DYNAMIC DEVICE ISOLATION IN A NETWORK
    451.
    发明申请

    公开(公告)号:US20190281085A1

    公开(公告)日:2019-09-12

    申请号:US16421858

    申请日:2019-05-24

    Abstract: In one embodiment, a device in a network inserts a profile tag into an address request sent by an endpoint node in the network to a lookup service. The lookup service is configured to identify one or more addresses with which the endpoint node is authorized to communicate based on a profile for the endpoint node associated with the inserted profile tag. The device receives an address response sent from the lookup service to the endpoint node that indicates the set of one or more addresses with which the endpoint node is authorized to communicate. The device determines whether a communication between the endpoint node and a particular network address is authorized using the set of one or more addresses with which the endpoint node is authorized to communicate. The device blocks the communication based on a determination that the particular network address is not in the set of one or more addresses with which the endpoint node is authorized to communicate.

    Concentric transmissions in a directed acyclic graph based on deferred contention to higher devices

    公开(公告)号:US10412010B1

    公开(公告)日:2019-09-10

    申请号:US15954786

    申请日:2018-04-17

    Abstract: In one embodiment, a network device starts a deferred discovery that defers to a prescribed transmission operation in response to detecting a message is from an identified higher device that is closer to a root of a network topology in a data network. The prescribed transmission operation and the deferred discovery each require a corresponding network device to wait at least a first half of a selected minimum contention interval before attempting transmission at a randomized position within a second half of the selected minimum contention interval. The minimum contention interval of the deferred discovery is at least twice the selected minimum contention interval. The network device transmits an updated message during the deferred discovery only if, upon reaching the corresponding randomized position of the deferred discovery, the subsequent messages from identified higher devices are less than a prescribed redundancy constant.

    Dynamic device isolation in a network

    公开(公告)号:US10356124B2

    公开(公告)日:2019-07-16

    申请号:US15446707

    申请日:2017-03-01

    Abstract: In one embodiment, a device in a network inserts a profile tag into an address request sent by an endpoint node in the network to a lookup service. The lookup service is configured to identify one or more addresses with which the endpoint node is authorized to communicate based on a profile for the endpoint node associated with the inserted profile tag. The device receives an address response sent from the lookup service to the endpoint node that indicates the set of one or more addresses with which the endpoint node is authorized to communicate. The device determines whether a communication between the endpoint node and a particular network address is authorized using the set of one or more addresses with which the endpoint node is authorized to communicate. The device blocks the communication based on a determination that the particular network address is not in the set of one or more addresses with which the endpoint node is authorized to communicate.

    DISTRIBUTING TRAFFIC TO MULTIPLE DESTINATIONS VIA AN ISOLATION NETWORK

    公开(公告)号:US20190190729A1

    公开(公告)日:2019-06-20

    申请号:US15845170

    申请日:2017-12-18

    Abstract: In one embodiment, a cloud-based service instructs one or more networking devices in a local area network (LAN) to form a virtual network overlay in the LAN that redirects traffic associated with a particular node in the LAN to the service. The service receives multicast or broadcast traffic sent by the particular node in the LAN and redirected to the service via the virtual network overlay. The service identifies a group of nodes in the network that are to receive the traffic sent by the particular node, based in part by profiling the traffic associated with the particular node. The service sends the traffic sent by the particular node to at least one networking device in the LAN with an indication of the identified group of nodes in the network that are to receive the traffic sent by the particular node. The at least one networking device forwards the traffic sent by the particular node to the nodes in the identified group.

    Per-packet, time slotted channel hopping (TSCH), meta-timeslot

    公开(公告)号:US10231253B2

    公开(公告)日:2019-03-12

    申请号:US15341099

    申请日:2016-11-02

    Abstract: In one embodiment, a device in a network receives a time-slotted channel hopping (TSCH) communication schedule. The TSCH communication schedule is divided into a plurality of macrocells, each macrocell comprising a plurality of TSCH cells. The device receives a packet from a routing protocol child node of the device during a particular macrocell of the TSCH communication schedule that is associated with propagation of the packet through the network. In response to receiving the packet, the device claims a token associated with the particular macrocell that authorizes the device to transmit during one or more cells of the macrocell. The device transmits the received packet to a second node in the network during the authorized one or more cells of the particular macrocell.

Patent Agency Ranking