US2009046728A1PendingUtilityA1

System and method for delivering security services

Assignee: FORTINET INCPriority: Sep 13, 2000Filed: Oct 27, 2008Published: Feb 19, 2009
Est. expirySep 13, 2020(expired)· nominal 20-yr term from priority
H04L 9/40H04L 63/0272
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for delivering security services. According to one embodiment, multiple virtual routers are established within a service processing switch, which is operable to be logically interposed between a public communications network and multiple subscriber sites. Each of the virtual routers has associated therewith a subset of processing and storage resources of the service processing switch. Subscribers are provided with respective sets of customized application layer services. Subscriber resource isolation is provided by partitioning the virtual routers between the subscribers including allocating and configuring partitions, having subsets of the virtual routers, to the subscribers. Changeable provisioning of processing capacity between the subscribers is provided by dynamically reallocating resources of the service processing switch between the partitions based on comparative processing demands of the customized application layer services.

Claims

exact text as granted — not AI-modified
1 - 18 . (canceled) 
   
   
       19 . A method comprising:
 establishing a plurality of virtual routers within a service processing switch, the service processing switch operable to be logically interposed between a public communications network and a plurality of subscriber sites and provide services to a plurality of subscribers of a service provider, each of the plurality of virtual routers having associated therewith a subset of processing and storage resources of the service processing switch;   providing a first subscriber and a second subscriber of the plurality of subscribers with a first set of customized application layer services and a second set of customized application layer services, respectively, and providing subscriber resource isolation by partitioning the plurality of virtual routers between the first subscriber and the second subscriber including (i) allocating and configuring a first partition, comprising a first subset of the plurality of virtual routers, to the first subscriber and (ii) allocating and configuring a second partition, comprising a second subset of the plurality of virtual routers, to the second subscriber; and   providing changeable provisioning of processing capacity between the first subscriber and the second subscriber by dynamically reallocating resources of the service processing switch between the first partition and the second partition based on comparative processing demands of the first set of customized application layer services and the second set of customized application layer services.   
   
   
       20 . The method of  claim 19 , wherein the first set of customized application layer services comprises one or more of firewall protection, web site hosting, internet services, e-mail services and virtual private network services. 
   
   
       21 . The method of  claim 19 , wherein in said providing changeable provisioning of processing capacity between the first subscriber and the second subscriber is controlled by a services management system of the service provider. 
   
   
       22 . An Internet Protocol (IP) service delivery platform comprising:
 a first service processing switch operable within a first point-of presence (POP) to provide customized application layer services to a plurality of subscribers of a service provider, the first POP being associated with a first site of a first subscriber of the plurality of subscribers and a first site of a second subscriber of the plurality of subscribers, the first service processing switch including a first set of processing resources and having established therein a first set of virtual routers among which the first set of processing resources are initially allocated;   a second service processing switch communicatively coupled with the first service processing switch via a network and operable within a second POP to provide customized application layer services to the plurality of subscribers, the second POP being associated with a second site of the first subscriber and a second site of the second subscriber, the second service processing switch including a second set of processing resources and having established therein a second set of virtual routers among which the second set of processing resources are initially allocated;   wherein isolation between processing resources associated with a first set of customized application layer services being provided to the first subscriber and those associated with a second set of customized application layer services being provided to the second subscriber is accomplished by partitioning of the first set of virtual routers and the second set of virtual routers between the first subscriber and the second subscriber including (i) allocating and configuring a first partition, comprising a first subset of the first set of virtual routers and a first subset of the second set of virtual routers, to the first subscriber and (ii) allocating and configuring a second partition, comprising a second subset of the first set of virtual routers and a second subset of the second set of virtual routers, to the second subscriber; and   wherein the first and second service processing switches are operable to provide changeable provisioning of processing capacity between the first subscriber and the second subscriber by dynamically reallocating the first set of processing resources or the second set of processing resources between the first partition and the second partition based on comparative processing demands of the first subscriber and the second subscriber.   
   
   
       23 . The IP service delivery platform of  claim 22 , wherein the first subscriber is provided with a first virtual private network (VPN) communicatively coupling the first site of the first subscriber with the second site of the first subscriber by establishing a first secure communication channel through the network and interconnecting virtual routers of the first partition. 
   
   
       24 . The IP service delivery platform of  claim 23 , wherein the second subscriber is provided with a second VPN communicatively coupling the first site of the second subscriber with the second site of the second subscriber by establishing a second secure communication channel through the network and interconnecting virtual routers of the second partition. 
   
   
       25 . The IP service delivery platform of  claim 24 , wherein the first secure communication channel and the second secure communication channel are established by sharing a single secure tunnel between the first service processing switch and the second service processing switch. 
   
   
       26 . The IP service delivery platform of  claim 22 , further comprising a services management system communicatively coupled with the first service processing switch and the second service processing switch and wherein said changeable provisioning of processing capacity is responsive to directives issued by the services management system. 
   
   
       27 . A service processing switch operable within a service provider network logically interposed between a public communications network and a plurality of subscriber sites to provide services to a plurality of subscribers of a service provider, the service processing switch comprising:
 a plurality of service blades each having a plurality of processing resources and a plurality of storage resources;   a plurality of virtual routers each having associated therewith a subset of the plurality of processing resources and a subset of the plurality of storage resources;   wherein isolation between those of the plurality of processing resources and those of the plurality of storage resources associated with a first set of customized application layer services being provided to a first subscriber of the plurality of subscribers and those associated with a second set of customized application layer services being provided to a second subscriber of the plurality of subscribers is accomplished by partitioning of the plurality of virtual routers into a first partition and a second partition including (i) allocating and configuring the first partition, comprising a first subset of the plurality of virtual routers, to the first subscriber and (ii) allocating and configuring the second partition, comprising a second subset of the plurality of virtual routers, to the second subscriber; and   wherein the service processing switch is operable to provide changeable provisioning of resource capacity between the first subscriber and the second subscriber by dynamically reallocating the plurality of processing resources or the plurality of storage resources between the first partition and the second partition based on comparative needs of the first subscriber and the second subscriber.   
   
   
       28 . A method comprising:
 a step for establishing a plurality of virtual routers within a service processing switch, the service processing switch operable to be logically interposed between a public communications network and a plurality of subscriber sites and provide services to a plurality of subscribers of a service provider, each of the plurality of virtual routers having associated therewith a subset of processing and storage resources of the service processing switch;   a step for providing a first subscriber and a second subscriber of the plurality of subscribers with a first set of customized application layer services and a second set of customized application layer services, respectively, and providing subscriber resource isolation by partitioning the plurality of virtual routers between the first subscriber and the second subscriber; and   a step for dynamically reallocating resources of the service processing switch to address relative processing demands of the first set of customized application layer services and the second set of customized application layer services.   
   
   
       29 . An Internet Protocol (IP) service delivery platform comprising:
 a first service processing switch means operable within a first point-of presence (POP) for providing customized application layer services to a plurality of subscribers of a service provider, the first POP being associated with a first site of a first subscriber of the plurality of subscribers and a first site of a second subscriber of the plurality of subscribers, the first service processing switch means including a first set of processing resources and having established therein a first set of virtual routers among which the first set of processing resources are initially allocated;   a second service processing switch means, communicatively coupled with the first service processing switch via a network and operable within a second POP, for providing customized application layer services to the plurality of subscribers, the second POP being associated with a second site of the first subscriber and a second site of the second subscriber, the second service processing switch including a second set of processing resources and having established therein a second set of virtual routers among which the second set of processing resources are initially allocated;   wherein isolation between processing resources associated with a first set of customized application layer services being provided to the first subscriber and those associated with a second set of customized application layer services being provided to the second subscriber is accomplished by partitioning of the first set of virtual routers and the second set of virtual routers between the first subscriber and the second subscriber including (i) allocating and configuring a first partition, comprising a first subset of the first set of virtual routers and a first subset of the second set of virtual routers, to the first subscriber and (ii) allocating and configuring a second partition, comprising a second subset of the first set of virtual routers and a second subset of the second set of virtual routers, to the second subscriber; and   wherein the first service processing switch means and the second service processing switch means are further operable to provide changeable provisioning of processing capacity between the first subscriber and the second subscriber by dynamically reallocating the first set of processing resources or the second set of processing resources between the first partition and the second partition based on comparative processing demands of the first subscriber and the second subscriber.   
   
   
       30 . A program storage device readable by a service processing switch, tangibly embodying a program of instructions executable by the service processing switch to perform method steps for providing customized application layer services to a plurality of subscribers of a service provider, said method steps comprising:
 establishing a plurality of virtual routers within the service processing switch, the service processing switch operable to be logically interposed between a public communications network and a plurality of subscriber sites and provide services to the plurality of subscribers, each of the plurality of virtual routers having associated therewith a subset of processing and storage resources of the service processing switch;   providing a first subscriber and a second subscriber of the plurality of subscribers with a first set of customized application layer services and a second set of customized application layer services, respectively, and providing subscriber resource isolation by partitioning the plurality of virtual routers between the first subscriber and the second subscriber including (i) allocating and configuring a first partition, comprising a first subset of the plurality of virtual routers, to the first subscriber and (ii) allocating and configuring a second partition, comprising a second subset of the plurality of virtual routers, to the second subscriber; and   providing changeable provisioning of processing capacity between the first subscriber and the second subscriber by dynamically reallocating resources of the service processing switch between the first partition and the second partition based on comparative processing demands of the first set of customized application layer services and the second set of customized application layer services.

Join the waitlist — get patent alerts

Track US2009046728A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.