IP Library › Granted Patent US 11,818,044
Granted Patent B2
US 11,818,044 · App. 17/377,047 · Granted Nov 14, 2023

Path signatures for data flows

Inventors: Atri Indiresan (Sunnyvale, CA); Frank Brockners (Cologne, DE); Shwetha Subray Bhandari (Bangalore, IN)
Assignee: Cisco Technology, Inc.
H04L45/7453H04L41/0695H04L47/2483H04L61/5007
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,044
App. No.
17/377,047
Granted
Nov 14, 2023
Kind
B2
Abstract

This disclosure describes various methods, systems, and devices related to identifying path changes of data flows in a network. An example method includes receiving, at a node, a packet including a first value. The method further includes generating a second value by inputting the first value and one or more node details into a hash function. The method includes replacing the first value with the second value in the packet. The packet including the second value is forwarded by the node.

Claims (61)

1. A method, comprising:

receiving, from a first node and at a second node, a first packet comprising a first value;

generating a second value by inputting the first value and data associated with the second node into a hash function;

replacing the first value with the second value in the first packet;

forwarding, to a third node and by the second node, the first packet comprising the second value;

receiving, at the second node, a second packet comprising a third value;

identifying that the third value is different than the first value; and

based on identifying that the third value is different than the first value, transmitting, by the second node, an alert to a network manager.

2. The method of claim 1 , wherein a size of the first value is equivalent to a size of the second value.

3. The method of claim 1 , wherein each of the size of the first value and the size of the second value is 32 bits or 64 bits.

4. The method of claim 1 , wherein the first value is a first signature and the second value is a second signature.

5. The method of claim 1 , wherein replacing the first value with the second value comprises replacing the first value in a data field having a fixed size with the second value, the data field comprising at least one of an In-situ OAM (IOAM) field, an In-Network Telemetry (INT) field, an Inband Flow Analyzer (IFA) field, or an In-situ Flow Information Telemetry (IFIT) field.

6. The method of claim 1 , further comprising:

receiving, at the second node, a third packet comprising a fourth value;

generating a fifth value by inputting the fourth value and the data associated with the second node into the hash function;

identifying that the fifth value is different than the second value; and

based on identifying that the fifth value is different than the second value, transmitting, by the second node, an alert to a network manager.

7. The method of claim 6 , wherein the third node identifies that the fifth value is different than the second value.

8. The method of claim 1 , wherein a size of the first value is equivalent to a size of the third value.

9. A system, comprising

at least one processor; and

memory storing instructions that, when executed by the at least one processor, cause the at least one processor to perform operations comprising:

receiving, from a first node and at a second node, a first packet comprising a first value;

generating a second value by inputting the first value and data associated with the second node into a hash function;

replacing the first value with the second value in the first packet;

forwarding, to a third node and by the second node, the first packet comprising the second value;

receiving, at the second node, a second packet comprising a third value;

generating a fourth value by inputting the third value and the data associated with the second node into the hash function;

identifying that the fourth value is different than the second value; and

based on identifying that the fourth value is different than the second value, transmitting, by the second node, an alert to a network manager.

10. The system of claim 9 , wherein a size of the first value is equivalent to a size of the second value.

11. The system of claim 9 , wherein each of the size of the first value and the size of the second value is 32 bits or 64 bits.

12. The system of claim 9 , wherein replacing the first value with the second value comprises replacing the first value in a data field having a fixed size with the second value, the data field comprising at least one of an In-situ OAM (IOAM) field, an In-Network Telemetry (INT) field, an Inband Flow Analyzer (IFA) field, or an In-situ Flow Information Telemetry (IFIT) field.

13. The system of claim 9 , wherein the operations further comprise:

receiving, at the second node, a third packet comprising a fifth value;

identifying that the fifth value is different than the third value; and

based on identifying that the fifth value is different than the third value, transmitting, by the second node, an alert to a network manager.

14. The system of claim 9 , wherein the third node identifies that the fourth value is different than the second value.

15. The system of claim 9 , wherein a size of the first value is equivalent to a size of the third value.

16. A system, comprising:

a first node comprising:

at least one processor; and

memory storing instructions that, when executed by the at least one processor, cause the at least one processor to perform operations comprising:

receiving, from a second node, a first packet;

identifying a first value in a first In-situ OAM (IOAM) field of the first packet;

generating a second value by inputting the first value and data associated with the first node into a hash function, a size of the first value being equivalent to a size of the second value;

replacing the first value with the second value in the first IOAM field of the first packet;

based on replacing the first value with the second value, forwarding the first packet to a third node;

receiving a second packet from the second node;

identifying a third value in a second IOAM field of the second packet;

identifying that the third value is different than the first value; and

based on determining that the third value is different than the first value, transmitting an alert to a network manager.

17. The system of claim 16 , wherein the at least one processor is at least one first processor, the memory is first memory, the instructions are first instructions, the operations are first operations, and the system further comprises:

the third node comprising:

at least one second processor; and

second memory storing second instructions that, when executed by the at least one second processor, cause the at least one second processor to perform second operations comprising:

receiving the first packet comprising the second value from the first node;

receiving a third packet from the first node;

identifying a fourth value in a third IOAM field of the third packet;

identifying that the fourth value is different than the second value; and

based on determining that the fourth value is different than the second value, transmitting an alert to a network manager.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2021
From: INDIRESAN, ATRI; BROCKNERS, FRANK; BHANDARI, SHWETHA SUBRAY
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056871/0727 →
Continuity (2)
Continuation 16661540 · Oct 23, 2019
Related Publication 20210344598A1 · Nov 4, 2021