The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 17, 2021

Filed:

Dec. 19, 2019
Applicant:

Hewlett Packard Enterprise Development Lp, Houston, TX (US);

Inventors:

Ying Zhang, Palo Alto, CA (US);

Jeongkeun Lee, Mountain View, CA (US);

Puneet Sharma, Palo Alto, CA (US);

Joon-Myung Kang, San Jose, CA (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 12/26 (2006.01); H04L 12/46 (2006.01); H04L 12/801 (2013.01); H04L 12/24 (2006.01); H04L 12/813 (2013.01); H04L 12/851 (2013.01); H04L 12/715 (2013.01); H04L 12/721 (2013.01);
U.S. Cl.
CPC ...
H04L 41/0893 (2013.01); H04L 41/0681 (2013.01); H04L 41/5032 (2013.01); H04L 47/20 (2013.01); H04L 47/2483 (2013.01); H04L 45/38 (2013.01); H04L 45/64 (2013.01);
Abstract

Example implementations relate to determining whether network invariants are violated by flow rules to be implemented by the data plane of a network. In an example, a verification module implemented on a device receives a flow rule transmitted from an SDN controller to a switch, the flow rule relating to an event. The module determines whether the flow rule matches any of a plurality of network invariants cached in the device. If determined that the flow rule matches one of the plurality of network invariants, the verification module determines whether the flow rule violates the matched network invariant. If determined that the flow rule does not match any of the plurality of network invariants, the verification module (1) reports the event associated with the flow rule to a policy management module, (2) receives a new network invariant related to the event from the policy management module, and (3) determines whether the flow rule violates the new network invariant. The verification module generates an alarm if determined that the flow rule violates any of the network invariants.


Find Patent Forward Citations

Loading…