SYSTEM AND METHOD FOR TRANSPORTING INFORMATION TO SERVICES IN A NETWORK ENVIRONMENT
    22.
    发明申请
    SYSTEM AND METHOD FOR TRANSPORTING INFORMATION TO SERVICES IN A NETWORK ENVIRONMENT 有权
    在网络环境中向服务运输信息的系统和方法

    公开(公告)号:US20150334595A1

    公开(公告)日:2015-11-19

    申请号:US14279724

    申请日:2014-05-16

    CPC classification number: H04L29/06 H04L41/0896 H04L41/5054 H04W28/0268

    Abstract: An example method is provided in one example embodiment and may include receiving a packet for a subscriber at a gateway, wherein the gateway includes a local policy anchor for interfacing with one or more policy servers and one or more classifiers for interfacing with one or more service chains, each service chain including one or more services accessible by the gateway; determining a service chain to receive the subscriber's packet; appending the subscriber's packet with a header, wherein the header includes, at least in part, identification information for the subscriber and an Internet Protocol (IP) address for the local policy anchor; and injecting the packet including the header into the service chain determined for the subscriber.

    Abstract translation: 在一个示例性实施例中提供了示例性方法,并且可以包括在网关处接收订户的分组,其中所述网关包括用于与一个或多个策略服务器进行接口的本地策略锚点以及用于与一个或多个服务 每个服务链包括由网关可访问的一个或多个服务; 确定服务链以接收订户的分组; 用标题附加订户的分组,其中该报头至少部分地包括用户的标识信息和用于本地策略锚的因特网协议(IP)地址; 以及将包括所述头部的分组注入到为所述用户确定的服务链中。

    METHOD, SYSTEM, AND LOGIC FOR IN-BAND EXCHANGE OF META-INFORMATION
    23.
    发明申请
    METHOD, SYSTEM, AND LOGIC FOR IN-BAND EXCHANGE OF META-INFORMATION 审中-公开
    元信息交换的方法,系统和逻辑

    公开(公告)号:US20150271205A1

    公开(公告)日:2015-09-24

    申请号:US14521856

    申请日:2014-10-23

    Abstract: In an embodiment, a method is provided for enabling in-band data exchange between networks. The method can comprise receiving, by a first enveloping proxy located in the first network, at least one regular secure sockets layer (SSL) record for a SSL session established between a client and a server; receiving the data from a network element located in the first network; encoding the data into at least one custom SSL record; and transmitting the at least one regular SSL record and the at least one custom SSL record to an enveloping proxy. In another embodiment, a method can comprise receiving at least one regular secure sockets layer (SSL) record and at least one custom SSL record for a SSL session established between a client and a server; extracting the data from the at least one custom SSL; transmitting the at least one regular SSL record.

    Abstract translation: 在一个实施例中,提供了一种用于实现网络之间的带内数据交换的方法。 该方法可以包括通过位于第一网络中的第一包络代理接收在客户端和服务器之间建立的SSL会话的至少一个常规安全套接字层(SSL)记录; 从位于所述第一网络中的网元接收所述数据; 将数据编码成至少一个自定义SSL记录; 以及将所述至少一个常规SSL记录和所述至少一个定制SSL记录发送到包络代理。 在另一个实施例中,一种方法可以包括:在客户端和服务器之间建立的SSL会话接收至少一个常规安全套接字层(SSL)记录和至少一个定制SSL记录; 从至少一个自定义SSL提取数据; 发送所述至少一个常规SSL记录。

    Systems and methods for distributing SD-WAN policies

    公开(公告)号:US12052569B2

    公开(公告)日:2024-07-30

    申请号:US17403676

    申请日:2021-08-16

    CPC classification number: H04W12/086 H04L63/0272 H04L63/20 H04W12/37 H04L45/64

    Abstract: In one embodiment, a router includes one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors. The one or more computer-readable non-transitory storage media include instructions that, when executed by the one or more processors, cause the router to perform operations including receiving software-defined networking in a wide area network (SD-WAN) policies from a component of an SD-WAN network. The operations also include establishing a session with a mobile device and receiving information associated with the mobile device in response to establishing the session with the mobile device. The operations further include filtering the SD-WAN policies based on the information associated with the mobile device to generate SD-WAN device-specific policies and communicating the SD-WAN device-specific policies to the mobile device.

    On-path dynamic policy enforcement and endpoint-aware policy enforcement for endpoints

    公开(公告)号:US11201800B2

    公开(公告)日:2021-12-14

    申请号:US16782769

    申请日:2020-02-05

    Abstract: Systems, methods, and computer-readable media for locally applying endpoint-specific policies to an endpoint in a network environment. A network device local to one or more endpoints in a network environment can receive from a centralized network controller one or more network-wide endpoint policies. A first endpoint of the one or more endpoints can be configured to inject policy metadata into first data traffic. Policy metadata injected into the first traffic data can be received from the first endpoint. The network device can determine one or more first endpoint-specific polices for the first endpoint by evaluation the first policy metadata with respect to the one or more network-wide endpoint policies. As follows, the one or more first endpoint-specific policies can be applied to control data traffic associated with the first endpoint.

    System and method of verifying network communication paths between applications and services

    公开(公告)号:US10511590B1

    公开(公告)日:2019-12-17

    申请号:US16413411

    申请日:2019-05-15

    Abstract: Disclosed are concepts for provided for managing application traffic. A method includes receiving a request to access a service from an application, confirming an entity of a user of the application and, based on the confirmation, generating, via an authentication service, a routing policy for data flows between the application and the service. The routing policy defines a mandated path between the application and the service. The method also can include storing proof-of-transit data in the traffic flow for tracking an actual path from the application to the service and determining whether the data path complies with the mandated path defined in the policy. When the determination indicates that the actual path followed the mandated path defined in the routing policy, the method includes granting access to the user for the service. When the actual path differs from the mandated path, the method includes denying access to the user.

    MANAGING MULTICAST SERVICE CHAINS IN A CLOUD ENVIRONMENT

    公开(公告)号:US20190342354A1

    公开(公告)日:2019-11-07

    申请号:US15968690

    申请日:2018-05-01

    Abstract: Techniques for provisioning multicast chains in a cloud-based environment are described herein. In an embodiment, an orchestration system sends a particular model of a distributed computer program application comprising one or more sources, destinations, and virtualized appliances for initiation by one or more host computers to a software-defined networking (SDN) controller. The SDN controller determines one or more locations for the virtualized appliances and generates a particular updated model of the distributed computer program application, the updated model comprising the one or more locations for the virtualized appliances. The SDN controller sends the updated model of the distributed computer program application to the orchestration system. The orchestration system uses the particular updated model to generate a mapping of virtualized appliances to available host computers of the one or more host computers based, at least in part, on the particular updated model of the distributed computer program application. Using the mapping of virtualized appliances to available host computers, the orchestration system sends instructions for initiating the virtualized appliances on the available host computers to one or more cloud management systems.

Patent Agency Ranking