IP Library Granted Patent US 8,271,640
Granted Patent B2
US 8,271,640 · App. 12/944,600 · Granted Sep 18, 2012

Domain isolation through virtual network machines

Assignee: Ericsson AB
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,271,640
App. No.
12/944,600
Granted
Sep 18, 2012
Kind
B2
Abstract

A method and device for communicating information resources between subscriber end stations and nodes belonging to different network domains is described. The device instantiates different virtual network machines for different network domains using separate independently administrable network databases. Each of the administrable chores of the separate independently administrable network databases includes the assignment of access control and the configuration of the policies for those network databases. The policies include traffic filtering policies to indicate what kind of information payloads can be carried, traffic and route filtering policies to indicate what paths through the network will be used for each payload carried. Each of the network domains includes one of the different virtual network machines and each of the different network domains is virtually isolated from other network domains.

Claims (30)

1. A single network device to act as an intermediate station comprising:

a plurality of transceivers to communicate information resources between subscriber end stations and nodes belonging to different network domains; and

a non-transitory machine-readable medium having stored therein a set of instructions to cause the single network device to, instantiate different virtual network machines for the different network domains,

wherein each of the different virtual network machines is one of a virtual router and a virtual bridge,

wherein each of the different virtual network machines has a separate independently administrable network database,

wherein administrative chores of the separate independently administrable network databases include an assignment of access control and a configuration of policies for the separate independently administrable network databases,

wherein the access control comprises user identifiers such as user names, passwords, and unique keys,

wherein the policies comprise traffic filtering policies to indicate what kind of information payloads can be carried, and traffic and route filtering policies to indicate what paths through the different network domains will be used for each payload carried, and

wherein each of the different network domains is to comprise a plurality of nodes and links that include one of the different virtual network machines, and each of the different network domains is virtually isolated from the other different network domains, and

couple different ones of the subscriber end stations to different ones of the different virtual network machines through dynamic bindings,

communicate information resources of different ones of the subscriber end stations using the virtual network machines to which those subscriber end stations are currently coupled, and

record subscriber activity for accounting.

2. The single network device of claim 1 , wherein a same administrative authority may administer more than one of the different network domains.

3. The single network device of claim 1 , wherein at least one of the subscriber end stations can be coupled to more than one of the different virtual network machines.

4. The single network device of claim 1 , wherein each of the separate independently administrable network databases includes layer 2 addressing, layer 2 connections, bridge filters, layer 3 addressing, layer 3 connections, address translation policies, access policies, routing configuration, and routing protocols.

5. The single network device of claim 1 , wherein the policies further comprises:

security policies to ensure integrity of the information payloads.

6. A network comprising:

a plurality of different network domains, wherein each of the different network domains comprises a plurality of nodes and links and each of the different network domains is virtually isolated from other different network domains;

a plurality of subscriber end stations; and

a single network device coupled between nodes of the different network domains and the plurality of subscriber end stations, the single network device having different virtual network machines belonging to the different network domains, wherein each of the different virtual network machines is one of a virtual router and a virtual bridge, wherein different ones of the subscriber end stations are coupled to different ones of the different virtual network machines through dynamic bindings, wherein the different virtual network machines communicate information resources between the subscriber end stations and nodes of the network domain to which that virtual network machine belongs, and wherein the different virtual network machines record subscriber activity, and

separate independently administrable network databases for each of the different virtual network machines,

wherein administrative chores of the separate independently administrable network databases include an assignment of access control and a configuration of policies for the separate independently administrable network databases,

wherein the access control comprises user identifiers such as user names, passwords, and unique keys, and

wherein the policies comprise traffic filtering policies to indicate what kind of information payloads can be carried, and traffic and route filtering policies to indicate what paths through the different network domains will be used for each payload carried.

7. The network of claim 6 , wherein a same administrative authority administers more than one of the different network domains.

8. The network of claim 6 , wherein at least one of the subscriber end stations can be coupled to more than one of the different virtual network machines.

9. The network of claim 6 , wherein each of the separate independently administrable network databases includes layer 2 addressing, layer 2 connections, bridge filters, layer 3 addressing, layer 3 connections, address translation policies, access policies, routing configuration, and routing protocols.

10. The network of claim 6 , wherein the policies further comprises:

security policies to ensure integrity of the information payloads.

Continuity (4)
Division 11869746 · Oct 9, 2007
Continuation 10461761 · Jun 12, 2003
Continuation 09220413 · Dec 24, 1998
Related Publication 20110060819A1 · Mar 10, 2011