Invention Grant
- Patent Title: Dynamically provisioning middleboxes
- Patent Title (中): 动态配置中间盒
-
Application No.: US13171119Application Date: 2011-06-28
-
Publication No.: US08923294B2Publication Date: 2014-12-30
- Inventor: H. Jonathan Chao , Kang Xi
- Applicant: H. Jonathan Chao , Kang Xi
- Applicant Address: US NY Brooklyn
- Assignee: Polytechnic Institute of New York University
- Current Assignee: Polytechnic Institute of New York University
- Current Assignee Address: US NY Brooklyn
- Agency: Straub & Pokotylo
- Agent John C. Pokotylo
- Main IPC: H04L12/28
- IPC: H04L12/28 ; H04L12/56 ; G06F15/16 ; G06F15/173 ; H04L29/08 ; H04L12/723 ; H04L12/721

Abstract:
Hybrid security architecture (HSA) provides a platform for middlebox traversal in the network. The HSA decouples the middlebox control from network forwarding. More specifically, such embodiments may receive a data packet having a packet header including an Ethernet header identifying source and destination addresses in the network. A traffic type of the data packet is determined. Then, layer-2 forwarding information, which encodes a set of non-forwarding network service provider middleboxes in the network to be traversed by the data packet, is determined based on the traffic type. The layer-2 forwarding information is inserted into the Ethernet header and the data packet is forwarded into the network. The data packet will then traverse, according to the layer-2 forwarding information, a sequence of the middleboxes in the network, wherein at least one non-forwarding network service will be provided by each of the middleboxes to the data packet in a sequence.
Public/Granted literature
- US20130003735A1 DYNAMICALLY PROVISIONING MIDDLEBOXES Public/Granted day:2013-01-03
Information query