Invention Grant
- Patent Title: Supporting access control list rules that apply to TCP segments belonging to ‘established’ connection
-
Application No.: US15820084Application Date: 2017-11-21
-
Publication No.: US10541921B2Publication Date: 2020-01-21
- Inventor: Claude Basso , Joseph A. Kirscht , Natarajan Vaidhyanathan
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Patterson + Sheridan, LLP
- Main IPC: H04L12/743
- IPC: H04L12/743 ; H04L12/26 ; H04L12/801 ; H04L12/46 ; H04L29/06

Abstract:
Embodiments provide a TCAM-based access control list that supports disjunction operations in rules. A network frame is received. Embodiments determine set TCP flags of the network frame. Upon determining that the set TCP flags match a first entry in a numeric range table, bits of a search key corresponding to the first entry are updated. The search key accesses a second entry stored in a TCAM. The first entry further comprises an encode field to scan a TCP header of the network frame for set TCP flags, a first mask field to a condition corresponding to unset TCP flags to identify in the network frame, a second mask field to a condition corresponding to set TCP flags to identify in the network frame, and an operation field specifying a disjunction operation for comparing the set TCP flags with the first mask field and the second mask field.
Public/Granted literature
- US20180097730A1 SUPPORTING ACCESS CONTROL LIST RULES THAT APPLY TO TCP SEGMENTS BELONGING TO 'ESTABLISHED' CONNECTION Public/Granted day:2018-04-05
Information query