会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 41. 发明授权
    • System and method for resolving network addresses for network devices on distributed network subnets
    • 用于解决分布式网络子网上网络设备的网络地址的系统和方法
    • US07072337B1
    • 2006-07-04
    • US10056886
    • 2002-01-25
    • Yuri ArutyunovJohn G. FijolekRonald LeeWilliam Necka
    • Yuri ArutyunovJohn G. FijolekRonald LeeWilliam Necka
    • H04L12/28H04L12/56G06F15/16
    • H04L29/12009H04L12/2801H04L12/2856H04L12/2872H04L29/12028H04L29/12226H04L61/103H04L61/2015
    • A system and methods for traffic gating in a computer network comprising a plurality of subnets are developed. One of the methods implemented in a data-over-cable system includes, responsive to receiving a first address resolution request message on a cable modem from a first host to a second host, generating a second address resolution request message on the cable modem and sending it to the second host. If the second host does not respond with an address resolution protocol reply message to the second request message, the cable modem determines a network subnet associated with the first host. Based on the network subnet, the cable modem determines a network address of a network element arranged to provide routing services to hosts on the subnet associated with the first host. Next, the cable modem generates an address resolution reply message including the network address of the network element and sends it to the first host.
    • 开发了包括多个子网的计算机网络中的流量选通的系统和方法。 在电缆数据系统中实现的方法之一包括响应于在电缆调制解调器上从第一主机接收到第二主机的第一地址解析请求消息,在电缆调制解调器上生成第二地址解析请求消息并发送 它到第二个主机。 如果第二主机不响应于第二请求消息的地址解析协议回复消息,则电缆调制解调器确定与第一主机相关联的网络子网。 基于网络子网,电缆调制解调器确定被布置为向与第一主机相关联的子网上的主机提供路由服务的网元的网络地址。 接下来,电缆调制解调器生成包括网络元件的网络地址的地址解析应答消息并将其发送到第一主机。
    • 44. 发明申请
    • Rules engine for access control lists in network units
    • 以网络为单位的访问控制列表的规则引擎
    • US20060092947A1
    • 2006-05-04
    • US11064227
    • 2005-02-22
    • Daniel O'KeeffeEugene O'NeillEdele O'MalleyKam Choi
    • Daniel O'KeeffeEugene O'NeillEdele O'MalleyKam Choi
    • H04L12/56H04L12/28
    • H04L45/00H04L45/60H04L45/7453H04L47/20
    • A rules engine for the examination of selected fields in an addressed data packet, has an access control list table of which the entries each define an access control list rule, an action and a chain identifier. The access control list rule is a basic rule which refers to a TCP flow. The engine also has an extension rule table of which the entries each define an extension rule, a respective action and a respective rule identifier. The extension rule may refer to a particular flag in a TCP header. When a packet arrives the engine searches both tales. This search is made independently of the usual address lookup. If there is a match in both tables, and the chain identifier matches the extension rule identifier the engine prescribes the action associated with the extension rule. If the chain identifier of a matched access control list rule does not match a rule identifier of a matched extension rule the engine prescribes the action associates with the access control list rule. In the absence of a match with any access control list rule the action on a packet is based on the result from a lookup engine.
    • 用于检查寻址数据分组中的所选字段的规则引擎具有访问控制列表表,其中条目各自定义访问控制列表规则,动作和链标识符。 访问控制列表规则是引用TCP流的基本规则。 引擎还具有扩展规则表,其中条目各自定义扩展规则,相应的动作和相应的规则标识符。 扩展规则可以指TCP头中的特定标志。 当一个包到达时,引擎搜索这两个故事。 该搜索是独立于通常的地址查找。 如果两个表中都有匹配,并且链标识符与扩展规则标识符匹配,则引擎规定与扩展规则相关联的操作。 如果匹配的访问控制列表规则的链标识符与匹配的扩展规则的规则标识符不匹配,则引擎规定与访问控制列表规则相关联的动作。 在没有与任何访问控制列表规则匹配的情况下,数据包上的操作基于查找引擎的结果。
    • 45. 发明授权
    • Packet filter policy verification system
    • 包过滤策略验证系统
    • US07039053B1
    • 2006-05-02
    • US09796314
    • 2001-02-28
    • Michael FreedMichael S. BorellaSatish Amara
    • Michael FreedMichael S. BorellaSatish Amara
    • H04L12/56
    • H04L41/0893H04L45/308H04L45/60H04L47/20
    • A method for determining the validity of an n-dimensional policy table in a router. The router may include a processor, a memory (e.g. ROM, flash memory, non-volatile memory, hard disk, etc.), and two or more policy rules stored in the memory. Each policy rule may have one or more dimensions (or parameters), designated generally by the symbol n. In accord with the method, the processor may make a determination whether any particular policy rule in the table intersects any subsequent policy rule in the table in every dimension n. If no rules in the table intersect in every dimension n, then the policy table is valid, and the router may operate normally.
    • 一种用于确定路由器中的n维策略表的有效性的方法。 路由器可以包括处理器,存储器(例如,ROM,闪速存储器,非易失性存储器,硬盘等)以及存储在存储器中的两个或多个策略规则。 每个策略规则可以具有通常由符号n指定的一个或多个维(或参数)。 根据该方法,处理器可以确定表中的任何特定策略规则是否与每个维度n中的表中的任何后续策略规则相交。 如果表中没有规则在每个维度n相交,则策略表有效,路由器可能正常运行。
    • 46. 发明授权
    • Method and system for distributed network address translation with network security features
    • 具有网络安全特性的分布式网络地址转换方法和系统
    • US07032242B1
    • 2006-04-18
    • US09270967
    • 1999-03-17
    • David GrabelskyMichael S. BorellaIkhlaq SidhuDanny M. Nessett
    • David GrabelskyMichael S. BorellaIkhlaq SidhuDanny M. Nessett
    • H04K1/00H04L9/00G06F15/16
    • H04L63/0407H04L29/12367H04L29/12405H04L61/2514H04L61/2528H04L63/0428
    • A method and system for distributed network address translation with security features. The method and system allow Internet Protocol security protocol (“IPsec”) to be used with distributed network address translation. The distributed network address translation is accomplished with IPsec by mapping a local Internet Protocol (“IP”) address of a given local network device and a IPsec Security Parameter Index (“SPI”) associated with an inbound IPsec Security Association (“SA”) that terminates at the local network device. A router allocates locally unique security values that are used as the IPsec SPIs. A router used for distributed network address translation is used as a local certificate authority that may vouch for identities of local network devices, allowing local network devices to bind a public key to a security name space that combines a global IP address for the router with a set of locally unique port numbers used for distributed network address translation. The router issues security certificates and may itself be authenticated by a higher certificate authority. Using a security certificate, a local network device may initiate and be a termination point of an IPsec security association to virtually any other network device on an IP network like the Internet or an intranet. The method and system may also allow distributed network address translation with security features to be used with Mobile IP or other protocols in the Internet Protocol suite.
    • 一种具有安全特性的分布式网络地址转换方法和系统。 该方法和系统允许使用Internet协议安全协议(“IPsec”)进行分布式网络地址转换。 分布式网络地址转换通过映射给定本地网络设备的本地Internet协议(“IP”)地址和与入站IPsec安全关联(“SA”)相关联的IPsec安全参数索引(“SPI”)来实现IPsec, 终止于本地网络设备。 路由器分配用作IPsec SPI的本地唯一安全性值。 用于分布式网络地址转换的路由器被用作可以保证本地网络设备的身份的本地证书机构,允许本地网络设备将公钥绑定到安全名称空间,该安全名称空间将路由器的全局IP地址与 用于分布式网络地址转换的本地唯一端口号码集。 路由器发出安全证书,并且本身可能由较高的证书颁发机构认证。 使用安全证书,本地网络设备可以发起IPsec安全关联的终端点,并将其作为IP网络上的任何其他网络设备(如Internet或Intranet)的终止点。 该方法和系统还可以允许具有安全特征的分布式网络地址转换与移动IP或因特网协议套件中的其他协议一起使用。