IP Library Granted Patent US 8,296,846
Granted Patent B2
US 8,296,846 · App. 12/500,519 · Granted Oct 23, 2012

Apparatus and method for associating categorization information with network traffic to facilitate application level processing

Assignee: CPacket Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,296,846
App. No.
12/500,519
Granted
Oct 23, 2012
Kind
B2
Abstract

An apparatus is described that associates categorization information with network traffic to facilitate application level processing through processing of network traffic in accordance with provisioned rules and policies. The apparatus includes a plurality of microcode controlled state machines, wherein at least one microcode state machine processes at least one input data field using a hash function to generate a hash identifier. This embodiment further includes a distribution circuit that routes input data to the plurality of microcode controlled state machines, such that at least one individual microcode controlled state machine applies a rule to the input data to produce the at least one input data field, and to produce modification instructions based on the hash identifier. This embodiment further includes a first circuit that appends the hash identifier to the input data to produce modified input data based on the modification instructions, and that routes the modified input data in accordance with an output routing strategy. Advantageously, the apparatus provides an architectural framework well suited to a low cost, high speed, robust implementation of flexible, advanced network security and monitoring features and network traffic analysis.

Claims (23)

1. An apparatus to facilitate application level processing of network traffic, comprising:

a first circuit that processes at least one input data field using a hash function to generate a hash identifier;

a plurality of microcode controlled state machines;

a distribution circuit that routes input data to the plurality of microcode controlled state machines, such that at least one individual microcode controlled state machine applies a rule to the input data to produce the at least one input data field, and to produce modification instructions based on the hash identifier; and

a second circuit that appends the hash identifier to the input data to produce modified input data based on the modification instructions, and that transmits the modified input data such that the hash identifier is available for reuse by another circuit to facilitate processing of the modified input data.

2. The apparatus of claim 1 , wherein the second circuit routes the modified input data by re-directing or duplicating the modified input data.

3. The apparatus of claim 1 , further comprising a management port, wherein the management port receives the modified input data from the second circuit.

4. The apparatus of claim 3 , wherein the second circuit includes an output circuit that appends the hash identifier to the input data to produce modified input data based on the modification instructions, and that provides the modified input data to the management port.

5. The apparatus of claim 1 , wherein the input data includes a packet comprising a header and a payload, and the at least one input data field includes at least one field of the header.

6. The apparatus of claim 5 , wherein the rule has bitwise granularity across the header and the payload of the packet.

7. The apparatus of claim 5 , wherein the hash identifier is appended to the header of the packet.

8. The apparatus of claim 7 , wherein the hash identifier is associated with a packet type or a packet flow.

9. An apparatus to facilitate application level processing of network traffic, comprising:

a plurality of microcode controlled state machines, wherein at least one microcode state machine processes at least one input data field using a hash function to generate a hash identifier;

a distribution circuit that routes input data to the plurality of microcode controlled state machines, such that at least one individual microcode controlled state machine applies a rule to the input data to produce the at least one input data field, and to produce modification instructions based on the hash identifier; and

a first circuit that appends the hash identifier to the input data to produce modified input data based on the modification instructions, and that transmits the modified input data such that the hash identifier is available for reuse by another circuit to facilitate processing of the modified input data.

10. The apparatus of claim 9 , wherein the first circuit routes the modified input data by re-directing or duplicating the modified input data.

11. The apparatus of claim 9 , further comprising a management port, wherein the management port receives the modified input data from the first circuit.

12. The apparatus of claim 11 , wherein the first circuit includes an output circuit that appends the hash identifier to the input data to produce modified input data based on the modification instructions, and that provides the modified input data to the management port.

13. The apparatus of claim 9 , wherein the input data includes a packet comprising a header and a payload, and the at least one input data field includes at least one field of the header.

14. The apparatus of claim 13 , wherein the rule has bitwise granularity across the header and the payload of the packet.

15. The apparatus of claim 13 , wherein the hash identifier is appended to the header of the packet.

16. The apparatus of claim 15 , wherein the hash identifier is associated with a packet type or a packet flow.

Assignments (10)
SECURITY INTEREST Recorded Jan 31, 2024
From: CPACKET NETWORKS INC.
To: TRINITY CAPITAL INC., AS COLLATERAL AGENT
Reel/Frame 066313/0479 →
RELEASE OF SECURITY INTEREST Recorded Jan 30, 2024
From: NH EXPANSION CREDIT FUND HOLDINGS LP
To: CPACKET NETWORKS INC.
Reel/Frame 066296/0675 →
SECURITY INTEREST Recorded Apr 17, 2020
From: CPACKET NETWORKS INC.
To: WESTERN ALLIANCE BANK
Reel/Frame 052424/0412 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2019
From: PARTNERS FOR GROWTH V, L.P.
To: CPACKET NETWORKS INC.
Reel/Frame 050953/0721 →
SECURITY INTEREST Recorded Nov 5, 2019
From: CPACKET NETWORKS, INC.
To: NH EXPANSION CREDIT FUND HOLDINGS LP
Reel/Frame 050924/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 18, 2019
From: SILICON VALLEY BANK
To: CPACKET NETWORKS INC.
Reel/Frame 050764/0597 →
SECURITY INTEREST Recorded Oct 27, 2017
From: CPACKET NETWORKS INC.
To: PARTNERS FOR GROWTH V, L.P.
Reel/Frame 043975/0953 →
SECURITY INTEREST Recorded Aug 3, 2014
From: CPACKET NETWORKS INC.
To: SILICON VALLEY BANK
Reel/Frame 033463/0506 →
SECURITY AGREEMENT Recorded Jun 8, 2012
From: CPACKET NETWORKS INC.
To: SILICON VALLEY BANK
Reel/Frame 028343/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2009
From: KAY, RONY
To: CPACKET NETWORKS, INC.
Reel/Frame 023271/0832 →
Continuity (3)
Continuation In Part 11483196 · Jul 7, 2006
Continuation In Part 11208022 · Aug 19, 2005
Related Publication 20100011434A1 · Jan 14, 2010