US2019007316A1PendingUtilityA1

Controller for software defined network

Assignee: TALLAC NETWORKS INCPriority: Apr 9, 2014Filed: Aug 20, 2018Published: Jan 3, 2019
Est. expiryApr 9, 2034(~7.7 yrs left)· nominal 20-yr term from priority
H04L 61/2557H04L 61/2514H04L 61/103H04L 12/4633H04L 61/2517H04L 61/2015H04L 45/7453H04L 61/5014
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A protocol such as OpenFlow providing communication between an SDN framework controller on one network and a data plane device for another network can be used to modify or process network packets so that an external application or server can communicate with the controller and obtain information needed to uniquely associate the packets with particular end-stations even after those packets have traversed a NAT router.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A controller for a Software Defined Networking (SDN) network, the controller comprising:
 an identifier module configured to determine identifying information of end-stations connected to the controller through a NAT device;   an assignment module configured to assign distinct parameters to end-stations on the SDN network;   a database associating the identifying information respectively with the distinct parameters; and   an interface configured to provide a server outside the SDN network with a mapping of one of the distinct parameters to the identifying information of the end-station to which the distinct parameter was assigned,   the controller being configured to program a data-path device to modify packets sent through the NAT device so that the packets as modified embody the distinct parameters assigned to the end-stations that sent the packets.   
     
     
         2 . The controller of  claim 1 , wherein the distinct parameter assigned to an end-station is selected from a group consisting of:
 a destination IP address;   a TCP port;   a value of an IP options field; and   a hash value calculated using packet content.   
     
     
         3 . The controller of  claim 1 , wherein the server is a captive portal server. 
     
     
         4 . The controller of  claim 1 , wherein the SDN network is a private network, and the server outside the SDN network connects to the SDN network through a second network and the NAT device. 
     
     
         5 . The controller of  claim 4 , wherein the interface of the controller connects to the server through the second network. 
     
     
         6 . The controller of  claim 5 , wherein the second network comprises a public network. 
     
     
         7 . The controller of  claim 1 , wherein the identifier module determines the identifying information of each of the end-stations from encapsulated HTTP packets sent through the NAT device. 
     
     
         8 . A process comprising:
 receiving, at a controller of a Software-Defined Networking (SDN) network, a message from a data-path device on the SDN network;   from the message at the controller, identifying an end-station on the SDN network;   the controller mapping a packet characteristic to the end-station identified;   programming the data-path device to modify packets from the end-station so that the packets from the end-station have the packet characteristic after passing through a network address translation (NAT) device; and   conveying to a server seeking to distinguish end-stations that the packet characteristic maps to the end-station, the server being outside the SDN network and receiving the packets from the end-station after the packets pass through the data-path device and the NAT device.   
     
     
         9 . The process of  claim 8 , wherein:
 the packet characteristic is a communication parameter is selected from a group consisting of a destination IP address, a source port number, and an IP Options value; and   the data-path device is programmed to modify a destination IP address, a source port number, or an IP Options value of packets from the end-station to match the packet characteristic mapped to the end-station.   
     
     
         10 . The process of  claim 8 , wherein the packet characteristic is a hash value of contents of the packet. 
     
     
         11 . A process comprising:
 receiving, at a controller on a first network, a message from a data-path device on a second network, wherein the message encapsulates a packet that is from an end-station on the second network and is encapsulated before the packet passes through a network address translation (NAT) device that is between the second network and the first network;   the controller determining from a header of the packet identifying information that identifies the end-station, calculating a hash value using contents of the first packet, and storing the identifying information and the hash value;   sending a second packet through the NAT device to a server;   the server calculating the hash value using contents of the second packet as received by the server; and   the server and the controller communicating the hash value and information to identify the end-station to the server.   
     
     
         12 . The process of  claim 11 , wherein the contents of the second packet are identical to the contents of the first packet. 
     
     
         13 . The process of  claim 11 , further comprising the controller modifying the first packet to construct the second packet, wherein the controller modifies the content of the first packet to ensure the hash value differs from other hash values that the controller has stored for other packets.

Join the waitlist — get patent alerts

Track US2019007316A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.