MULTI-DESTINATION FORWARDING IN NETWORK CLOUDS WHICH INCLUDE EMULATED SWITCHES
    1.
    发明申请
    MULTI-DESTINATION FORWARDING IN NETWORK CLOUDS WHICH INCLUDE EMULATED SWITCHES 有权
    包括仿真开关的网络云中的多目标转发

    公开(公告)号:US20120027017A1

    公开(公告)日:2012-02-02

    申请号:US12848048

    申请日:2010-07-30

    IPC分类号: H04L12/56

    摘要: Techniques are described which facilitate multi-destination forwarding in a Layer 2 Multipath (L2MP) network which includes an emulated switch. The emulated switch may correspond to two or more underlying peer link switches in the L2MP network, in which each of the peer link switches is linked to a Classical Ethernet (CE) switch over a virtual port channel (vPC). Traffic received by one of the peer link switches over the vPC is automatically forwarded to the other peer link switch (or switches). Multi-destination frames originating from the L2MP network addressed to hosts within the CE network are sent over only one of the peer link switches.

    摘要翻译: 描述了在包括仿真开关的二层多路径(L2MP)网络中促进多目的地转发的技术。 仿真交换机可以对应于L2MP网络中的两个或更多个底层对等链路交换机,其中每个对等链路交换机通过虚拟端口信道(vPC)链接到经典以太网(CE)交换机。 通过vPC上的一个对等链路交换机接收到的流量将自动转发到另一个对等链路交换机(或交换机)。 通过寻址到CE网络内的主机的源自L2MP网络的多目标帧仅通过一个对等链路交换机发送。

    Method and system for redundant secure storage of sensitive data by using multiple keys
    2.
    发明申请
    Method and system for redundant secure storage of sensitive data by using multiple keys 有权
    通过使用多个密钥对敏感数据进行冗余安全存储的方法和系统

    公开(公告)号:US20070106911A1

    公开(公告)日:2007-05-10

    申请号:US11270155

    申请日:2005-11-09

    摘要: A method and apparatus for secure storage of data by using redundant keys is provided. The method includes encrypting a data set by using a master key, which can be encrypted by different sync keys. Sync keys can be generated by different supervisor cards. Thereafter, the encrypted master key and the encrypted data set can be stored in a memory. Further, credentials stored in one of the supervisor cards can be encrypted and transferred to other supervisor cards, to provide redundancy of supervisor cards.

    摘要翻译: 提供了一种通过使用冗余密钥来安全存储数据的方法和装置。 该方法包括通过使用主密钥来加密数据集,该主密钥可以由不同的同步密钥加密。 同步键可以由不同的主管卡生成。 此后,加密的主密钥和加密数据集可以存储在存储器中。 此外,存储在其中一个管理卡中的凭证可被加密并传送到其他管理卡,以提供管理卡的冗余。

    SYSTEM AND METHOD FOR LAYER-2 NETWORK ROUTING
    3.
    发明申请
    SYSTEM AND METHOD FOR LAYER-2 NETWORK ROUTING 有权
    用于层2网络路由的系统和方法

    公开(公告)号:US20140023074A1

    公开(公告)日:2014-01-23

    申请号:US13551350

    申请日:2012-07-17

    IPC分类号: H04L12/56

    摘要: An example method is provided and includes receiving a data message from a first virtual local area network; determining at an edge switch-router of a Layer-2 network whether the message should be routed; and routing the message in the Layer-2 network at the edge switch-router if the message should be routed. The method also includes switching the message at the edge switch-router if the message should not be routed.

    摘要翻译: 提供了一种示例性方法,包括从第一虚拟局域网接收数据消息; 在第二层网络的边缘交换路由器处确定消息是否应被路由; 并且如果消息应该路由,则在边缘交换机路由器的第2层网络中路由消息。 该方法还包括在边缘交换机路由器上切换消息,如果消息不应被路由。

    iSCSI and fibre channel authentication
    4.
    发明授权
    iSCSI and fibre channel authentication 有权
    iSCSI和光纤通道认证

    公开(公告)号:US08594083B2

    公开(公告)日:2013-11-26

    申请号:US11097613

    申请日:2005-04-01

    申请人: Chandan Mishra

    发明人: Chandan Mishra

    IPC分类号: H04L12/28 G06F7/04

    摘要: Methods and apparatus are provided for authenticating an iSCSI initiator connected to a fiber channel storage area network. An iSCSI initiator performs an authentication exchange with a fiber channel target such as a fiber channel host or disk array through one or more fiber channel switches. Authentication information such as password information no longer is required at fiber channel switches and can instead be aggregated at fiber channel targets.

    摘要翻译: 提供了用于认证连接到光纤通道存储区域网络的iSCSI启动器的方法和装置。 iSCSI启动器通过一个或多个光纤通道交换机执行与光纤通道目标(如光纤通道主机或磁盘阵列)的认证交换。 在光纤通道交换机上不再需要诸如密码信息的认证信息,而是可以在光纤通道目标上聚合。

    REKEY SCHEME ON HIGH SPEED LINKS
    6.
    发明申请
    REKEY SCHEME ON HIGH SPEED LINKS 有权
    关于高速链接的计划

    公开(公告)号:US20110252231A1

    公开(公告)日:2011-10-13

    申请号:US12756711

    申请日:2010-04-08

    申请人: Chandan Mishra

    发明人: Chandan Mishra

    IPC分类号: H04L9/00

    CPC分类号: H04L63/061 H04L9/0891

    摘要: In one embodiment, apparatus and methods for a rekey process are disclosed. In certain rekey embodiments, when a key-generation protocol exchange is executed, instead of generating a single new security relationship, such as a Security Association or SA, a multiple set (e.g., 10) of new security relationships (e.g., SAs) are generated. An authorized device can then individually use these security relationships (e.g., SAs) as needed to securely communicate with each other. For example, a set of SAs can be efficiently programmed into an 802.1ae protocol ASIC for handling transmitted and received data packets. In the description herein, embodiments of the invention are described with respect to SA's, and this “SA” term is generally defined as any type of security relation that can be formed to allow a particular node to securely transmit packets or frames to another receiving node.

    摘要翻译: 在一个实施例中,公开了用于重新密钥处理的装置和方法。 在某些重新密钥实施例中,当执行密钥生成协议交换时,代替生成诸如安全关联或SA的单个新的安全关系,新的安全关系(例如,SA)的多个集合(例如,10))是 生成。 然后,授权设备可以根据需要单独使用这些安全关系(例如,SA)以彼此安全地通信。 例如,可以将一组SA有效地编程到用于处理发送和接收的数据分组的802.1ae协议ASIC中。 在本文的描述中,关于SA的描述了本发明的实施例,并且该“SA”术语通常被定义为任何类型的安全关系,其可以形成为允许特定节点将分组或帧安全地传输到另一个接收节点 。

    System and method for layer-2 network routing
    7.
    发明授权
    System and method for layer-2 network routing 有权
    二层网络路由的系统和方法

    公开(公告)号:US09178837B2

    公开(公告)日:2015-11-03

    申请号:US13551350

    申请日:2012-07-17

    摘要: An example method is provided and includes receiving a data message from a first virtual local area network; determining at an edge switch-router of a Layer-2 network whether the message should be routed; and routing the message in the Layer-2 network at the edge switch-router if the message should be routed. The method also includes switching the message at the edge switch-router if the message should not be routed.

    摘要翻译: 提供了一种示例性方法,包括从第一虚拟局域网接收数据消息; 在第二层网络的边缘交换路由器处确定消息是否应被路由; 并且如果消息应该路由,则在边缘交换机路由器的第2层网络中路由消息。 该方法还包括在边缘交换机路由器上切换消息,如果消息不应被路由。

    Active-active multi-homing support for overlay transport protocol
    9.
    发明授权
    Active-active multi-homing support for overlay transport protocol 有权
    主动主动多重归属支持覆盖传输协议

    公开(公告)号:US08694664B2

    公开(公告)日:2014-04-08

    申请号:US12952790

    申请日:2010-11-23

    IPC分类号: G06F15/16

    CPC分类号: H04L45/04 H04L45/16 H04L45/24

    摘要: Techniques are provided for two peer edge switches in an edge switch cluster of a first data center site to actively provide traffic flow redundancy in an active-active configuration and provide multi-homing support over an overlay transport virtualization (OTV) protocol. Information is stored indicating a media access control (MAC) address of at least one endpoint device at the first site. An edge switch in the edge switch cluster at the first site sends via an OTV protocol a Layer-3 message that is configured to advertise the MAC address of the at least one endpoint at the first site to enable at least one edge switch at a second site to perform multipath routing to the endpoint device at the first site based on each of the edge switches in the edge switch cluster at the first site.

    摘要翻译: 为第一数据中心站点的边缘交换机集群中的两个对等边缘交换机提供技术,以主动提供主动 - 主动配置中的业务流冗余,并提供覆盖传输虚拟化(OTV)协议的多归属支持。 存储指示在第一站点处的至少一个端点设备的媒体访问控制(MAC)地址的信息。 第一站点的边缘交换机集群中的边缘交换机通过OTV协议发送第三层消息,该第三层消息被配置为在第一站点通告至少一个端点的MAC地址,以使能至少一个边缘交换机 基于第一站点上的边缘交换机集群中的每个边缘交换机,在第一站点处执行多路径路由到端点设备。

    PASSIVE NETWORK LATENCY MONITORING
    10.
    发明申请
    PASSIVE NETWORK LATENCY MONITORING 有权
    被动网络延迟监控

    公开(公告)号:US20140043987A1

    公开(公告)日:2014-02-13

    申请号:US13571706

    申请日:2012-08-10

    IPC分类号: H04L12/26 H04L12/56

    摘要: A method measures a resident delay for each port in a node in a network and a peer delay between each pair of neighbor nodes in the network. From these resident delays and peer delays, latency between each pair of neighbor nodes in the network is determined. The method includes weighting a route for a data packet going through the nodes in the network using the determined latencies. Each node includes a switch having switchable connections and is configured by a controller to send probe packets from an output port to a port in a neighbor node. The packet may include a time stamp and an identifier.

    摘要翻译: 一种方法测量网络中节点中每个端口的驻留延迟以及网络中每对邻居节点之间的对等延迟。 从这些驻留延迟和对等延迟中,确定网络中每对邻居节点之间的延迟。 该方法包括使用所确定的延迟对通过网络中的节点的数据分组的路由加权。 每个节点包括具有可切换连接的交换机,并且由控制器配置以将探测分组从输出端口发送到邻居节点中的端口。 分组可以包括时间戳和标识符。