×

Domain isolation through virtual network machines

  • US 7,908,395 B1
  • Filed: 10/09/2007
  • Issued: 03/15/2011
  • Est. Priority Date: 12/24/1998
  • Status: Expired due to Term
First Claim
Patent Images

1. A network comprising:

  • a set of subscriber end stations;

    a first virtual network;

    a set of layered virtual networks, wherein each of the set of layered virtual networks comprises a plurality of nodes and links, wherein each of the set of layered virtual networks is isolated from each other and the first virtual network, and wherein the set of layered virtual networks is layered on top of the first virtual network; and

    a single network device coupled between nodes of the set of different layered virtual networks and the set of subscriber end stations, and coupled to the first virtual network, the single network device having,a first independently administrable virtual network database,a set of independently administrable network databases, wherein each of the independently administrable network databases is separate from the first independently administrable virtual network database and other ones of the set of independently administrable network databases,a virtual network machine, communicatively coupled to the first virtual network, wherein the virtual network machine is one of a virtual router and a virtual bridge, and the virtual network machine communicates traffic within the first virtual network according to control and policy information in the first independently administrable virtual network database and with accounting for the virtual network machine, anda set of virtual bridges to communicate a plurality of independent information flows through the single network device, wherein each of the set of virtual bridges belongs to a different one of the layered virtual networks, wherein the set of virtual bridges are virtually independent but share a set of physical resources of the single network device, wherein each of the set of virtual bridges includes a different one of the set of independently administrable network databases with control and policy information for that virtual bridge, wherein the control and policy information comprises layer 2 addressing, layer 2 connectivity, tunneling configuration, and tunneling protocols, wherein each of the set of virtual bridges communicates different ones of the plurality of independent information flows through a tunnel coupled to that virtual bridge based on the control and policy information in the respective independently administrable network database, wherein the set of the virtual bridges performs accounting by recording subscriber end station activity represented by the plurality of independent information flows.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×