IP Library › Granted Patent US 8,077,723
Granted Patent B2
US 8,077,723 · App. 12/780,695 · Granted Dec 13, 2011

Packet processing in a multiple processor system

Assignee: Juniper Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,077,723
App. No.
12/780,695
Granted
Dec 13, 2011
Kind
B2
Abstract

Packet processing is provided in a multiple processor system including a first processor to processing a packet and to create a tag associated with the packet. The tag includes information about the processing of the packet. A second processor receives the packet subsequent to the first processor and processes the packet using the tag information.

Claims (72)

1. A system comprising:

a first engine to:

route a packet to a second engine, and

route the packet to a third engine, after receiving the packet from the second engine;

the second engine to:

process the packet, and

associate a tag with the packet, the tag including information about the processing of the packet; and

the third engine to:

process the packet using the information included in the tag,

where the second engine and the third engine comprise a firewall processing engine, an intrusion detection system, or a network address translation (NAT) engine,

where the second engine is different than the third engine, and

where the second engine and the third engine are included on one integrated circuit.

2. The system of claim 1 , where the one integrated circuit includes a central processing unit.

3. The system of claim 1 , where the first engine is further to:

determine routing of the packet using the information included in the tag.

4. The system of claim 3 , where the tag includes information associated with a next engine that is to process the packet, and

where the first engine is further to route the packet to the next engine based on the information associated with the next engine.

5. The system of claim 4 , where the information, associated with the next engine, includes identification information for the next engine.

6. The system of claim 1 , where the first engine includes a flow-based router.

7. The system of claim 1 , where the packet includes a first packet and the tag includes a first tag,

where the second engine is to process a second packet, and

where the third engine is to:

process the second packet, and

associate a second tag with the second packet, the second tag including information associated with processing of the second packet by the third engine, or including information associated with processing of the second packet by the second engine and processing of the second packet by the third engine.

8. The system of claim 1 , where the third engine is further to:

add data to the tag, the data including information, for at least one subsequent engine, associated with processing of the packet by the third engine.

9. A method comprising:

routing, using a first engine, a packet to a second engine that is different than the first engine;

processing, using the second engine, the packet;

associating, using the second engine, a tag with the packet,

where the tag includes information associated with the processing of the packet using the second engine;

routing, using the first engine and based on the information included in the tag, the packet to a third engine, after receiving the packet from the second engine,

where the third engine is different than the first engine and the second engine; and

processing, using the third engine and based on the information included in the tag, the packet,

where the second engine and the third engine include a firewall processing engine, an intrusion detection system, or a network address translation (NAT) engine.

10. The method of claim 9 , where the information, included in the tag, includes identification information for another engine to process the packet after the packet has been processed using the third engine,

the method further comprising:

routing the packet to the other engine based on the identification information for the other engine.

11. The method of claim 9 , where the second engine and the third engine are included on one integrated circuit, and where the one integrated circuit includes a central processing unit.

12. The method of claim 9 , where the tag further includes information associated with a fourth engine that is to process the packet, and

the method further comprising:

routing the packet to the fourth engine using the information associated with the fourth engine.

13. The method of claim 9 , further comprising:

removing the tag; and

routing the packet to a destination of the packet when the tag is removed.

14. The method of claim 9 , where the packet corresponds to a first packet and the tag corresponds to a first tag, and

where the method further comprises:

processing a second packet using the second engine;

processing the second packet using the third engine; and

associating a second tag with the second packet, the second tag including information associated with processing of the second packet using the second engine and processing of the second packet using the third engine.

15. The method of claim 9 , further comprising:

adding data to the tag, the data including information associated with processing of the packet using the third engine.

16. The method of claim 9 , further comprising:

determining, prior to associating the tag with the packet, whether the packet is allowed to proceed to the third engine; and

generating the tag when the packet is allowed to proceed to the third engine.

17. A device comprising:

a first engine to:

route a packet to a second engine that is different than the first engine, and

route the packet to a third engine, after receiving the packet from the second engine, where the third engine is different than the first engine and the second engine;

the second engine to:

process the packet, and

associate a tag with the packet,

where the tag includes information associated with the processing of the packet; and

the third engine to:

process the packet using the information included in the tag,

where the second engine and the third engine comprise a firewall processing engine, an intrusion detection system, or a network address translation (NAT) engine, and

where the second engine and the third engine are included on one integrated circuit.

18. The device of claim 17 , where the one integrated circuit includes a central processing unit.

19. The device of claim 17 , where the second engine is further to:

generate the tag when the packet is allowed to proceed to the third engine.

20. The device of claim 17 , where the tag includes identification information associated with another engine that is to process the packet after the packet has been processed using the third engine, and

where the first engine is to route the packet to the other engine based on the identification information associated with the other engine.

Continuity (3)
Continuation 11338732 · Jan 25, 2006
Provisional Application 60704432 · Aug 2, 2005
Related Publication 20100220727A1 · Sep 2, 2010