US2019044888A1PendingUtilityA1

Methods and apparatus for providing services in a distributed switch

Assignee: JUNIPER NETWORKS INCPriority: Jun 29, 2012Filed: Sep 28, 2018Published: Feb 7, 2019
Est. expiryJun 29, 2032(~5.9 yrs left)· nominal 20-yr term from priority
H04L 49/355H04L 45/54H04L 67/63H04L 49/25H04L 45/38
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In some embodiments, a non-transitory processor-readable medium stores code representing instructions to be executed by a processor. The code causes the processor to receive, at an edge device, a first data unit having a characteristic. The code causes the processor to identify, at a first time, an identifier of a service module associated with the characteristic in response to each entry from a set of entries within a flow table not being associated with the characteristic. The code causes the processor to define an entry in the flow table associated with the characteristic and the identifier of the service module. The code causes the processor to send the first data unit to the service module. The code causes the processor to receive, at the edge device, a second data unit having the characteristic, and send the second data unit to the service module based on the entry.

Claims

exact text as granted — not AI-modified
1 - 22 . (canceled) 
     
     
         23 . A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:
 determine, in response to receiving from a source peripheral processing device data to be sent to a destination peripheral processing device via a distributed switch fabric, a service to be performed on the data based on a header associated with the data;   generate a timestamp for the received data based on a time at which the data was received from the source peripheral processing device;   receive a data structure provided by a provisioning module, where the provisioning module is configured to maintain the data structure which stores information associated with service modules that are available to perform a service, or service modules that are actively performing a service, on data transmitted across the switch fabric system;   select a service module to provide the determined service, based on the data structure provided by the provisioning module and the result of a hash function having a destination address and the timestamp of the data as inputs to the hash function; and   send the data to the selected service module via the distributed switch fabric such that the service module performs the determined service on the data before sending the data to the destination peripheral processing device via the distributed switch fabric.   
     
     
         24 . The non-transitory processor-readable medium of  claim 23 , wherein the service is at least one of a security service or a load balancing service. 
     
     
         25 . The non-transitory processor-readable medium of  claim 23 , wherein the distributed switch fabric includes a Clos architecture. 
     
     
         26 . The non-transitory processor-readable medium of  claim 23 , wherein the service is at least one of a security service or a load balancing service and the distributed switch fabric includes a Clos architecture. 
     
     
         27 . The non-transitory processor-readable medium of  claim 23 , wherein the service module is within one of an edge device or a service peripheral processing device different from both the source peripheral processing device and the destination peripheral processing device. 
     
     
         28 . The non-transitory processor-readable medium of  claim 23 , wherein the service module is a first service module, the service is a first service, the code further comprising code to cause the processor to:
 identify a second service to be performed on the data; and   select, based on the second service, a second service module associated with the second service,   the code to cause the processor to send includes code to cause the processor to send the data to the first service module via the distributed switch fabric such that the first service module performs the first service on the data and sends the data to the destination peripheral processing device via the distributed switch fabric and the second service module.   
     
     
         29 . An apparatus, comprising:
 an edge device configured to receive, from a first peripheral processing device, data to be sent to a second peripheral processing device via a distributed switch fabric, the edge device configured to:   determine a service to be provided to the data based on a header associated with the data;   generate a timestamp for the received data based on a time at which the data was received from the first peripheral processing device;   receive a data structure provided by a provisioning module, where the provisioning module maintains the data structure which stores information associated with service modules that are available to perform a service, or service modules that are actively performing a service, on data transmitted across the switch fabric system;   select a service module to provide the determined service, based on the data structure provided by the provisioning module and the result of a hash function having a destination address and the timestamp of the data as inputs to the hash function;   and send the data to the selected service module via the distributed switch fabric, the data being configured so that the service module performs the determined service on the data before sending the data to the second peripheral processing device via the distributed switch fabric.   
     
     
         30 . The apparatus of  claim 29 , wherein the service is at least one of a security service or a load balancing service. 
     
     
         31 . The apparatus of  claim 29 , wherein the edge device is a first edge device, the first edge device configured to select based on a hash function a second edge device directly coupled to the service module, the first edge device configured to send the data to the service module via both the distributed switch fabric and the second edge device. 
     
     
         32 . The apparatus of  claim 29 , wherein the service is a first service, the edge device is a first edge device, the first edge device configured to send the data to the service module associated with the first service such that the service module associated with the first service performs the first service on the data and sends the data to the second peripheral processing device via both a service module associated with a second service and via the distributed switch. 
     
     
         33 . The apparatus of  claim 29 , wherein the distributed switch fabric includes a Clos architecture. 
     
     
         34 . The apparatus of  claim 29 , wherein the service module is a virtual service module. 
     
     
         35 . The apparatus of  claim 29 , wherein the edge device is a first edge device, the first edge device configured to select a second edge device directly coupled to the service module based on at least one of an address associated with the first peripheral processing device or an address associated with the second peripheral processing device, the first edge device configured to send the data to the service module via both the distributed switch fabric and the second edge device. 
     
     
         36 . The apparatus of  claim 29 , wherein the data is first data, the edge device configured to receive, from a third peripheral processing device, second data to be sent to a fourth peripheral processing device via the distributed switch fabric, the edge device configured to determine that a service is not to be provided to the second data, the edge device configured to send the second data to the fourth peripheral processing device via the distributed switch and without passing through a service module. 
     
     
         37 . The apparatus of  claim 29 , wherein the edge device is a first edge device, the service module is within one of a second edge device different from the first edge device or a third peripheral processing device different from both the first peripheral processing device and the second peripheral processing device. 
     
     
         38 . The apparatus of  claim 29 , wherein the service is at least one of a security service or a load balancing service, the service module is a virtual service module, and the distributed switch fabric includes a Clos architecture. 
     
     
         39 . A method, comprising:
 determining, in response to receiving from a source peripheral processing device data to be sent to a destination peripheral processing device via a distributed switch fabric, a service to be performed on the data based on a header associated with the data;   receiving a data structure provided by a provisioning module, where the provisioning module is configured to maintain the data structure which stores information associated with service modules that are available to perform a service, or service modules that are actively performing a service, on data transmitted across the switch fabric system;   selecting a service module to provide the determined service, based on the data structure provided by the provisioning module and the result of a hash function having a destination address and a timestamp of the data that is based on a time at which the data was received from the source peripheral processing device as inputs to the hash function; and   sending the data to the selected service module via the distributed switch fabric such that the service module performs the determined service on the data before sending the data to the destination peripheral processing device via the distributed switch fabric.   
     
     
         40 . The method of  claim 39 , further comprising:
 generating the timestamp for the received data based on the time at which the data was received from the source peripheral processing device.   
     
     
         41 . The method of  claim 39 , wherein the service is at least one of a security service or a load balancing service. 
     
     
         42 . The method of  claim 39 , wherein the service module is within one of an edge device or a service peripheral processing device different from both the source peripheral processing device and the destination peripheral processing device.

Join the waitlist — get patent alerts

Track US2019044888A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.