Method for maintaining differentiated services data flow at a network device implementing redundant packet discard security techniques
Abstract
An improved method is described for providing Differentiated Services (Diffserv) traffic to a node in a network that implements a security method that discards duplicate packets received at the node. The method includes the step of identifying at least two service levels to be provided to received traffic and assigning different size look-back window counts to each of the service levels. The look-back window count indicates a number of packets that have been previously received at the node that should be compared against a received packet to determine whether a duplicate packet has been received. In one embodiment, a service level that has higher priority is assigned a lower look-back window count and thus examines fewer previously received packets than a service level having a lower priority. Such an arrangement reduces the possibility that traffic having higher priority is dropped as a security measure.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A node for a packet communication network, the node comprising:
a communication interface configured to receive packets from the communication network; and a packet processor coupled to the communication interface, the packet processor being configured:
to compare a sequence number associated with a received packet against sequence numbers associated with a number of previously received packets, the number of previously received packets having been determined responsive to a service level associated with the received packet; and
to discard the received packet in the event of a match between the respective sequence number associated with any one of the number of previously received packets and the sequence number associated with the received packet.
2 . The node of claim 1 , wherein the packet processor is configured to determine the service level associated with the received packet in response to a differentiated services codepoint associated with the received packet.
3 . The node of claim 1 , wherein the packet processor is configured to be responsive to at least two service levels wherein the number of previously received packets determined for a higher priority service level is less than a number of previously received packets determine for a lower priority service level.
4 . The node of claim 3 , wherein at least one of the service levels corresponds to an Expedited Forwarding (EF) per hop behavior.
5 . The node of claim 3 , wherein at least one of the service levels corresponds to an Assured Forwarding (AF) per hop behavior.
6 . The node of claim 3 , wherein at least one of the service levels corresponds to a Best Efforts (BE) per hop behavior.
7 . The node of claim 1 , wherein the packet processor is configured to discard the received packet in the event of a match in accordance with an Internet Protocol Security (IPsec) anti-replay mechanism.
8 . The node of claim 1 , wherein the communication interface comprises a packet buffer configured to buffer received packets.
9 . The node of claim 1 , wherein the communication interface comprises a packet parser configured to determine a respective sequence number associated with each received packet.
10 . The node of claim 1 , comprising a differentiated services code table configured to determine a respective level of service associated with each received packet.
11 . The node of claim 1 , comprising a table of look back window sizes configured to associate a respective look back window size with each level of service.
12 . The node of claim 1 , comprising a sequence number buffer configured to buffer sequence numbers associated with previously received packets.Join the waitlist — get patent alerts
Track US2014269316A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.