Abstract:
An example method is provided in one example embodiment and may include configuring a measurement indication for a packet; forwarding the packet through a service chain comprising one or more service functions; recording measurement information for the packet as it is forwarded through the service chain; and managing capacity for the service chain based, at least in part, on the measurement information. In some cases, the method can include determining end-to-end measurement information for the service chain using the recorded measurement information. In some cases, managing capacity for the service chain can further include identifying a particular service function as a bottleneck service function for the service chain; and increasing capacity for the bottleneck service. In various instances, increasing capacity for the bottleneck service can include at least one of: instantiating additional instances of the bottleneck service; and instantiating additional instances of the service chain.
Abstract:
A method is provided in one example embodiment and may include receiving a first Internet protocol (IP) flow for an IP session for a subscriber; selecting a first service function group from a plurality of service function groups to perform one or more services for the IP session for the subscriber, wherein each of the plurality of service function groups comprises a plurality of service function chain types and wherein each service function chain type comprises an ordered combination of one or more service functions; assigning the IP session for the subscriber to the first service function group; and forwarding the first IP flow for the IP session of the subscriber across a first service function chain type for the first service function group based, at least in part, on a service policy for the subscriber.
Abstract:
A method is provided in one example embodiment and includes sending, by a first entity associated with an access network, a first request message including a session identifier associated with a user session to a second entity associated with a core network. The method further includes establishing a first control channel with the second entity in which the first control channel is associated with the session identifier. The first control channel is an in-band channel between the first entity and the second entity. The method further includes receiving policy information associated with the user session from the second entity using the first control channel. The policy information is indicative of one or more policies to be applied in the access network to user data associated with the user session.
Abstract:
A method is provided in one example embodiment and includes receiving, by a first proxy within an access network, a first request for content associated with a remote server. The first request includes a subscriber identifier associated with a subscriber. The method further includes sending the first request to a second proxy within a core network. The first request is intercepted by an intercept function within the core network in a first intercept operation. The intercept function is configured to forward the first request to the second proxy. The method further includes receiving a redirect from the second proxy. The redirect is configured to redirect the first request to the first proxy. The redirect is intercepted by the intercept function in a second intercept operation, and the intercept function is configured to forward the redirect to the first proxy.
Abstract:
An example method is provided in one example embodiment and may include receiving a packet for a subscriber at a gateway, wherein the gateway includes a local policy anchor for interfacing with one or more policy servers and one or more classifiers for interfacing with one or more service chains, each service chain including one or more services accessible by the gateway; determining a service chain to receive the subscriber's packet; appending the subscriber's packet with a header, wherein the header includes, at least in part, identification information for the subscriber and an Internet Protocol (IP) address for the local policy anchor; and injecting the packet including the header into the service chain determined for the subscriber.
Abstract:
A method provided in one embodiment includes receiving a resource list including a first core network identifier identifying a first core network, at least a first resource identifier identifying a first subset of network resources from a plurality of network resources associated with the first core network, and a first priority value associated with each of the identified resources of the first core network. The method further includes receiving a first device identifier associated with a first user equipment, determining whether a portion of the first device identifier matches the first core network identifier, and modifying the resource list to include at least a second resource identifier identifying a second subset of the network resources from the plurality of network resources associated with the first core network when the portion of the first device identifier is determined to match the first core network identifier.
Abstract:
An example method is provided in one example embodiment and can include obtaining, within a radio access network, a channel state for a data channel associated with a mobile terminal; including the channel state in a differentiated services (diffserv) marking within an Internet Protocol (IP) header of at least one IP packet associated with the mobile terminal; and transmitting the at least one IP packet including the IP header having the diffserv marking toward a packet data network.
Abstract:
A method provided in one embodiment includes receiving a resource list including a first core network identifier identifying a first core network, at least a first resource identifier identifying a first subset of network resources from a plurality of network resources associated with the first core network, and a first priority value associated with each of the identified resources of the first core network. The method further includes receiving a first device identifier associated with a first user equipment, determining whether a portion of the first device identifier matches the first core network identifier, and modifying the resource list to include at least a second resource identifier identifying a second subset of the network resources from the plurality of network resources associated with the first core network when the portion of the first device identifier is determined to match the first core network identifier.
Abstract:
An example method is provided in one example embodiment and may include receiving a packet for a subscriber at a gateway, wherein the gateway includes a local policy anchor for interfacing with one or more policy servers and one or more classifiers for interfacing with one or more service chains, each service chain including one or more services accessible by the gateway; determining a service chain to receive the subscriber's packet; appending the subscriber's packet with a header, wherein the header includes, at least in part, identification information for the subscriber and an Internet Protocol (IP) address for the local policy anchor; and injecting the packet including the header into the service chain determined for the subscriber.
Abstract:
In an embodiment, a method is provided for enabling in-band data exchange between networks. The method can comprise receiving, by a first enveloping proxy located in the first network, at least one regular secure sockets layer (SSL) record for a SSL session established between a client and a server; receiving the data from a network element located in the first network; encoding the data into at least one custom SSL record; and transmitting the at least one regular SSL record and the at least one custom SSL record to an enveloping proxy. In another embodiment, a method can comprise receiving at least one regular secure sockets layer (SSL) record and at least one custom SSL record for a SSL session established between a client and a server; extracting the data from the at least one custom SSL; transmitting the at least one regular SSL record.