Patents Assigned to Hillstone Networks, Corp.
-
Patent number: 10678727Abstract: A method for processing network data traffic includes obtaining a first distributed structure corresponding to a program based on a first storage structure, wherein the program is configured to process network data traffic; dividing a network device based on a second storage structure into a plurality of execution units, wherein the plurality of execution units is configured to execute the program; mapping the first distributed structure and the plurality of execution units to obtain a second distributed structure; and controlling the plurality of execution units to process network data traffic based on the second distributed structure.Type: GrantFiled: November 9, 2018Date of Patent: June 9, 2020Assignee: HILLSTONE NETWORKS CORP.Inventors: Dongyi Jiang, Linyang Shu, Jiangbo Nie, Ye Zhang, Yu Jia, Qijun Yang, Juxi Li
-
Patent number: 10567340Abstract: A data center system includes: at least two data center subsystems interconnected through a layer-2 network, each of the data center subsystems comprising a plurality of hosts, a plurality of layer-2 switches connected with the plurality of hosts, a firewall group connected with the layer-2 switches, and a layer-2 extension device connected with the layer-2 switches; wherein the firewall groups of the at least two data center subsystems are configured to transmit synchronization information to each other through a synchronization channel in a first virtual local area network; wherein the layer-2 extension devices of the at least two data center subsystems are configured to transmit service information through a service channel in a second virtual local area network; and wherein the first virtual local area network and the second virtual local area network are implemented in the layer-2 network.Type: GrantFiled: April 4, 2017Date of Patent: February 18, 2020Assignee: HILLSTONE NETWORKS CORP.Inventors: Dongyi Jiang, Qijun Yang, Jin Shang, Linyang Shu
-
Publication number: 20200007472Abstract: A processing system includes: a first service machine having a first service module; and a first service switch; wherein the first service machine and the first service switch are configured for logically coupling between virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the first service switch.Type: ApplicationFiled: September 9, 2019Publication date: January 2, 2020Applicant: HILLSTONE NETWORKS CORP.Inventors: Dongyi Jiang, Jin Shang, Ye Zhang, Juxi Li, Hua Ji
-
Publication number: 20200004711Abstract: A method for processing network data traffic includes obtaining a first distributed structure corresponding to a program based on a first storage structure, wherein the program is configured to process network data traffic; dividing a network device based on a second storage structure into a plurality of execution units, wherein the plurality of execution units is configured to execute the program; mapping the first distributed structure and the plurality of execution units to obtain a second distributed structure; and controlling the plurality of execution units to process network data traffic based on the second distributed structure.Type: ApplicationFiled: November 9, 2018Publication date: January 2, 2020Applicant: Hillstone Networks, Corp.Inventors: Dongyi Jiang, Linyang Shu, Jiangbo Nie, Ye Zhang, Yu Jia, Qijun Yang, Juxi Li
-
Patent number: 10419365Abstract: A processing system includes: a first service machine having a first service module; and a first service switch; wherein the first service machine and the first service switch are configured for logically coupling between virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the first service switch.Type: GrantFiled: April 20, 2015Date of Patent: September 17, 2019Assignee: Hillstone Networks Corp.Inventors: Dongyi Jiang, Jin Shang, Ye Zhang, Juxi Li, Hua Ji
-
Patent number: 9954898Abstract: This disclosure makes public a data flow forwarding method and device, and in this method, a second health state is acquired based on the first health state of one or more pieces of identifying information of the received data flow, wherein the first health state and second health state are associated with the access rights of the user and/or user device that sent the data flow; it employs firewall policy property sets to determine whether or not to forward the data flow, wherein the firewall policy property sets comprise: the second health state. The technical schemes based on this disclosure improve the ability of a firewall to identify network attacks or abnormal activities and reduce administration costs.Type: GrantFiled: July 31, 2014Date of Patent: April 24, 2018Assignee: Hillstone Networks, Corp.Inventors: Timothy Liu, Zhong Wang, Lingling Zhang, Bin Jia
-
Publication number: 20170310641Abstract: A data center system includes: at least two data center subsystems interconnected through a layer-2 network, each of the data center subsystems comprising a plurality of hosts, a plurality of layer-2 switches connected with the plurality of hosts, a firewall group connected with the layer-2 switches, and a layer-2 extension device connected with the layer-2 switches; wherein the firewall groups of the at least two data center subsystems are configured to transmit synchronization information to each other through a synchronization channel in a first virtual local area network; wherein the layer-2 extension devices of the at least two data center subsystems are configured to transmit service information through a service channel in a second virtual local area network; and wherein the first virtual local area network and the second virtual local area network are implemented in the layer-2 network.Type: ApplicationFiled: April 4, 2017Publication date: October 26, 2017Applicant: Hillstone Networks, Corp.Inventors: Dongyi Jiang, Qijun Yang, Jin Shang, Linyang Shu
-
Publication number: 20170070535Abstract: This disclosure makes public a data flow forwarding method and device, and in this method, a second health state is acquired based on the first health state of one or more pieces of identifying information of the received data flow, wherein the first health state and second health state are associated with the access rights of the user and/or user device that sent the data flow; it employs firewall policy property sets to determine whether or not to forward the data flow, wherein the firewall policy property sets comprise: the second health state. The technical schemes based on this disclosure improve the ability of a firewall to identify network attacks or abnormal activities and reduce administration costs.Type: ApplicationFiled: July 31, 2014Publication date: March 9, 2017Applicant: HILLSTONE NETWORKS, CORP.Inventors: Timothy Liu, Zhong Wang, Lingling Zhang, Bin Jia
-
Publication number: 20160308790Abstract: A processing system includes: a first service machine having a first service module; and a first service switch; wherein the first service machine and the first service switch are configured for logically coupling between virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the first service switch.Type: ApplicationFiled: April 20, 2015Publication date: October 20, 2016Applicant: Hillstone Networks Corp.Inventors: Dongyi Jiang, Jin Shang, Ye Zhang, Juxi Li, Hua Ji
-
Patent number: 9332075Abstract: A method performed by a network appliance having a plurality of application processing units, includes: receiving a first packet at the network appliance; calculating a first value using a mathematical algorithm based on one or more information regarding the first packet; and using the calculated first value to identify a first application processing unit of the plurality of application processing units in the network appliance. A network appliance includes: a plurality of processing units that are communicatively connected to each other; wherein a first processing unit of the plurality of processing units is configured for: calculating a first value using a mathematical algorithm based on one or more information regarding a first packet; and using the calculated first value to identify a second processing unit of the plurality of processing units.Type: GrantFiled: March 15, 2013Date of Patent: May 3, 2016Assignee: Hillstone Networks, Corp.Inventors: Dongyi Jiang, Jin Shang, David Yu, Michael Lin, Jun Xie, Ye Zhang
-
Patent number: 9311123Abstract: A method performed by a network system having a plurality of processing units implemented using a plurality of respective virtual machines, includes: receiving a first packet at a first virtual machine of the plurality of virtual machines, wherein the first virtual machine is configured to receive the first packet from a network through an interface and has session processing capability; calculating a first value using a mathematical algorithm based on one or more information regarding the first packet; and using the calculated first value to identify a second virtual machine of the plurality of virtual machines in the network system.Type: GrantFiled: July 2, 2013Date of Patent: April 12, 2016Assignee: Hillstone Networks, Corp.Inventors: Dongyi Jiang, Jin Shang, David Yu, Michael Lin, Jun Xie, Ye Zhang, Mike Ji
-
Publication number: 20160036856Abstract: This disclosure makes public a data flow forwarding method and device, and in this method, a second health state is acquired based on the first health state of one or more pieces of identifying information of the received data flow, wherein the first health state and second health state are associated with the access rights of the user and/or user device that sent the data flow; it employs firewall policy property sets to determine whether or not to forward the data flow, wherein the firewall policy property sets comprise: the second health state. The technical schemes based on this disclosure improve the ability of a firewall to identify network attacks or abnormal activities and reduce administration costs.Type: ApplicationFiled: July 31, 2014Publication date: February 4, 2016Applicant: HILLSTONE NETWORKS, CORP.Inventors: Timothy Liu, Zhong Wang, Lingling Zhang, Bin Jia
-
Publication number: 20140280442Abstract: A method performed by a network appliance having a plurality of application processing units, includes: receiving a first packet at the network appliance; calculating a first value using a mathematical algorithm based on one or more information regarding the first packet; and using the calculated first value to identify a first application processing unit of the plurality of application processing units in the network appliance. A network appliance includes: a plurality of processing units that are communicatively connected to each other; wherein a first processing unit of the plurality of processing units is configured for: calculating a first value using a mathematical algorithm based on one or more information regarding a first packet; and using the calculated first value to identify a second processing unit of the plurality of processing units.Type: ApplicationFiled: March 15, 2013Publication date: September 18, 2014Applicant: Hillstone Networks, Corp.Inventors: Dongyi Jiang, Jin Shang, David Yu, Michael Lin, Jun Xie, Ye Zhang