Patents Assigned to A10 Networks, Inc.
  • Patent number: 8077473
    Abstract: A lever assembly for use with electronic modules has a handle lever with a self-sprung cantilevered handle section. The cantilevered handle section can be flexed with respect to the non-cantilevered portion of the handle lever during module insertion to automatically engage a catch that prevents the handle lever from inadvertently or accidentally being released and unseating the module. Once the flexing force is removed, compression of the handle section remains at the catch, such that the handle section continues to apply leverage force in the closure direction to hold the module securely in place.
    Type: Grant
    Filed: August 28, 2008
    Date of Patent: December 13, 2011
    Assignee: Force10 Networks, Inc.
    Inventor: Donald Lewis
  • Patent number: 8079077
    Abstract: A system and method for a distributed multi-processing security gateway establishes a host side session, selects a proxy network address for a server, uses the proxy network address to establish a server side session, receives a data packet, assigns a central processing unit core from a plurality of central processing unit cores in a multi-core processor of the security gateway to process the data packet, processes the data packet according to security policies, and sends the processed data packet. The proxy network address is selected such that a same central processing unit core is assigned to process data packets from the server side session and the host side session. By assigning central processing unit cores in this manner, higher capable security gateways are provided.
    Type: Grant
    Filed: November 29, 2007
    Date of Patent: December 13, 2011
    Assignee: A10 Networks, Inc.
    Inventors: Lee Chen, Ronald Wai Lun Szeto
  • Publication number: 20110283108
    Abstract: A trusted relationship service includes a certificate authentication server and a secure file host. The certificate authentication server operates to receive requests from a supplier and a customer to register with the service, verifies the identities of the supplier and the customer and sends digital certificates to both the supplier and the customer. The supplier can send information to the trusted relationship service where it is posted in a secure file host. The supplier can solicit the customer to visit the trusted relationship service web site to view the supplier information stored there, whereupon the customer can use their digital certificate to access the trusted relationship service site and is granted permission by the site to view the supplier information.
    Type: Application
    Filed: May 14, 2010
    Publication date: November 17, 2011
    Applicant: Force10 Networks, Inc.
    Inventor: Bruce D. Miller
  • Publication number: 20110235545
    Abstract: An autonomous system includes at least some packet network devices that are capable of operating in a virtual route aggregation environment and some packet network devices that are not capable of operating in a virtual route aggregation environment. The autonomous system includes at least one egress border router, at least one aggregation router and at least one intermediate router. The egress border router uses an interior border gateway protocol to distribute a label message to the other routers in the autonomous system, the label message including a next hop MAC address associated with either an external router or the egress border router. The egress border router and the intermediate router using information included in the label message to contrast layer 2 table entries and the aggregation router using information included in the label message to construct a layer 3 table entry.
    Type: Application
    Filed: March 26, 2010
    Publication date: September 29, 2011
    Applicant: Force 10 Networks, Inc.
    Inventors: KRISHNAMURTHY SUBRAMANIAN, SHIVI FOTEDAR, JANARDHNAN NARASIMHAN
  • Publication number: 20110239289
    Abstract: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time. To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record. If they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.
    Type: Application
    Filed: June 3, 2011
    Publication date: September 29, 2011
    Applicant: A10 Networks, Inc.
    Inventors: Xin Wang, Lee Chen, John Chiong
  • Patent number: 8026450
    Abstract: A circuit board comprises a center segment distributing power and low-speed signaling, and outer segments for high-speed signaling. The segments use dielectric materials with different dielectric constants, with the outer segments supporting higher-speed signal transmission.
    Type: Grant
    Filed: October 30, 2007
    Date of Patent: September 27, 2011
    Assignee: Force 10 Networks, Inc.
    Inventor: Joel R. Goergen
  • Patent number: 8027256
    Abstract: In one embodiment of a network device, multiple packet sources contend for access to a packet processing pipeline. The packet processing pipeline tracks the usage of lookup resources by each of the multiple packet sources. When a packet source is detected to be using more than an acceptable allocation of the lookup resources, access to the packet processing pipeline for that source is limited or curtailed to bring that source back within an acceptable allocation of resources. This backpressure mechanism can be used to control sources that, although within a bandwidth limit, are submitting a packet type mix that is consuming unfair percentages of lookup resources in an oversubscribed system. Other embodiments are described and claimed.
    Type: Grant
    Filed: June 2, 2005
    Date of Patent: September 27, 2011
    Assignee: Force 10 Networks, Inc.
    Inventors: Krishnamurthy Subramanian, Amrik Baines, Manu Thomas, Jason Lee, Ajoy Aswadhati
  • Publication number: 20110228779
    Abstract: A packet network device such as a network switch includes a number of functional cards or chassis modules at least some of which are connected to both an electrical backplane and a wireless backplane. The electrical backplane provides data plane signal paths and the wireless backplane provides control plane signal paths.
    Type: Application
    Filed: May 10, 2010
    Publication date: September 22, 2011
    Applicant: Force 10 Networks, Inc.
    Inventor: JOEL R. GOERGEN
  • Publication number: 20110225207
    Abstract: A network device such as a router or a switch is comprised of a control module and a plurality of physical line cards. The control module includes a control processor virtual machine, a plurality of route processing virtual machines and one or more instances of a line card virtual machine. The line card virtual machine operates to receive routing information base update information, to modify the routing information base according to the update information and to update each instance of a plurality of forwarding information bases included on each of the physical line cards.
    Type: Application
    Filed: March 12, 2010
    Publication date: September 15, 2011
    Applicant: Force 10 Networks, Inc.
    Inventors: KRISHNAMURTHY SUBRAMANIAN, RAHUL KULKARNI
  • Publication number: 20110222547
    Abstract: A packet network device includes a packet network processor memory system for storing information used to process and forward packets of information in and through the network device. The information is included in look-up tables whose entries can be mapped either horizontally or vertically into the memory system. In the event that the entries are mapped horizontally, a complete entry can be access at a single memory location and in the event that the entries are mapped vertically, the entries can be accessed at one or more memory locations.
    Type: Application
    Filed: March 12, 2010
    Publication date: September 15, 2011
    Applicant: Force 10 Networks, Inc.
    Inventors: KRISHNAMURTHY SUBRAMANIAN, Raja Jayakumar, Jason Lee
  • Patent number: 8014278
    Abstract: A packet network device has multiple equal output paths for at least some traffic flows. The device adjusts load between the paths using a structure that has more entries than the number of equal output paths, with at least some of the output paths appearing as entries in the structure more than once. By adjusting the frequency and/or order of the entries, the device can effect changes in the portion of the traffic flows directed to each of the equal output paths. Other embodiments are described and claimed.
    Type: Grant
    Filed: December 17, 2008
    Date of Patent: September 6, 2011
    Assignee: Force 10 Networks, Inc
    Inventors: Krishnamurthy Subramanian, Eddie Tan, Rajeev Manur
  • Patent number: 7983297
    Abstract: A communications network gateway receives a stream of information formatted to be compatible with a first sub-network and it receives a stream of information formatted to be compatible with a second sub-network. The frames in the second stream are extracted and modified to be compatible with the transmission format of the first sub-network. The two streams of information are then aggregated for transmission over a logical network link in a manner that optimizes the bandwidth utilization of the overall communications network.
    Type: Grant
    Filed: February 6, 2009
    Date of Patent: July 19, 2011
    Assignee: Force 10 Networks, Inc.
    Inventors: Bruce D. Miller, Mark Sanders
  • Patent number: 7979585
    Abstract: The inventive system includes a host, a network including a security gateway, and a public application. Established are an access session between the network and the host and an application session between the public application and the network. An application session record is created for the application session, and includes the user's public user identity used to access the public application, the user's private user identity used to access the network, a host identity, and an application session time. To determine the private user identity for the application session, the security gateway sends a query with the host identity and the application session time. These are compared with the host identity and access session time in an access session record. If they match, then the private user identity in the access session record is returned, and it is stored as the private user identity in the application session record.
    Type: Grant
    Filed: April 30, 2010
    Date of Patent: July 12, 2011
    Assignee: A10 Networks, Inc.
    Inventors: Lee Chen, John Chiong, Xin Wang
  • Publication number: 20110149975
    Abstract: Systems, methods, and apparatuses are provided that enable streaming of ATM cells between a transmit/receive data processing application and a transmission convergence function. Data to be segmented into an ATM cell is received at a SAR engine, and provided to a transmission convergence function, with the first cells transmitted to the transmission convergence function before the SAR function receives an end-of-packet indication from the optimization engine. Data received at a transmission convergence function is placed in a received packet queue at the SAR function, with packets provided to an application after a start-of-packet indication is received, and before an end-of-packet indication is received, at the SAR function.
    Type: Application
    Filed: December 21, 2009
    Publication date: June 23, 2011
    Applicant: Force 10 Networks, Inc.
    Inventor: MARK SANDERS
  • Patent number: 7957391
    Abstract: A physical layer device distributes a high-speed packet data stream to multiple lower-speed physical channels, and reverses the process to receive a high-speed packet data stream that has been distributed across multiple lower-speed physical channels. The packet data is distributed by removing interpacket gap characters from between packets and using a different control character to delineate packets. Interpacket gap characters can then be used to delineate equal-length frames distributed to each of the multiple physical channels. Each frame consists of a concatenation of fixed-size blocks of packet data. By selecting a frame size larger than the average packet size, overhead on the multiple physical channels can actually be lower than the overhead on the single high-speed channel, allowing the aggregation to achieve line rate operation at the high-speed rate.
    Type: Grant
    Filed: September 25, 2008
    Date of Patent: June 7, 2011
    Assignee: Force 10 Networks, Inc
    Inventor: Krishnamurthy Subramanian
  • Patent number: 7949134
    Abstract: In one embodiment, a hybrid backplane coding scheme transmits data using lengthy sequences of scrambled data, separated by 8b/10b control character sequences that prepare the receiver for the next scrambled sequence and permit realignment if necessary. Several lanes are coded separately in this manner, and then multiplexed on a common channel. Alignment sequences in the control character sequences, as well as scrambler seeds, are set to avoid synchronization of patterns generated among all lanes, which would tend to confuse a receiving serdes and/or phase-locked loop that recovers timing from the multiplexed scrambled signals.
    Type: Grant
    Filed: October 17, 2007
    Date of Patent: May 24, 2011
    Assignee: Force 10 Networks, Inc.
    Inventors: Joel Goergen, Krishnamurthy Subramanian, Ann Gui
  • Patent number: 7945884
    Abstract: Methods of designing a backplane, a backplane, and a packet switch using such a backplane are disclosed. The backplane comprises communication channels that connect each of a set of first card slots to each of a set of second card slots. Instead of forcing the backplane to route the communication channels to match a preset card configuration, the backplane communication channels are routed so as to reduce crosstalk and attenuation on at least the most difficult routing pairs. The cards perform logical translation of their backplane traffic to conform to the physical pin assignment for the particular card slot in which they are inserted. Other embodiments are also described and claimed.
    Type: Grant
    Filed: April 8, 2008
    Date of Patent: May 17, 2011
    Assignee: Force 10 Networks, Inc.
    Inventors: Joel R. Goergen, John D'Ambrosia
  • Publication number: 20110088842
    Abstract: Circuit boards and methods for their manufacture are disclosed. The circuit boards carry high-speed signals using conductors formed to include lengthwise channels. The channels increase the surface area of the conductors, and therefore enhance the ability of the conductors to carry high-speed signals. In at least some embodiments, a discontinuity also exists between the dielectric constant within the channels and just outside the channels, which is believed to reduce signal loss into the dielectric material.
    Type: Application
    Filed: December 7, 2010
    Publication date: April 21, 2011
    Applicant: Force10 Networks, Inc.
    Inventors: JOEL R. GOERGEN, Yi Zheng
  • Publication number: 20110093522
    Abstract: A method and system to determine a web server based on geo-location information is disclosed. The system includes: a local DNS server coupled to a web client; a plurality of web servers; and a global load balancer coupled to the local DNS server. The global load balancer: receives a request for a web service sent by the web client, the request comprising local DNS server information; determines a geographic location for the local DNS server based on the local DNS server information; determines a web server from the plurality of web servers based on the requested web service; determines a geographic location for the determined web server; determines that the geographic location for the local DNS server matches the geographic location for the determined web server; selects the determined web server; and sends a response comprising information on the selected web server to the local DNS server.
    Type: Application
    Filed: October 21, 2009
    Publication date: April 21, 2011
    Applicant: A10 NETWORKS, INC.
    Inventors: Lee Chen, John Chiong
  • Patent number: 7903554
    Abstract: Traffic engineering using a label-switching protocol is enhanced for label-switched paths that traverse a logical link that is an aggregation of component links. In one embodiment, a label edge router is provided with information regarding the bandwidth capabilities and loading of the component links of a LAG. The label edge router is then allowed to set up paths that traverse a specific component link of a LAG, and reserve bandwidth on such a component link. Other traffic may continue to be distributed across the LAG membership.
    Type: Grant
    Filed: April 4, 2008
    Date of Patent: March 8, 2011
    Assignee: Force 10 Networks, Inc.
    Inventors: Rajeev Manur, Krishnamurthy Subramanian, Vishal Zinjuvadia