Secure communication session resumption in a service function chain preliminary class

    公开(公告)号:US12028378B2

    公开(公告)日:2024-07-02

    申请号:US18068470

    申请日:2022-12-19

    IPC分类号: H04L9/40 H04L9/08

    摘要: A method for resuming a Transport Layer Security (TLS) session in a Service Function Chain comprising a plurality of Service Function nodes coupled to a Service Function Forwarder. A request is received at a first Service Function node to establish a TLS session, and a Pre-Shared Key (PSK) and a PSK identifier that uniquely correspond to the first Service Function node and the TLS session are generated. The PSK identifier is forwarded to one or more of the Service Function Forwarder and the plurality of Service Function nodes. A request to resume the TLS session is received from a client device that previously disconnected. It is determined that the connection request contains the PSK identifier, a second Service Function node is selected, and the TLS session is re-established between the client device and the second Service Function node using the same PSK as the prior TLS session.

    Federated insertion of 3rd party software as a service for network slices

    公开(公告)号:US10863333B2

    公开(公告)日:2020-12-08

    申请号:US16277309

    申请日:2019-02-15

    摘要: Systems, methods, and computer-readable mediums for federating an enterprise and a SaaS provider across one or more network slices of a network service provider. A SaaS provided by a SaaS provider for provisioning to an enterprise can be recognized. One or more network slices within a network of a network service provider between the enterprise and the SaaS provider can be identified. The one or more network slices can be used to provision the SaaS to the enterprise. As follows, the SaaS provider can be federated with the enterprise across one or more network service providers, including the network service provider. Specifically, the SaaS provider can be federated with the enterprise by uniquely associating the one or more network slices provided by the network service provider with the SaaS provisioned by the SaaS provider to the enterprise.

    Endpoint privacy preservation with cloud conferencing

    公开(公告)号:US10523657B2

    公开(公告)日:2019-12-31

    申请号:US14942898

    申请日:2015-11-16

    IPC分类号: H04L29/06 H04L12/18

    摘要: In one embodiment, a first request may be received from a first endpoint to access a cloud-based conference platform. The first request can include a first access token. Based at least on the first request, a first certificate may be provided to the first endpoint, wherein the first certificate may not include an identity of the first endpoint. A second request may be received from a second endpoint to access the cloud-based conference platform. The second request can include a second access token. Based at least on the second request, a second certificate can be provided to the second endpoint, wherein the second certificate may not include an identity of the second endpoint. Data can be routed within the cloud-based conference platform between the first endpoint and second endpoint based at least upon the first certificate and the second certificate.

    AUTOMATIC THRESHOLD LIMIT CONFIGURATION FOR INTERNET OF THINGS DEVICES

    公开(公告)号:US20180159894A1

    公开(公告)日:2018-06-07

    申请号:US15366354

    申请日:2016-12-01

    IPC分类号: H04L29/06

    摘要: Presented herein are techniques for mitigating a distributed denial of service attack. A method includes, at a network security device, such as a firewall, monitoring network traffic, flowing through the firewall, destined for a network device, determining whether the network traffic is below a predetermined amount, while the network traffic is below the predetermined amount, sending to the network device a plurality of probes, receiving responses from the network device in response to the probes, and setting one or more thresholds for subsequent traffic destined for the network device based on the responses received from the network device.

    Propagating flow characteristics in service function chaining (SFC) headers

    公开(公告)号:US09954774B2

    公开(公告)日:2018-04-24

    申请号:US15066467

    申请日:2016-03-10

    IPC分类号: H04L12/721

    CPC分类号: H04L45/566 H04L45/302

    摘要: In one embodiment, a service function classifier device determines a classification of a packet using one or more packet classification rules. The device selects a service function path based on the classification of the packet. The device determines one or more traffic flow characteristics based on the classification of the packet. The device generates a service function chaining (SFC) header that identifies the selected service function path and the determined one or more traffic flow characteristics. The SFC header is configured to cause a device along the service function path to forward the encapsulated packet based on the identified service function path and the determined one or more traffic flow characteristics. The device sends the packet along the selected service function path as an encapsulated packet that includes the generated SFC header.

    Domain Name Service Redirection for a Content Delivery Network with Security as a Service
    10.
    发明申请
    Domain Name Service Redirection for a Content Delivery Network with Security as a Service 审中-公开
    具有安全即服务的内容传送网络的域名服务重定向

    公开(公告)号:US20160380975A1

    公开(公告)日:2016-12-29

    申请号:US14748499

    申请日:2015-06-24

    IPC分类号: H04L29/06 H04L29/12 H04L29/08

    摘要: In one implementation, a cloud connector obtains location information for a proxy server of a security as a service (SecaaS) function. The cloud connector receives a content request from a user device for content hosted in a content delivery network (CDN). A domain name service (DNS) request, with location information, is forwarded to a DNS authoritative server. An identification of a downstream CDN server is received from the DNS authoritative server. The identification of the downstream CDN is based on the location information for the proxy server of the SecaaS function. The content is obtained from the downstream CDN server through the proxy server of the SecaaS function.

    摘要翻译: 在一个实现中,云连接器获得作为服务(SecaaS)功能的安全服务器的代理服务器的位置信息。 云连接器从用户设备接收内容传送网络(CDN)中托管的内容的内容请求。 具有位置信息的域名服务(DNS)请求被转发到DNS权威服务器。 从DNS权威服务器接收到下游CDN服务器的标识。 下游CDN的识别基于SecaaS功能的代理服务器的位置信息。 内容通过SecaaS功能的代理服务器从下游CDN服务器获取。