IP Library Granted Patent US 8,259,628
Granted Patent B2
US 8,259,628 · App. 13/226,306 · Granted Sep 4, 2012

Method and system for handling connection setup in a network

Assignee: Broadcom Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,259,628
App. No.
13/226,306
Granted
Sep 4, 2012
Kind
B2
Abstract

Certain embodiments of a method and system for handling connection setup in a network may comprise a network interface hardware device (NIHW) that may be operable to receive a services list and/or connection acceptance criteria from a first guest operating system running on a host system, receive a connection request from a second guest operating system running on the host system, and determine whether to allow establishment of the requested connection based on one or both of the services list and the connection acceptance criteria. The determination may be made prior to or during connection set up. The NIHW may maintain a connection state comprising information regarding set up of the requested connection. The services list may comprise one or more of a local network address, a local transport address, a network protocol, and a transport protocol. The communicated acceptance criteria may comprise packet filtering operations and/or security operations.

Claims (32)

1. A method for data communication, the method comprising:

in a network interface hardware device:

receiving connection acceptance criteria from a guest operating system running virtually on a host system;

determining whether to allow establishment of a requested connection from a remote peer based on said received connection acceptance criteria; and

maintaining a connection state that comprises information regarding set up of said requested connection.

2. The method according to claim 1 , comprising receiving a services list from said guest operating system.

3. The method according to claim 2 , comprising determining whether to allow establishment of said requested connection from said remote peer based on said received services list prior to or during connection set up.

4. The method according to claim 1 , wherein said services list comprises one or more of: a local network address, a local transport address, a network protocol, and/or a transport protocol.

5. The method according to claim 1 , comprising determining whether to allow establishment of said requested connection from said remote peer based on receiving, from said guest operating system, an indication regarding results from one or more of: a resident packet filtering, a denial of service mitigation service, and/or a security and cryptography service.

6. The method according to claim 1 , comprising tearing down an established said requested connection based on an indication from said guest operating system running virtually on said host, a fatal network event, or a signal from said remote peer.

7. The method according to claim 1 , comprising making said connection state available to one or more other guest operating systems running virtually on said host to enable said one or more other guest operating systems to tear down an established said requested connection.

8. The method according to claim 1 , wherein said communicated acceptance criteria comprises one or more of: qualifying remote IP addresses, packet filtering and/or security operations.

9. The method according to claim 1 , comprising, subsequent to receiving an indication that said guest operating system has rejected said requested connection, discontinuing exchanging network primitives and discarding associated said connection state information.

10. The method according to claim 1 , comprising, subsequent to establishing said requested connection, tearing down said requested connection and discarding associated said connection state information upon receiving an indication that said requested connection has been rejected by said guest operating system.

11. A system for data communication, the system comprising:

one or more circuits for use in a network interface hardware device, said one or more circuits being operable to:

receive connection acceptance criteria from a guest operating system running virtually on a host system;

determine whether to allow establishment of a requested connection from a remote peer based on said received connection acceptance criteria; and

maintain a connection state that comprises information regarding set up of said requested connection.

12. The system according to claim 11 , wherein said one or more circuits are operable to receive a services list from said guest operating system.

13. The system according to claim 12 , wherein said one or more circuits are operable to determine whether to allow establishment of said requested connection from said remote peer based on said received services list prior to or during connection set up.

14. The system according to claim 11 , wherein said services list comprises one or more of: a local network address, a local transport address, a network protocol, and/or a transport protocol.

15. The system according to claim 11 , wherein said one or more circuits are operable to determine whether to allow establishment of said requested connection from said remote peer based on receiving, from said guest operating system, an indication regarding results from one or more of: a resident packet filtering, a denial of service mitigation service, and/or a security and cryptography service.

16. The system according to claim 11 , wherein said one or more circuits are operable to tear down an established said requested connection based on an indication from said guest operating system running virtually on said host, a fatal network event, or a signal from said remote peer.

17. The system according to claim 11 , wherein said one or more circuits are operable to make said connection state available to one or more other guest operating systems running virtually on said host to enable said one or more other guest operating systems to tear down an established said requested connection.

18. The system according to claim 11 , wherein said communicated acceptance criteria comprises one or more of: qualifying remote IP addresses, packet filtering and/or security operations.

19. The system according to claim 11 , wherein said one or more circuits are operable to discontinue exchanging network primitives and discard associated said connection state information subsequent to receiving an indication that said guest operating system has rejected said requested connection.

20. A method for data communication, the method comprising:

in a network interface hardware device:

receiving a services list from a guest operating system running virtually on a host system;

determining whether to allow establishment of a requested connection from a remote peer based on said received services list prior to or during connection set up; and

maintaining a connection state that comprises information regarding set up of said requested connection.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF MERGER TO 09/05/2018 PREVIOUSLY RECORDED AT REEL: 047230 FRAME: 0133. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047630/0456 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047230/0133 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2012
From: EL ZUR, URI
To: BROADCOM CORPORATION
Reel/Frame 028333/0726 →
Continuity (5)
Continuation 12625313 · Nov 24, 2009
Continuation 11452645 · Jun 14, 2006
Provisional Application 60690465 · Jun 14, 2005
Provisional Application 60718418 · Sep 19, 2005
Related Publication 20120036272A1 · Feb 9, 2012