Method and apparatus for dynamically controlling the provision of differentiated services
Abstract
An apparatus comprising a network interface, through which the apparatus facilitates communication between a client device and a remote device and a controller is presented. In accordance with one aspect or the present invention, the controller, coupled to the network interface, dynamically creates and removes admission filters based, at least in part, on an admissions profile that, when triggered, the filter(s) initiate an admission control decision preventing premature allocation of resources which are not used or authorized.

Term
Term ended
Projected expiry passed 23 December 2019, 6.8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
15 claims: 3 independent, 12 dependent
- 1An apparatus comprising:a network interface, through which the apparatus facilitates communication between a client device and a remote device at any of a number of alternative service levels;and a controller, coupled to the network interface, to dynamically create and remove filters controlling access to the different service levels based, at least in part, on an admissions profile.
- 7The apparatus claim 1, wherein the admissions profile is available locally within the apparatus.
- 13A method for controlling provision of differentiated services in a data network, the method comprising:(a) installing a filter on a network edge device to provide a trigger notification upon detecting data packers adhering to filter criteria, in accordance with a network administration policy;and (b) dynamically creating an ingress profiler which polices admission to a particular service level.
Independent claims3
49 paragraphs in 5 sections, as filed
COPYRIGHT NOTICE
A portion of the disclosure of this parent document contains material which is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent file or records, but otherwise expressly reserves all rights whatsoever in said copyright works.
BACKGROUND OF THE INVENTION
1.
Field of the Invention
The present Invention relates to the field of data networking and, in particular, to a method and apparatus for dynamically controlling the provision of differentiated services.
2.
Background Information
As computer technology has evolved, so too has the use of networks which communicatively couple computer systems together enabling them to communicate with one another. One of the more popular of such computer networks is colloquially referred to as the Internet, which is an internetworking of a number of publicly accessible networks and servers distributed throughout the world. The Internet provides the communication means by which individual enterprise networks (e.g., Local Area Networks (LANs), Wide Area Networks (WANs), and the like), servers and other network devices communicate with one another. Individually, the networks/servers comprising the Internet come in many different topologies, employing a corresponding number of alternative communication technologies. One of the profound advantages of the Internet is that communication at the network layer is standardized around a standard set of communication protocols commonly referred to as the Internet communication suite. By adhering to the Internet communication suite, any network device can communicate with any other network device, effectively creating a single, seamless ubiquitous network.
Once the domain of government agencies and academic institutions, the Internet has grown to become a form of entertainment in many parts of the world, as well as a source of commerce. However, the increased popularity of the Internet has also revealed some of its limitations. One such limitation is bandwidth management. That is to say, the increased popularity of the Internet has resulted in increased congestion, for which the Internet is ill-equipped to manage.
One reason for the Internet's limited ability to manage congestion centers around its "best-effort" service level paradigm. Simply stated, in communicating data packets from one network device to another, each intervening network device processes data traffic in the order in which it was received and selects the best route currently available to deliver the data packets to its destination, If a network device is overburdened, or the data packets are corrupted in transit (e.g., due to noise or other factors), the data packers may be dropped requiring re-transmission. While dropped or re-transmitted data packets are not a problem for many applications, it does pose a problem for multimedia applications executing over the Internet. Moreover, the best-effort service level of the Internet does nor take into account that certain data packets are more time-sensitive than others.
To illustrate this last point, consider for example computer telephony applications, the so-called Internet telephones. The speech quality and cognition provided by computer telephony applications are heavily dependent upon a network's ability to transmit data packets from the source to the destination in a near real-time fashion, without dropping packets or otherwise requiring re-transmission. Dropped or re-transmitted data packets may well result in choppy, unintelligible speech at to receiving end of the communication.
To overcome the limitations of the best-effort service paradigm, the Internet Engineering Task Force (IETF), an association of networking professionals, have proposed inclusion of differentiated services in the Internet standard, providing different levels of service within the bandwidth or the Internet. Differentiated services enable an application/network device/enterprise network/etc. to reserve communication bandwidth with which to facilitate transmission of data packets between a source and destination. Those skilled in the art will recognize that reserving bandwidth using to differentiated services paradigm comes at a cost. That is, Internet Service Providers (ISP) and other Internet access points charge a premium to secure and dedicate bandwidth to individual clients/applications. Even if there is not a per-use coat associated with the use of differentiated services, there is an inherent cost in dedicating equipment on a per-port basis to support such differentiated services. Consequently, simply adding more ports to alleviate congestion and provide differentiated services is a costly solution.
To more effectively manage the costly resources required to provide differentiated services, it is known to install filters on network edge device which control the provision of differentiated services. Thus, rather than simply dedicating bandwidth to support a service level between two networks, a such bandwidth is not allocated until such time as network traffic satisfying filter criteria is detected. One skilled in the art will appreciate, however, that the network devices can quickly became over-burdened with such filters.
Thus, a method and apparatus for dynamically controlling the provision of differentiated services is presented, unencumbered by the deficiencies and inherent limitations commonly associated with the network devices of the prior art. It will be apparent to those skilled in the art, from the description to follow, that the present invention achieves these and other desired results.
SUMMARY OF THE INVENTION
In accordance with the teachings of the present invention, a method and apparatus for controlling access to a network information source is provided. In particular, in accordance with one embodiment of the present invention, an apparatus comprising a network interfare, through which the apparatus facilitates communication between a client device and a remote device and a controller is presented. In accordance with one aspect of the present invention, the controller, coupled to the network interface, dynamically creates and removes admission filters based, at least in part on an admissions profile such that, when triggered, the filter(s) initiate an admission control decision preventing premature allocation of differentiated services resources which are not used or authorized.
BRIEF DESCRIPTION OF DRAWINGS
The present Invention will be described by way of exemplary embodiments, but not limitations, illustrated in the accompanying drawings in which like references denote similar elements, and in which: <ul id="ul0001" list-style="none" compact="compact"><li><b>Figure 1</b> illustrates a block diagram of an example data network within which the teachings of the present inventions may be practiced, In accordance with one embodiment of the present invention;</li><li><b>Figure 2</b> illustrates a block diagram of a network device incorporating the teachings at the present invention, in accordance with one embodiment of the present invention;</li><li><b>Figure 3</b> illustrates a flow chart of an example method for dynamically controlling the provision of differentiated services, in accordance with one embodiment of the present invention;</li><li><b>Figure 4</b> illustrates an example communication packet suitable for use in the example network of <b>Figure 1</b>, in accordance with one embodiment of the present invention;</li><li><b>Figure 5</b> graphically illustrates an example profile database from which trigger filters and admission profiles are dynamically generated, in accordance with one embodiment of the present invention; and</li><li><b>Figure 6</b> illustrates a block diagram or an example network device incorporating the teachings of the present invention, in accordance with an alternate embodiment of the present invention.</li></ul>
DETAILED DESCRIPTION OF THE INVENTION
In the following description, various aspects of the present invention will be described. However, it will be apparent to those skilled in the art that the present invention may be practiced with only some or all aspects of the present invention. For purposes of explanation, specific numbers and configurations are set forth in order to provide a thorough understanding of the present inventive. However, it will also be apparent to those skilled in the art that the present invention may be practical without these specific details. In other instances, well known features are omitted or simplified for clarity.
A portion of the disclosure of this patent document contains material which is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent file or records, but otherwise expressly reserves all rights whatsoever in said copyright works.
In alternative embodiment, the present invention may be applicable to implementations of the invention in integrated circuits or chip sets, wireless implementations, switching system products and transmission systems products. For purposes of this application, the was switching systems products shall be taken to mean private branch exchanges (PBXs), central office switching systems that interconnect subscribers, toll/tandem switching systems for interconnecting trunks between switching centers, and broadband core switches found at the center of a service provider's network that may be fed by broadband edge switches or access multiplexers, and associated signaling, and support systems and services. The term transmission systems products shall be taken to mean products used by service providers to provide interconnection between their subscribers and their networks such as loop systems, and which provide multiplexing, aggregation and transport between a service provider's switching systems across the wide area, and associated signaling and support systems and services.
Turning to <b>Figure 1</b>, an example data network within which the teachings of the present invention are practiced is presented, in accordance with one embodiment of the present invention. In accordance with the illustrated example embodiment of <b>Figure 1</b>, data network <b>100</b> is shown comprising a plurality of clients (<b>112, 114, 116, 120, 122, 128</b> and <b>130</b>) communicatively coupled to a network core device <b>108</b> via a network edge device (<b>110</b>, <b>118</b>, and <b>124</b>) as shown. Those skilled in the art will appreciate, from the description to follow, that network edge devices <b>110</b>, <b>118</b> and/or <b>124</b> incorporating the teachings of the present invention dynamically provision the differential services offered by and through core device(s) <b>108</b> on an as-needed, as-authorized basis, thereby minimizing the resources required of the network edge device and the network to support differentiated services. More specifically, network edge devices <b>110</b>, <b>118</b> and/or <b>124</b>, in conjunction with a bandwidth broker, dynamically create and remove filters that, when triggered, initiate an admission decision controlling provision of end access to to differentiated services of data network <b>100</b>. Accordingly, a network device incorporating the teachings of the present invention ensures that the differentiated services of data network <b>100</b> are not provisioned until they are needed and authorized, thereby preventing the allocation of unused network resources and reducing the operating cost of data network <b>100</b>. These and other aspects of the present invention will be apparent to those skilled in the art based on the description to follow.
As depicted In <b>Figure 1</b>, client computers <b>112</b>, <b>114</b> and <b>116</b> are coupled to a common network <b>103</b>, which is coupled to core device <b>108</b> via network edge device <b>110</b>. In one embodiment clients <b>112</b>, <b>114</b> and <b>116</b> along with network edge device <b>110</b> form a local area network (LAN) <b>102</b>. Similarly, clients <b>128</b> and <b>130</b>, bandwidth broker <b>126</b> and network edge device <b>124</b>, coupled via network <b>105</b> form LAN <b>104</b>, while clients <b>120</b> and <b>122</b> coupled to network edge device <b>118</b> via network <b>107</b> form LAN <b>106</b>. As shown, each of LANs <b>102</b>, <b>104</b> and <b>106</b> are coupled to a common network core device. e.g., core device <b>108</b>. In one embodiment, the combination of LANs <b>102</b>, <b>104</b> and <b>106</b> coupled to a comman core device <b>108</b> form a domain of an enterprise-wide network, also commonly referred to as a wide area network (WAN) or wide area information system (WAIS). In an alternate embodiment, core devic<b>e 108</b> is one of a plurality of network core devices comprising a global data network, e.g., the Internet.
As depicted, example data network <b>100</b> of <b>Figure 1</b> much like the typical prior art network described above, with the notable exception that access filters arc dynamically established and removed on network edge devices <b>110</b>, <b>118</b> and <b>124,</b> incorporating the teachings of the present invention, to control access to the differentiated services offered by core device <b>108</b>. The filters are installed on an as-needed, as-authorized basis, thereby preserving network resources as well filter resources of the network edge device. Accordingly, chose skilled in the art will appreciate that data network <b>100</b> is intended to represent any of a number network architectures employing any of a number of alternative communication protocols known or anticipated in the art. Thus, except for the teachings of the present invention to be described more fully below, as used herein the term network device is broadly employed to describe any of a number of alternative network devices commonly known and used in the data networking arts to support communication between network elements.
As used herein, bandwidth broker <b>126</b> of LAN <b>104</b> controls provision of differentiated services at a network level for the domain associated with core device <b>108</b>. Accordingly, bandwidth broker maintains "bandwidth pools" for each class of service supported by network core device <b>108</b>. In accordance with one embodiment of the present invention, bandwidth broker <b>126</b> also maintains an admission policy database, which correlates subscribed services to admission filters and classifier profiles that, when triggered, are installed on or removed from network edge devices incorporating the teachings of the present invention, as appropriate. Thus, in accordance with one aspect of the present invention, bandwidth broker <b>126</b> awaits and removes admission filters (also referred to as access filters, or policy filters) and classifier profiles on network edge devices incorporating the teachings of to present invention, e.g., <b>110</b>, <b>118</b> and/or <b>124</b> to control provision of the differentiated services offered by core device <b>108</b>. Although depicted so a seperate entiry, those skilled in the art will appreciate from the description to follow that bandwidth broker <b>126</b> may well be integrated with one or more of network edge devices <b>110,118</b> and/or <b>124</b>.
As used herein, clients, e.g.. <b>112, 114, 116, 120, 122, 128</b> and/or <b>130</b> are intended to represent any of a number of alternative computing devices known in the art. In one embodiment, for example, clients are typical desktop computers coupled to subnetworks as is well known in the art. In an alternate embodiment clients are the so-called network computers. i.e., computers which rely on a network server for application and hard drive storage. In an alternate embodiment, client <b>102</b> is an electronic appliance, e.g., a webTV™ Internet Terminal available from Sony Electronics, Inc. of Park Ridge, NJ, that enables one to utilize the resources of data network <b>100</b> without the need of a full-featured computer system.
In accordance with the illustrates example data network of <b>Figure 1</b>, core device(s) <b>108</b> is intended to represent any of a number of core network devices known to those skilled in the art which provide differentiated service levels of communication. In one embodiment, for example, core device <b>108</b> is a network switching cancer comprising a number of switches, hubs, routers and servers. In an alternate embodiment, core devic<b>e 108</b> is a switch. In an alternate embodiment, core device <b>108</b> is a server supporting network switching and communications.
Similarly, the communication links illustrated in <b>Figure 1</b> may be any of a wide range of conventional wireline and wireless communication media, and may be different for different clients, servers, bandwidth broken and other network devices. For example, a communication link may be a cable, a fiber optic cable, or may represent a nonphysical medium transmitting electromagnetic signals in the electromagnetic spectrum. Additionally, a wireless communication link way also include any number of conventional routing or repeating devices, such as satellites or electromagnetic signal repeaters or basestations. Irregardless of the form of communication medium, data is typically transferred between network elements using any of a number of data communication protocols. In accordance with such data communication protocols, data is generally transferred between network elements in units commonly referred to as packets, frames, datagrams and the like. Typically, such packet includes data, a source address and a target address. As will be described in greater detail below, additional control information, generally included In a header, may also be included in the packet. The number of bytes of data contained within a packet is dependent upon the communication resources of the client, the host and the network protocol employed.
Having introduced the operating environmant for the present invention, a block diagram of an example network edge device incorporating the teachings of the present invention in provided with reference to <b>Figure 2</b>. As depicted, <b>Figure 2</b> illustrates a block diagram of an example network device <b>200</b> incorporating the teachings of the present invention, in accordance with one embodiment of the present invention. In one embodiment, network device <b>200</b> may well be beneficially incorporated into network <b>100</b> as one or more of network edge devices <b>110</b>, <b>118</b> and/or <b>124</b>. Further, us alluded to above, except for the teachings of the present invention, network edge device <b>200</b> is intended to represent any of a number of alternative network devices commonly used and known in the art. Thus, those skilled in the art will appreciate that to present invention may be practiced in any of a number of alternate embodiments without deviating from the spirit and scope of the present invention.
As presented in the example embodiment of <b>Figure 2</b>, network device <b>200</b> is shown comprising input/output driven <b>202</b> and <b>208</b>, network Interface <b>204</b> and controller <b>206</b> coupled as shown. In accordance with one aspect of the present invention, so be developed most fully below, controller <b>206</b> controls the dynamic provision of filters <b>210</b> and classifier profiles <b>222</b> providing access to the differentiated services offered within the domain of resident core device(s). Although depicted as separate entities, those skilled in the art will appreciate that this is for ease of explanation only, and that controller <b>206</b> may well be incorporated as a functional block of network interface <b>204</b>. In an alternate embodiment, controller <b>206</b> may wall be remotely located and communicatively coupled to network device <b>200</b> and network interface <b>204</b>. As used herein, controller <b>206</b> is intended to represent any of a number of microprocessors, microcontrollers, programmable logic devices (PLDs), application specific integrated circuits (ASICs) and the like.
As depicted in <b>Figure 2.</b> I/O driven <b>202</b> and <b>208</b> provide the physical interface between network device <b>200</b> and the client network and core network, respectively. That is, I/O driver <b>202</b> provides an interface supporting data communication (bi-directional) with clients, e.g., client <b>112</b>, while I/O driver <b>208</b> provides an interface supporting data communication (also bi-directional) with core devices. e.g., core device <b>108</b>. Such I/O devices are well known in the art and need not be further described here.
In accordance with the illustrated example embodiment of <b>Figure 2</b>, network interface <b>204</b> is shown comprising Decaps/DeMUX unit <b>210</b>, filter(s) <b>212</b> classifier <b>214</b> including profiles <b>222</b>, routing unit <b>216</b>. Encaps/Multiplexer (MUX) <b>218</b> and scheduler <b>220</b>, each communicatively coupled as shown. As shown, Decaps/DeMUX <b>210</b> receives data packets from a communicatively coupled network via I/O driver <b>202</b> and translates the data packets from the communication protocol employed by the network.
Filter(s) <b>212</b> and classifier <b>214</b> are employed to identity incoming data traffic adhering to admission policy criteria and marks the data packets with an appropriate routing classification in accordance with a predetermined differentiated services admission policy. That is, filter <b>212</b> provides an indication, or trigger, denoting when data packets are received that satisfy filter criteria. In accordance with one aspect or the present invention, the filters populating filter(s) <b>212</b> are dynamically provisioned on network interface <b>204</b> by controller <b>206</b> in accordance with a admission control policy, In one embodiment, controller <b>206</b> creates and removes specific filters front filter <b>212</b> in response to control messages from a remote bandwidth broker, e.g., bandwidth broker <b>126</b>. In an alternate embodiment, controller <b>206</b> is a bandwidth broker and creases/removes specific filters from filter <b>212</b> on its own accord, in furtherance of a admission control policy. Once in place, filter <b>212</b> issues a trigger message to controller <b>206</b> when data packers are received satisfying the criteria of an installed filter.
Classifier <b>214</b> functions to classify and mark data packets in accordance with their service level. In operation, once a trigger is received denoting receipt of data packets satisfying the filter criteria of at least one filter <b>212</b>, controller <b>206</b> updates the installed profiles <b>222</b> of classifier <b>214</b> such that any data packets received at classifier <b>214</b> satisfying at least one profile <b>222</b> will be marked in accordance with their subscribed service level. More specifically, in accordance with one embodiment of the present invention, the Type of Service (ToS) field in a "header" appended to the data packet is marked to denote an appropriate level of service for transmission of the data packet. One example of a header is provided with reference to <b>Figure 4</b>.
Turning briefly to <b>Figure 4</b>, a graphical illustration of an example header <b>400</b> suitable for use in conjunction with the present invention is depicted. As shown, in accordance with the illustrated example embodiment, header <b>400</b> is a byte wide, containing up to eight separate data fields. Of particular interest with respect to the present invention is the Type of Service (ToS) field <b>402</b>. Those skilled in the art will appreciate that the number of bits allocated to ToS field <b>402</b> determines number of service gradations supported by header <b>400</b>. In accordance with the illustrated example embodiment, the ToS field <b>402</b> is a one-bit field. Consequently, ToS field <b>402</b> can be marked to differentiate two levels of service, associated with a ToS field <b>402</b> entry of '0' or '1'. In one embodiment, for example, a ToS field <b>402</b> populated with '0' denotes a best-effort service level. Accordingly, when data packets are received which do nor satisfy filter criteria, classifier <b>214</b> updates the ToS field <b>402</b> of the header appended to such data packers with a '0'. Alternatively, as will be described in greater detail below, receipt of data packets satisfying filter <b>212</b> criteria may result in marking the ToS field <b>402</b> of the header appended to such data packets with a '1', denoting an expedited forwarding (EF) level of service. Those skilled in the art will appreciate that larger ToS fields <b>402</b> will enable header <b>400</b> to support increased gradations in service levels. Indeed, the number of service levels may increase exponentially as the number of bits allocated to ToS field <b>402</b> increases.
Returning to <b>Figure 2</b>, in accordance with one aspect of the present invention, the provision of profiles <b>222</b> to classifier <b>214</b> by controller <b>206</b> is closely monitored. That is, profiles <b>222</b> are created by controller <b>206</b> in satisfy individual flows, e.g., transmission of a number of related data packets, and are summarily removed what the flow no longer exists. Accordingly, a network device such as network device <b>200</b> incorporating the teachings of the present invention minimizes the resources dedicated to support filters and classifier profiles by allocating resource to only those filters/classifier profiles currently in use.
In addition to the foregoing, network interface <b>204</b> includes routing unit <b>216</b>, Encaps/MUX <b>218</b> and scheduler <b>220</b>, as shown. Routing unit <b>216</b> identifies and marks to data packets with routing information in accordance with the subscribed service level. Encaps/MUX <b>218</b> places the data packets in the proper format for transmission over the data network. Scheduler <b>220</b> is used to schedule transmission of data packets through I/O driver <b>208</b> in accordance with their subscribed service level, if congestion on the outgoing communication link is detected. Thus, those skilled in the art will appreciate that routing unit <b>216</b>, Encaps/MUX <b>218</b> and schedule<b>r 220</b> are typical of those used in the data networking art and, thus, need not be further described.
Thus, in accordance with one aspect of the present invention, controller <b>206</b> dynamically controls to provision of filters <b>212</b> and classifier profiles <b>222</b> in accordance with a differentiated services admission policy, thereby reducing the resources dedicated to support differentiated services.
Given to foregoing architectural description, the operation at example network device <b>200</b> incorporating the teachings of the present invention will now be developed with reference to the flow chart depicted in <b>Figure 3</b>. In particular, an example method for dynamically controlling the provision of differentiated services in a data network will be developed with reference to rho flow chart depicted in <b>Figure 3</b>, in accordance with one embodiment of the present invention.
For ease of explanation, and not limitation, the example method depicted in <b>Figure 3</b> will be developed in accordance with an example communication session with continued reference to <b>Figures 1</b> and <b>2</b>. Consider the following, a corporate entity has a number of distributed sites, each having their own respective local area network, e.g., LANs <b>102,104</b> and <b>106</b>. In order to link these remote sites, the corporate entity has contacted with an internet service provider (ISP) to provide premium network services between LAN <b>102</b> and LAN <b>106</b> between the hours of 9AM and 5PM via its network core device <b>108</b>.
With reference to <b>Figure 3</b>, the example method for controlling the provision of differentiated services of core device <b>108</b> begins when data packets are received by a network edge device, e.g., network edge device <b>110</b>, with an initial determination of whether a filter corresponding to the received data packets is installed <b>301</b>. If not, a further determination is made of whether a filter need be installed one network edge device, block <b>302</b>.
In accordance with the above example implementation, bandwidth broker <b>126</b> determines at 9AM that differentiated services have been contracted for between LAN <b>102</b> and LAN <b>106</b> and issues a setup message to install the appropriate filter an an appropriate network edge device, block <b>304</b>. More specifically, bandwidth broker <b>126</b> issues a command to controller <b>206</b> of network edge device <b>110</b> incorporating the teachings of the present invention to install a filter in filter(s) <b>212</b>. In one embodiment, the newly installed filter issues a trigger when a source of LAN <b>102</b> (e.g., clients <b>112</b>, <b>114</b> and/or <b>116</b>) and a destination of LAN <b>106</b> (e.g., clients <b>120</b> or <b>122</b>) are denoted in the received data packets.
In block <b>306</b>, a determination is made as to whether any of the installed filters of filter(s) <b>212</b> have expired. If so, they as removed from the appropriate network edge device at block <b>308</b>. Thus, in accordance with one aspect of the present invention, a network edge device incorporating the teachings of the present invention allocates only those resources necessary to support filters that are currently needed, thereby reducing the overall amount of resources required of the network device. If the filter has not expired, however, it continues to monitor received data packets for a "hit", e.g., a received data packet which satisfies the filter criteria (e.g., source from LAN <b>102</b> and destination within LAN <b>106</b>), block <b>310</b>. If the received data packets do not satisfy the filter criteria at <b>310</b>, they are processed in accordance with the best-effort service paradigm, <b>312</b>. That is, if data packets are received which do not adhere to a subscribed service level, the ToS field <b>402</b> of the header <b>400</b> appended to the data packets is marked by classifier <b>214</b> to denote a best-effort service level.
If, however, the received data packets satisfy at least one installed filter <b>212</b> at <b>310</b>, a further determination is made by controller <b>206</b> or whether an appropriate classifier profile <b>222</b> is installed in classifier <b>214</b> to appropriately mark the data packets in accordance with their subscribed service level, <b>314</b>. If controller <b>206</b> determined that the necessary profile <b>222</b> is not installed, controller <b>206</b> forwards the trigger notification received from filter <b>212</b> to bandwidth broker <b>126</b> which correlates the trigger notification with the appropriate classifier profile, and issues an update message to classifier <b>214</b> via controller <b>206</b>, block <b>316</b>. In one embodiment, in response to receiving a trigger notification from controller <b>206</b>, bandwidth broker <b>126</b> looks up the received trigger in the admissions policy database to identify an associated classifier profile <b>222</b>,<b>316</b>. Once the appropriate classifier profile <b>222</b> is identified it is sent to classifier <b>214</b> via controller <b>206</b> in an update message. Once the appropriate profile <b>222</b> has been installed in classifier <b>214</b>, classifier <b>214</b> marks the ToS field <b>402</b> of header <b>400</b> appended to the received data packets in accordance with their subscribed service level. In one embodiment, for example, ToS field <b>402</b> is marked to denote a best effort service level, and the data packets an subsequently routed in accordance with their subscribed service level <b>318</b>. At <b>320</b>, a determination is made of whether transmission is complete. If not, the method continues with black <b>318</b>.
If transmission is complete, controller <b>206</b> makes a determination of whether to remove the classifier profile <b>222</b>. In one embodiment, for example, controller <b>206</b> makes this determination in accordance with the service level it supports. For example, if profile <b>222</b> supports the highest service level, and the filter has not yet expired for chat service level, controller <b>206</b> maintains the profile to support the service level with minimal delay. If however, profile <b>222</b> corresponds to a lower service level, controller <b>206</b> may remove the profile, even though the corresponding ulcer remains in place, to liberate network interface <b>204</b> resources, If, In <b>322</b>, a determination is made to remove the filter, controller <b>206</b> instructs classifier <b>214</b> to purge filter <b>222</b>, and an update message is sent to bandwidth broker <b>126</b> denoting the update. Subsequently, the process continues with
Thus, in accordance with the above example, controller <b>206</b> is responsible for the provision of filters <b>212</b> and classifier profiles <b>222</b> necessary to support differentiated services via network edge device <b>110</b>. In one embodiment, controller <b>206</b> relies on the information provided by a remote bandwidth broker <b>126</b> or some other policy server. In an alternate embodiment, controller <b>206</b> accesses a co-located admission policy database autonomously. Irregardless of where the admissions policy database is located, access to the differentiated services of core device <b>108</b> is dynamically controlled through the selective provision of trigger filters end classifier profiles on network devices, e.g., network device <b>110</b>, as appropriate.
Thus, one method for implementing the teachings of the present invention has been described with reference to <b>Figures 1-4</b>. Those skilled in the art will appreciate, however, that modifications and alterations to the network topology, header size, network elements and differentiated services admission policy can be made without deviating from the spirit and scope of the present invention. For example, in addition to the teachings above in <b>Figures 3</b>, controller <b>206</b> may install or remove filter(s) <b>212</b> or classifier profiles <b>222</b> based on time of day, received network traffic, and any of a number of core network operating parameters (e.g., identified faults, etc.). Indeed, such modifications and alterations to the above description are anticipated within the spirit and scope of the present invention. Having described an example network device incorporating the teachings of the present invention with reference to <b>Figure 2</b>, and a method of operation in <b>Figure 3</b>, one embodiment of an example admission profile database is provided wit brief reference to <b>Figure 5</b>. Accordingly, <b>Figure 5</b> illustrates an example two-dimensional admission profile database <b>500</b>, wherein a network administrator establishes the filters and profiles for admission to be provisioned on appropriate network devices controlling access to differentiated services. Although represented as a two-dimensional database, those skilled in the art will appreciate that this is of ease of explanation only, and that a database of greater or lesser complexity may well be substituted for database <b>500</b> without deviating from the spirit and scope of the present invention.
With reference to <b>Figure 5</b>, example admission profile database <b>500</b> is shown comprising classifiers <b>502</b> and <b>504</b> and associated profiles <b>512-522</b> differentiated based on time of day indicators <b>506</b>, <b>508</b> and <b>510</b>. In accordance with the illustrated example embodiment, the filter established on a network device device corresponds to an appropriate one or wait of classifiers <b>502</b> and <b>504</b>, such that the filter associated with classifier <b>502</b> monitors received network traffic for data packets emanating from network A (e.g.. LAN <b>102</b>) destined for network B (e.g., LAN <b>106</b>). Accordingly, when a hit is received corresponding to classifier <b>502</b> during the hours of 9-5, profile <b>512</b> will be installed in classifier <b>214</b> of network edge device <b>110</b> of LAN <b>102</b> to mark darn packets satisfying the filter criteria in accordance with their subscribed service level. In accordance with to information provided by admission control policy database <b>500</b>, such packets are marked for expedited forwarding (EF) with a throughput rate of 10Mbps, no burst in accordance with profile <b>512</b>. Packets corresponding to classifier <b>502</b> received before 9AM or after 5PM will be marked for best-effort delivery, in accordance with profiles <b>514</b> and <b>516</b>. Similarly, profiles <b>518-522</b> denote service level support for network traffic defined by classifier <b>504</b>. Thus, a network device incorporating the teachings of the present invention Installs and removes filters and classifier profiles, defined in an admission policy database, on an as-needed, as-authorized basis, thereby limiting the network and device resources dedicated to supporting the differentiated services of an associated data network.
Turning next to <b>Figure 6</b>, an alternate embodiment of an example network device incorporating the teachings of the present invention is presented. Those skilled in the art will recognize that example network device <b>600</b> is similar to that of network device <b>200</b> presented above, with the notable exceptions that controller <b>206</b> is depicted integrated with network interface <b>204</b> and the addition of egress classifier/profiler <b>602</b>. Thus, those skilled in the art will appreciate that network device <b>600</b> controls the provision of differentiated services by dynamically installing/removing trigger filters and classifier profiles in accordance with an admission control policy. In doing so, network device <b>600</b>, like network device <b>200</b> described more fully above, reduces the amount of network and management resources required to support the differentiated services, thereby reducing the overall cost associated with supporting such services.
In addition to the embodiments described above, those skilled in the art will appreciate that the teachings of the present invention may well be integrated wit a single integrated circuit (not shown). That is, those skilled in the art will appreciate that advances in IC fabrication technology now enable complex systems so be integrated onto a single IC. Thus, in accordance with one embodiment of the present invention, the teachings of the present invention may be practiced within an application specific integrated circuits (ASIC), programmable logic devices (PLD), microcontroller, processor and the like.
While the innovative features for controlling access to network information sources of the present invention have been described in terms of the above illustrated embodiments, those skilled in the art will recognize that the invention is not limited to the embodiments described. The present invention can be practiced with modification and alteration within the spirit and scope of the appended claims. In particular, the present invention may be practiced with other features and/or feature settings. Particular examples at other features include but are not limited to transaction communication protocols and architectural attributes. Accordingly, the description is to be regarded as illustrative instead of restrictive on the present invention.
Thus, alternate methods and apparatus for dynamically controlling the provision of differentiated services incorporating the teachings of the present invention have been described.
Contents5
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8611363B2 | Cited by | United States of America | Applicant |
| US6968374B2 | Cited by | United States of America | Applicant |
| US8565235B2 | Cited by | United States of America | Applicant |
| WO2005018174A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO03005666A2 | Cited by | World Intellectual Property Organization (WIPO) | Applicant |
| WO03005666A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US7028179B2 | Cited by | United States of America | Applicant |
| FR2841713A1 | Cited by | France | Search report |
| EP1376984A1 | Cited by | European Patent Office (EPO) | Search report |
| WO03005666A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
8 members in 4 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 222340 | United States of America | – | |
| 22234098 | United States of America | A | |
| 22234098 | United States of America | A | |
| 222340 | – | – | – |
| US19980222340 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| CA2293130A1 | Canada | A1 | |
| EP1024642A2This record | European Patent Office (EPO) | A2 | |
| EP1024642A3 | European Patent Office (EPO) | A3 | |
| US2002188720A1 | United States of America | A1 | |
| EP1024642B1 | European Patent Office (EPO) | B1 | |
| DE69926477D1 | Germany | D1 | |
| DE69926477T2 | Germany | T2 | |
| CA2293130C | Canada | C |
37 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of representativeR082 | R082 | DE | |
| Change of representativeR082 | R082 | DE | |
| Transmission of propertyTP | TP | FR | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)REGISTERED BETWEEN 20101209 AND 20101215732E | 732E | GB | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation filedET | ET | EP | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Designation fees paidAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1024642
- Publication, DOCDB
- 1024642
- Publication, EPODOC
- EP1024642
- Application
- 99310504
- Application, DOCDB
- 99310504
- Application, EPODOC
- EP19990310504
Titles3
- German
- Verfahren und Vorrichtung zur dynamischen Steuerung der Bereitstellung von differenzierter Diensten
- English
- Method and apparatus for dynamically controlling the provision of differentiated services
- French
- Procédé et appareil pour contrôler de façon dynamique la mise à disposition de services différenciés
Classification
- CPC, 5
- H04L47/10
- H04L47/20
- H04L47/2408
- H04L47/2441
- H04L63/102
- IPC, 2
- H04L12 56
- H04L29 06
Designated states2
- Contracting states, 1
- Sweden
- Extension states, 1
- Slovenia