-arm echo message through a VF network port indicated by the VF network port information, the destination address of the single-arm echo message being the same as the source address; in the case that the second CNI plug-in detects a response message of the single-arm echo message, it is determined that a network path corresponding to the VF network port is connected. The application solves the problem of network path fault detection after the working node introduces the DPU.
Owner:YUSUR TECH CO LTD

Managing a subsystem of an information handling system by a data processing unit (DPU)

Managing a subsystem of an information handling system by a data processing unit (DPU), including identifying a first connection between the DPU and a switch; identifying a second connection between the switch and the subsystem; identifying computational capabilities of the DPU, including routing support of the DPU; determining, based on the identified computational capabilities of the DPU, that the DPU supports multi-directional link subdivision; in response to determining that the DPU supports multi-directional link subdivision: configuring the DPU to select the multi-directional link subdivision as an operating mode of the DPU; configuring the switch to invoke a virtual switch hierarchy at the switch to enable communication between the DPU and the subsystem through the virtual switch hierarchy; and after configuring the DPU and the switch, accessing, by the DPU, the subsystem to manage operation of the subsystem.
Owner:DELL PROD LP

Network data encryption method, network data decryption method, and electronic device

PendingCN122339843AVirtual switchNetwork data
This application provides a network data encryption method, a network data decryption method, and an electronic device, which can be applied in the field of network security technology. The network data encryption method includes: a first back-end processing module encrypting the message data to be sent to obtain initial data, and sending the initial data to a virtual switch running in the kernel space or user space of the host; the first back-end processing module and the virtual switch communicate via shared memory or shared kernel path; the virtual switch determines the target virtual machine corresponding to the message data and sends the initial data to a second back-end processing module corresponding to the target virtual machine; the second back-end processing module and the virtual switch communicate via shared memory or shared kernel path.
Owner:DAWNING CLOUD COMPUTING TECH CO LTD +1

Data processing device, control method thereof, initialization method and initialization device

The application discloses a data processing device and a control method, an initialization method and an initialization device thereof, relates to the technical field of electronic equipment, and comprises at least two service modules, an interface module, an aggregation controller and a virtual switch. The aggregation controller determines a target service function corresponding to a service request, determines a target service module in the at least two service modules according to the target service function, the virtual switch sends the service request to the target service module, and in the case that service data sent by the target service module is received, the service data is sent to a computer device. By increasing the aggregation controller and the virtual switch, the data processing device originally needing to be allocated multiple bus numbers can be normally initialized and started only by using one bus number, the problem that the PCIe bus number requested by the data processing device exceeds the reserved number of the platform and causes the system to be unable to start is solved, and the technical effect that the upstream computer device can support more expansion devices is achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Vehicle control device

The invention relates to a vehicle control apparatus. The vehicle control device includes: a first signal processing device including a first processor and a first memory; the second signal processing device is electrically connected with the first signal processing device and is provided with a second processor and a second memory; the control device is electrically connected with the second signal processing device and is used for receiving a signal from the hardware switch or the sensor or controlling at least one actuator; the first processor or the second processor is controlled to execute a virtual switch service and output a virtual switch object corresponding to the virtual switch service to the electrically connected display when the hardware switch fails; the first processor or the second processor controls the controller in the control device to output an operation on signal, an operation off signal or an operation control signal to the actuator when the virtual switch object is selected. As a result, it is possible to quickly execute an alternative service when a hardware device connected to the controller fails.
Owner:LG ELECTRONICS INC

Switch upgrading method and system and server

The embodiment of the invention provides a switch upgrading method, a switch upgrading system and a server in the field of computers, which are used for realizing hot upgrading of a virtual switch with lower occupied resources and shorter interruption duration. Deployment in the switch upgrading system comprises but is not limited to a first virtual switch and a virtual machine, the first virtual switch is used for providing a communication function, such as data forwarding, for the virtual machine, the first virtual switch is connected with a persistent memory, and configuration parameters of the first virtual switch are stored in the persistent memory. The configuration parameter can be used for supporting the first virtual switch to realize a communication function; the method comprises the following steps: under the condition that a second virtual switch is deployed in a switch upgrading system, the second virtual switch synchronizes configuration parameters from a persistent memory; and under the condition that the second virtual switch completes synchronous parameter configuration, the first virtual switch stops data forwarding, and the second virtual switch starts data forwarding.
Owner:HUAWEI TECH CO LTD

Hybrid architecture target range multilayer overlay network simulation method

The invention provides a multi-layer coverage network simulation method for a hybrid architecture target range, belongs to the technical field of network simulation and virtualization, and can at least partially solve the problem that flexible creation, efficient isolation and centralized management and control of a virtual network are difficult to realize due to physical dispersion of heterogeneous computing nodes in the hybrid architecture target range in the prior art. The method comprises the following steps: acquiring a virtual network topology structure defined by a user through an integrated controller on a data plane of a heterogeneous computing node comprising a plurality of processor architectures; generating corresponding overlay network configuration and flow table rules according to the topological structure; the configuration and the rule are issued to a virtual switch on a related heterogeneous computing node; the virtual switch establishes an overlay network over the physical network based thereon. Through a centralized control mode, bottom layer hardware architecture difference is shielded, a virtual network of any topology can be delivered in a minute level without changing a physical network, and the method has the advantages of being flexible, efficient, high in control capacity and good in expansibility.
Owner:HUANENG POWER INT INC +1