-
公开(公告)号:US20220224565A1
公开(公告)日:2022-07-14
申请号:US17148481
申请日:2021-01-13
Applicant: Cisco Technology, Inc.
Inventor: Vincent Cuissard , Domenico Ficara , Amine Choukir , Roberto Muccifora
Abstract: A method for establishing a VPN with a client device is provided. In the method, an AP can receive an access request directed to an OpenRoaming (OR) Service Set Identifier (SSID) from the client device. The AP can send the access request to an OR connector. In response to the access request, the AP may receive an access response from the OR connector. The access response can include an attribute indicating an address to connect to a company Virtual Private Network (VPN) headend. The AP may then use the attribute to establish the VPN connection with the company VPN headend.
-
公开(公告)号:US20220183111A1
公开(公告)日:2022-06-09
申请号:US17111625
申请日:2020-12-04
Applicant: Cisco Technology, Inc.
Inventor: Vincent Cuissard , Domenico Ficara , Alessandro Erta , Luca Bisti , Kasi Nalamalapu , Sudhir Kumar Jain , Salvatore Valenza , Arun Khanna , Stefano Ferrari , Loris Gazzarrini
Abstract: In one embodiment, a gateway to a Layer-3 network forms a first Layer-2 tunnel between the gateway and a first wireless access point (AP) that communicates wirelessly with a first mobile node of a mobile system (MS) via a first wireless connection. The gateway generates a mapping that associates an onboard device of the MS with the first AP and an identifier for the MS, based on traffic conveyed via the first Layer-2 tunnel and associated with the onboard device, the traffic comprising a header that indicates the identifier for the MS. The gateway receives, from a second AP, an indication that the MS is roaming from the first wireless connection to a second wireless connection, the indication including the identifier for the MS. The gateway updates the mapping to associate the onboard device of the MS with a second AP, based on the indication that the MS is roaming.
-
公开(公告)号:US09705700B2
公开(公告)日:2017-07-11
申请号:US14519714
申请日:2014-10-21
Applicant: Cisco Technology, Inc.
Inventor: Domenico Ficara , Davide Cuda , Leo Caldarola , Salvatore Valenza , Roberto Muccifora
IPC: H04L12/28 , H04L12/417 , H04L12/875
CPC classification number: H04L12/417 , H04L47/56
Abstract: Embodiments provide techniques for transmitting data packets across a deterministic Ethernet network. Embodiments receive, at a first device in the deterministic Ethernet network, a deterministic binary schedule specifying timing information for transmitting data fragments relating to a plurality of data flows. Data packets to transmit to a destination device within the deterministic Ethernet network are received at the first device. Embodiments include fragmenting each of the data packets into two or more fragments and encoding at least one of the two or more fragments for each of the data packets with a respective sparse graph code. The encoded fragments are transmitted to the destination device, across multiple paths through the deterministic Ethernet network, according to timing information specified in the deterministic binary schedule.
-
34.
公开(公告)号:US20160359728A1
公开(公告)日:2016-12-08
申请号:US14729810
申请日:2015-06-03
Applicant: CISCO TECHNOLOGY, INC.
Inventor: Domenico Ficara , Davide Cuda , Amine Choukir
IPC: H04L12/721
Abstract: Techniques are disclosed for exchanging anonymized information between autonomous systems. In one example, a method comprises accessing an eigenvalue, wherein the eigenvalue is based on topology data associated with the first autonomous system; encoding the eigenvalue into a message; and transmitting, by a network element located in the first autonomous system, the message to an external edge router located in the second autonomous system. A further method can comprise receiving, by a network component located in a first autonomous system, a message, wherein the message comprises an eigenvalue and the message is received from an external network element located in a second autonomous system; accessing another other eigenvalue, the another eigenvalue corresponding to an autonomous system different from the first autonomous system; analyzing the another eigenvalue and the eigenvalue; and executing, by the network element, an action based on the analyzing.
Abstract translation: 公开了用于在自治系统之间交换匿名信息的技术。 在一个示例中,一种方法包括访问特征值,其中特征值基于与第一自治系统相关联的拓扑数据; 将特征值编码成消息; 以及通过位于所述第一自治系统中的网络单元将所述消息发送到位于所述第二自治系统中的外部边缘路由器。 另一方法可以包括通过位于第一自治系统中的网络组件接收消息,其中所述消息包括特征值,并且所述消息是从位于第二自治系统中的外部网络元件接收的; 访问另一个特征值,对应于与第一自治系统不同的自治系统的另一个特征值; 分析另一个特征值和特征值; 并且由网元执行基于分析的动作。
-
公开(公告)号:US09407735B2
公开(公告)日:2016-08-02
申请号:US14486556
申请日:2014-09-15
Applicant: CISCO TECHNOLOGY, INC.
Inventor: Salvatore Valenza , Domenico Ficara , Roberto Muccifora , Leo Caldarola
CPC classification number: H04L69/22 , H04L43/026
Abstract: In one embodiment, a method includes identifying at a network device, a number of items for matching at a hash table, the number of items exceeding matching available with ternary content addressable memory (TCAM) at the network device, defining at the network device, an optimal cyclic redundancy check (CRC) polynomial based on the number of items for matching at the hash table, and generating at the network device, an optimal hash function based on the optimal CRC polynomial to extend packet classification capability at the network device. An apparatus is also disclosed herein.
Abstract translation: 在一个实施例中,一种方法包括在网络设备处识别用于在散列表处进行匹配的项目的数量,在网络设备处定义的与网络设备上的三进制内容可寻址存储器(TCAM)可用的项目数量相匹配的数量, 基于用于在散列表处进行匹配的项目的数量的最佳循环冗余校验(CRC)多项式,以及在网络设备处生成基于最佳CRC多项式的最优哈希函数,以在网络设备上扩展分组分类能力。 本文还公开了一种装置。
-
公开(公告)号:US20250030741A1
公开(公告)日:2025-01-23
申请号:US18356147
申请日:2023-07-20
Applicant: Cisco Technology, Inc.
Inventor: Giacomo Trifilo , Domenico Ficara , Anirban Karmakar
IPC: H04L9/40
Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for extending and standardizing heterogeneous network devices using instrumentation. A method includes: receiving, by a client device using a first network interface, instrumentation bytecode to supplement with a data link layer from a management device, wherein a verifier of the client device verifies that the instructions of the bytecode are constrained for security based on a plurality of rules; in response to detecting a trigger at the client device, executing the instrumentation bytecode at the client device to perform at least one function associated with the trigger; and sending a response from the client device based on an execution result of the instrumentation bytecode.
-
公开(公告)号:US20250016568A1
公开(公告)日:2025-01-09
申请号:US18892955
申请日:2024-09-23
Applicant: Cisco Technology, Inc.
Inventor: Domenico Ficara , Roberto Muccifora , Amine Choukir , Robert Barton , Jerome Henry , Arun Khanna
IPC: H04W12/122 , H04W12/106 , H04W12/73
Abstract: A method is provided that is performed in a wireless network to detect a rogue wireless device. The method comprises detecting a suspect wireless device in the wireless network based on messages transmitted by the suspect wireless device using a first Media Access Control (MAC) address that is also used by a valid wireless device in the wireless network. When a suspect wireless device is detected, the method next includes sending to the valid wireless device in the wireless network a request configured to cause the valid wireless device to change its MAC address. After the valid wireless device has changed its MAC address, the method involves observing messages transmitted by the suspect wireless device in the wireless network. The method then includes determining that the suspect wireless device is a rogue device when the suspect wireless device continues to transmit messages using the first MAC address.
-
公开(公告)号:US12177943B2
公开(公告)日:2024-12-24
申请号:US17111625
申请日:2020-12-04
Applicant: Cisco Technology, Inc.
Inventor: Vincent Cuissard , Domenico Ficara , Alessandro Erta , Luca Bisti , Kasi Nalamalapu , Sudhir Kumar Jain , Salvatore Valenza , Arun Khanna , Stefano Ferrari , Loris Gazzarrini
IPC: H04W76/00 , H04W4/40 , H04W40/24 , H04W76/11 , H04W76/12 , H04W88/16 , H04W36/00 , H04W92/02 , H04W92/24
Abstract: In one embodiment, a gateway to a Layer-3 network forms a first Layer-2 tunnel between the gateway and a first wireless access point (AP) that communicates wirelessly with a first mobile node of a mobile system (MS) via a first wireless connection. The gateway generates a mapping that associates an onboard device of the MS with the first AP and an identifier for the MS, based on traffic conveyed via the first Layer-2 tunnel and associated with the onboard device, the traffic comprising a header that indicates the identifier for the MS. The gateway receives, from a second AP, an indication that the MS is roaming from the first wireless connection to a second wireless connection, the indication including the identifier for the MS. The gateway updates the mapping to associate the onboard device of the MS with a second AP, based on the indication that the MS is roaming.
-
39.
公开(公告)号:US20240422846A1
公开(公告)日:2024-12-19
申请号:US18817885
申请日:2024-08-28
Applicant: Cisco Technology, Inc.
Inventor: Amine Choukir , Robert Barton , Anirban Karmakar , Domenico Ficara , Vincent Cuissard , Jerome Henry
Abstract: A user device connected to a wireless network maintains session persistence through a MAC address change of a user device. The user device establishes a multi-path communication session including a first subflow associated with a first MAC address for the user device. When the user device changes from the first MAC address to a second MAC address. the user device establishes a second subflow of the multi-path communication session. The second subflow is associated with the second MAC address. After establishing the second subflow associated with the second MAC address, the user device ends the first subflow associated with the first MAC address.
-
公开(公告)号:US12089089B2
公开(公告)日:2024-09-10
申请号:US17581188
申请日:2022-01-21
Applicant: Cisco Technology, Inc.
Inventor: Pascal Thubert , Domenico Ficara , Patrick Wetterwald , Alessandro Erta , Amine Choukir
CPC classification number: H04W28/16 , H04B10/1149 , H04W16/26 , H04W16/28 , H04W84/18
Abstract: In one embodiment, a controller identifies access points forming an overhead mesh of access points in an area, each access point comprising one or more directional transmitters each configured to transmit a beam cone in a substantially downward direction towards a floor of the area. The controller assigns the access points to access point groups. The controller generates communication schedules for the access points such that each access point in an access point group is on a common channel and only one of neighboring directional transmitters of access points in that group is able to transmit at any given time. The controller sends the communication schedules to the access points forming the overhead mesh of access points in the area.
-
-
-
-
-
-
-
-
-