IP Library Granted Patent US 7,853,952
Granted Patent B2
US 7,853,952 · App. 12/180,661 · Granted Dec 14, 2010

Dynamic partitioning of network resources

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,853,952
App. No.
12/180,661
Granted
Dec 14, 2010
Kind
B2
Abstract

Methods and apparatuses allowing for dynamic partitioning of a network resource among a plurality of users. In one embodiment, the invention involves recognizing new users of a network resource; creating user partitions on demand for new users, wherein the user partition is operable to allocate a portion of a network resource; and, reclaiming inactive user partitions for subsequent new users.

Claims (45)

1. A method, comprising:

receiving, at a network device, a packet of a data flow between a first host and a second host;

determining, relative to the network device, which of the first and second hosts is an inside host and which of the first and second hosts is an outside host;

accessing a memory space comprising a plurality of partition objects, wherein the plurality of partition objects includes one or more dynamic partition objects, each one of the one or more dynamic partition objects having at least one attribute defining a first allocation of network bandwidth across all data flows associated with the one of the one or more dynamic partition objects and a side parameter indicating which of the inside and outside host is a user, and a second attribute defining user partition allocations of the network bandwidth within the first allocation;

selecting a partition object from the plurality of partition objects based on one or more attributes of the data flow; and

if the selected partition object is a dynamic partition object,

identifying either the first or second host as a user based on the side parameter of the selected dynamic partition object;

creating, if no user partition object exists for the identified user, a user partition object as a child of the selected dynamic partition object in the memory space for the identified user, wherein the user partition object is accessible by a data flow control mechanism to allocate utilization of the network bandwidth within the first allocation, according to the second attribute defined in the selected dynamic partition object, across all data flows associated to the selected dynamic partition object and the identified user.

2. The method of claim 1 wherein the determining, relative to the network device, which of the first and second hosts is an inside host and which of the first and second hosts is an outside host is based on source and destination addresses of the packet and a direction of the packet flow.

3. The method of claim 1 wherein the user partition object is configurable based on a characteristic of the identified user's utilization of the network bandwidth.

4. The method of claim 1 wherein the user partition object is operable to provide a minimum allocation of the network bandwidth to the identified user.

5. The method of claim 1 wherein the user partition object is operable to limit utilization of the network bandwidth.

6. The method of claim 1 further comprising

accessing a traffic class database storing a plurality of traffic class definitions;

matching the data flow to a traffic class definition of the plurality of traffic class definitions; and wherein the partition object is selected based on the traffic class definition to which the data flow is matched.

7. The method of claim 6 wherein the first host is an inside server operative to establish data flows corresponding to a first traffic class definition of the plurality of traffic class definitions, and wherein a first dynamic partition object of the one or more dynamic partition objects is configured to correspond to the first traffic class definition and the side parameter of the first dynamic partition object is set to identify inside hosts as users.

8. The method of claim 1 further comprising deleting inactive user partition objects from the partition object space.

9. The method of claim 8 wherein an inactive user partition object is identified in relation to a threshold period of inactivity.

10. The method of claim 1 further comprising reclaiming inactive user partition objects from the partition object space as required for new users.

11. The method of claim 10 wherein an inactive user partition object is identified in relation to a threshold period of inactivity.

12. A method, comprising:

receiving, at an interface of a plurality of interfaces of a network device, a packet of a data flow between a first host and a second host;

accessing a memory space comprising a plurality of partition objects, wherein the plurality of partition objects includes a dynamic partition object having at least one attribute defining a first allocation of network bandwidth across all data flows associated with the dynamic partition object and a parameter identifying an interface of the plurality of interfaces, and a second attribute defining user partition allocations of the network bandwidth within the first allocation;

selecting a partition object from the plurality of partition objects based on one or more attributes of the data flow; and

if the selected partition object is the dynamic partition object,

identifying either the first or second host as a user based on the interface identified in the parameter and the respective relationships between the interface identified in the parameter and the first and second hosts;

creating, if no user partition object exists for the identified user, a user partition object as a child of the selected dynamic partition object in the memory space for the identified user, wherein the user partition object is accessible by a data flow control mechanism to allocate utilization of the network bandwidth within the first allocation, according to the second attribute defined in the selected dynamic partition object, across all data flows associated to the selected dynamic partition object and the identified user.

13. The method of claim 12 wherein the identifying either the first or second host as a user is further based on source and destination addresses of the packet and a direction of the packet flow.

14. The method of claim 12 wherein the user partition object is configurable based on a characteristic of the identified user's utilization of the network bandwidth.

15. The method of claim 12 wherein the user partition object is operable to provide a minimum allocation of the network bandwidth to the identified user.

16. The method of claim 12 wherein the user partition object is operable to limit utilization of the network bandwidth.

17. The method of claim 12 further comprising

accessing a traffic class database storing a plurality of traffic class definitions;

matching the data flow to a traffic class definition of the plurality of traffic class definitions; and wherein the partition object is selected based on the traffic class definition to which the data flow is matched.

18. The method of claim 17 wherein the first host is server corresponding to a first interface operative to establish data flows corresponding to a first traffic class definition of the plurality of traffic class definitions, and wherein a first dynamic partition object of the one or more dynamic partition objects is configured to correspond to the first traffic class definition and the parameter of the first dynamic partition object is set to identify hosts associated with the first interface as users.

19. The method of claim 12 further comprising deleting inactive user partition objects from the partition object space.

20. The method of claim 19 wherein an inactive user partition object is identified in relation to a threshold period of inactivity.

21. The method of claim 12 further comprising reclaiming inactive user partition objects from the partition object space as required for new users.

22. The method of claim 21 wherein an inactive user partition object is identified in relation to a threshold period of inactivity.

23. A method, comprising:

recognizing a new user of network bandwidth based on one or more attributes of at least one packet in a data flow;

accessing a memory space comprising a plurality of partition objects including a dynamic partition object having at least one attribute defining a first allocation of the network bandwidth across all data flows corresponding to the dynamic partition object, and a second attribute defining user partition allocations of the network bandwidth within the first allocation;

selecting a partition object from the plurality of partition objects based on one or more attributes of the data flow; and

if the selected partition object is the dynamic partition object, creating a user partition object as a child of the dynamic partition object on demand for the new user, wherein the user partition object is operable to allocate utilization of the network bandwidth, according to the second attribute defined in the dynamic partition object, across all data flows corresponding to the new user; and,

reclaiming the user partition object after it becomes inactive.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0144 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 16, 2012
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 027727/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2011
From: PACKETEER, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 027307/0603 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2008
From: RIDDLE, GUY
To: PACKETEER, INC.
Reel/Frame 021298/0463 →