Virtualized network functions through address space aggregation

    公开(公告)号:US11522828B2

    公开(公告)日:2022-12-06

    申请号:US15664869

    申请日:2017-07-31

    Abstract: In some examples, an example method to provide a virtualized Carrier-grade Network Address Translation (CGN) at a first customer edge router may include establishing a tunnel between the first customer edge router and each aggregation router among one or more aggregation routers, performing a Network Address Translation (NAT) on a first data packet to create a NAT'ed first data packet, selecting a first aggregation router from amongst the one or more aggregation routers to send the NAT'ed first data packet to, encapsulating the NAT'ed first data packet with overlay information corresponding to a tunnel established between the first customer edge router and a first aggregation router, and sending the encapsulated NAT'ed first data packet through the tunnel to the first aggregation router.

    Method and system for key generation, distribution and management

    公开(公告)号:US10742402B2

    公开(公告)日:2020-08-11

    申请号:US15881666

    申请日:2018-01-26

    Abstract: A method for securing communications for a given network topology is provided. The method comprises generating by a node N(i) of the network, security parameters for the node N(i); transmitting by the node N(i), said security parameters to a controller for the network; maintaining by the controller said security parameters for the node N(i); receiving by the controller a request from a node N(j) for the security parameters for the node N(i); retrieving by the controller the security parameters for the node N(i); and transmitting by the controller said security parameters to the node N(j).

    HASH-BASED KEY DISTRIBUTION
    4.
    发明申请

    公开(公告)号:US20200169390A1

    公开(公告)日:2020-05-28

    申请号:US16570791

    申请日:2019-09-13

    Abstract: A method for securing communications for a given network is provided. The method comprises by at least one node(i) of the network configured to utilize pairwise keys: generating a set of encryption keys; and transmitting the set of encryption keys to a controller for the network; by the controller, executing a key selection process wherein for each node(j) in the network an encryption key J is selected from the set of encryption keys; assigning the encryption key J to the node(j); and transmitting the selected encryption key J to the node(j); by each node(j), generating an encryption key I to the node(i); and sending the encryption key I to the node(i) via the controller.

    Service chaining based on labels in control and forwarding

    公开(公告)号:US10142254B1

    公开(公告)日:2018-11-27

    申请号:US14028514

    申请日:2013-09-16

    Abstract: A method for routing is disclosed. The method comprises establishing an overlay network, comprising a plurality of network elements and an overlay controller; wherein the overlay controller is in communication with each network element via a secure tunnel established through an underlying transport network; receiving by the overlay controller, information from each service-hosting network element information said information identifying a service hosted at that service-hosting network element, and label associated with the service-hosting network element; identifying by the overlay controller, at least one policy that associates traffic from a site with a service; and causing by said overly controller, the at least one policy to be executed so that traffic from the site identified in the policy is routed using the underlying transport network to the service-hosting network element associated with the said service.

    APPARATUS AND METHOD TO HIDE TRANSIT ONLY MULTI-ACCESS NETWORKS IN OSPF
    6.
    发明申请
    APPARATUS AND METHOD TO HIDE TRANSIT ONLY MULTI-ACCESS NETWORKS IN OSPF 审中-公开
    在OSPF中仅隐藏多个接入网络的设备和方法

    公开(公告)号:US20140003289A1

    公开(公告)日:2014-01-02

    申请号:US14013990

    申请日:2013-08-29

    Abstract: In one embodiment, a first router determines whether a network coupling the first router to one or more second routers is transit-only, wherein transit-only indicates connecting only routers to provide for transmission of data from router to router. When the network is transit-only, the first router generates an Open Shortest Path First (OSPF) Link State Advertisement (LSA) that includes an address for the network and a designated network mask. The designated network mast operates as a transit-only identification that indicates the address should not be installed in a Routing Information Base (RIB) upon receipt of the OSPF LSA at the one or more second routers. When the network is not transit-only, the first router generates an OSPF LSA that includes the address for the network but does not include the designated network mask, to permit installation of the address in a RIB upon receipt of the OSPF LSA at the one or more second routers.

    Abstract translation: 在一个实施例中,第一路由器确定将第一路由器耦合到一个或多个第二路由器的网络是否是仅运输,其中,传输仅指示仅连接路由器以提供从路由器到路由器的数据传输。 当网络仅传输时,第一路由器生成包括网络地址和指定网络掩码的开放最短路径优先(OSPF)链路状态通告(LSA)。 指定的网络桅杆作为仅传输标识操作,其指示在一个或多个第二路由器上接收到OSPF LSA时,该地址不应安装在路由信息库(RIB)中。 当网络不通过时,第一个路由器生成包含网络地址但不包括指定网络掩码的OSPF LSA,以便在接收到OSPF LSA时在一个RIB中安装该地址 或更多的第二路由器。

    Hash-based key distribution
    8.
    发明授权

    公开(公告)号:US12069164B2

    公开(公告)日:2024-08-20

    申请号:US16570791

    申请日:2019-09-13

    Abstract: A method for securing communications for a given network is provided. The method comprises by at least one node(i) of the network configured to utilize pairwise keys: generating a set of encryption keys; and transmitting the set of encryption keys to a controller for the network; by the controller, executing a key selection process wherein for each node(j) in the network an encryption key J is selected from the set of encryption keys; assigning the encryption key J to the node(j); and transmitting the selected encryption key J to the node(j); by each node(j), generating an encryption key I to the node(i); and sending the encryption key I to the node(i) via the controller.

    SYSTEM AND METHOD OF PROVIDING POLICY SELECTION IN A NETWORK

    公开(公告)号:US20220086083A1

    公开(公告)日:2022-03-17

    申请号:US17534101

    申请日:2021-11-23

    Abstract: Disclosed are systems and methods for providing policy selection in a software defined network. An example method includes registering, by an enterprise controller on an enterprise domain, in a shared mapping system on a service provider domain, one or more entries specifying one or more services for one or more classes of traffic to yield registered entries, reading, by a service provider controller, from the shared mapping system, the registered entries, posting, by the service provider controller, the one or more entries to one or more routing tables at a software-defined wide area network of the service provider domain and receiving a request, by a mobile node on the enterprise domain, of a specific service for a particular class of packets according to a classification of the particular class of packets based on a particular label defined in the registered entries for the specific service.

    METHOD AND SYSTEM FOR KEY GENERATION, DISTRIBUTION AND MANAGEMENT

    公开(公告)号:US20210152344A1

    公开(公告)日:2021-05-20

    申请号:US17162473

    申请日:2021-01-29

    Abstract: A method for securing communications for a given network topology is provided. The method comprises generating by a node N(i) of the network, security parameters for the node N(i);transmitting by the node N(i), said security parameters to a controller for the network; maintaining by the controller said security parameters for the node N(i);receiving by the controller a request from a node N(j) for the security parameters for the node N(i); retrieving by the controller the security parameters for the node N(i); and transmitting by the controller said security parameters to the node N(j).

Patent Agency Ranking