会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Method, system, and device for negotiating SA on IPv6 network
    • 用于在IPv6网络上协商SA的方法,系统和设备
    • US08418242B2
    • 2013-04-09
    • US12987502
    • 2011-01-10
    • Dong ZhangLifeng Liu
    • Dong ZhangLifeng Liu
    • H04L12/22H04L12/24
    • H04L67/141H04L63/061H04L63/164H04L67/14H04L69/24
    • A method, system, and device for negotiating a security association (SA) on an Internet Protocol version 6 (IPv6) network are disclosed. In this method, the initiator and the responder generate an SA through the interaction of two messages. Compared with the conventional procedure for setting up an SA based on the Internet Key Exchange Protocol (IKE), the interaction procedure in the present invention is simplified significantly. Therefore, the negotiation is faster and more convenient. In addition, with the present invention, cryptographically generated address parameters (CGA Params) are carried in the message and the CGA may be verified so that the invader cannot spoof the address.
    • 公开了一种在因特网协议版本6(IPv6)网络上协商安全关联(SA)的方法,系统和设备。 在这种方法中,发起者和应答者通过两个消息的交互生成SA。 与基于互联网密钥交换协议(IKE)建立SA的常规过程相比,本发明的交互过程被大大简化。 因此,谈判更快更方便。 另外,利用本发明,在消息中携带密码产生的地址参数(CGA Params),并且可以验证CGA,使得入侵者不能欺骗地址。
    • 2. 发明申请
    • METHOD, SYSTEM, AND DEVICE FOR NEGOTIATING SA ON IPv6 NETWORK
    • 在IPv6网络上讨论SA的方法,系统和设备
    • US20110107104A1
    • 2011-05-05
    • US12987502
    • 2011-01-10
    • Dong ZhangLifeng Liu
    • Dong ZhangLifeng Liu
    • H04L9/00
    • H04L67/141H04L63/061H04L63/164H04L67/14H04L69/24
    • A method, system, and device for negotiating a security association (SA) on an Internet Protocol version 6 (IPv6) network are disclosed. In this method, the initiator and the responder generate an SA through the interaction of two messages. Compared with the conventional procedure for setting up an SA based on the Internet Key Exchange Protocol (IKE), the interaction procedure in the present invention is simplified significantly. Therefore, the negotiation is faster and more convenient. In addition, with the present invention, cryptographically generated address parameters (CGA Params) are carried in the message and the CGA may be verified so that the invader cannot spoof the address.
    • 公开了一种在因特网协议版本6(IPv6)网络上协商安全关联(SA)的方法,系统和设备。 在这种方法中,发起者和应答者通过两个消息的交互生成SA。 与基于互联网密钥交换协议(IKE)建立SA的常规过程相比,本发明的交互过程被大大简化。 因此,谈判更快更方便。 另外,利用本发明,在消息中携带密码产生的地址参数(CGA Params),并且可以验证CGA,使得入侵者不能欺骗地址。
    • 3. 发明授权
    • Method, system and apparatus for establishing communication
    • 用于建立通信的方法,系统和装置
    • US08880891B2
    • 2014-11-04
    • US12976701
    • 2010-12-22
    • Lifeng LiuDong Zhang
    • Lifeng LiuDong Zhang
    • H04L9/32H04L29/06
    • H04L63/126H04L9/3247H04L63/0869H04L63/1458H04L2209/20
    • A method, a system, and an apparatus for establishing communication are disclosed. The method is invented to establish communication between at least two communication parties including a first communication party and a second communication party. The method includes: sending a Cryptographically Generated Address (CGA) request to the first communication party; receiving CGA parameters and a CGA signature returned by the first communication party; and authenticating the CGA parameters and the CGA signature, and establishing communication with the first communication party if the authentication succeeds. By using the method disclosed herein, in the process of establishing communication, the communication party authenticates the CGA parameters and CGA signature carried in the CGA extension header to determine authenticity of the CGA, thus preventing the IP address spoofing and preventing or mitigating the network security problems caused by the IP address spoofing.
    • 公开了一种用于建立通信的方法,系统和装置。 该方法被发明以在包括第一通信方和第二通信方的至少两个通信方之间建立通信。 该方法包括:向第一通信方发送加密生成地址(CGA)请求; 接收第一通信方返回的CGA参数和CGA签名; 并认证CGA参数和CGA签名,并且如果认证成功,则建立与第一通信方的通信。 通过使用本文公开的方法,在建立通信的过程中,通信方认证CGA扩展报头中携带的CGA参数和CGA签名以确定CGA的真实性,从而防止IP地址欺骗并防止或减轻网络安全 IP地址欺骗引起的问题。
    • 4. 发明申请
    • METHOD, SYSTEM AND APPARATUS FOR ESTABLISHING COMMUNICATION
    • 用于建立通信的方法,系统和设备
    • US20110093716A1
    • 2011-04-21
    • US12976701
    • 2010-12-22
    • Lifeng LiuDong Zhang
    • Lifeng LiuDong Zhang
    • H04L9/32H04L29/06
    • H04L63/126H04L9/3247H04L63/0869H04L63/1458H04L2209/20
    • A method, a system, and an apparatus for establishing communication are disclosed. The method is invented to establish communication between at least two communication parties including a first communication party and a second communication party. The method includes: sending a Cryptographically Generated Address (CGA) request to the first communication party; receiving CGA parameters and a CGA signature returned by the first communication party; and authenticating the CGA parameters and the CGA signature, and establishing communication with the first communication party if the authentication succeeds. By using the method disclosed herein, in the process of establishing communication, the communication party authenticates the CGA parameters and CGA signature carried in the CGA extension header to determine authenticity of the CGA, thus preventing the IP address spoofing and preventing or mitigating the network security problems caused by the IP address spoofing.
    • 公开了一种用于建立通信的方法,系统和装置。 该方法被发明以在包括第一通信方和第二通信方的至少两个通信方之间建立通信。 该方法包括:向第一通信方发送加密生成地址(CGA)请求; 接收第一通信方返回的CGA参数和CGA签名; 并认证CGA参数和CGA签名,并且如果认证成功,则建立与第一通信方的通信。 通过使用本文公开的方法,在建立通信的过程中,通信方认证CGA扩展报头中携带的CGA参数和CGA签名以确定CGA的真实性,从而防止IP地址欺骗并防止或减轻网络安全 IP地址欺骗引起的问题。
    • 6. 发明授权
    • Method and system for forwarding data between private networks
    • 用于在专用网络之间转发数据的方法和系统
    • US08549286B2
    • 2013-10-01
    • US12915430
    • 2010-10-29
    • Lifeng LiuMin HuangShi Wan
    • Lifeng LiuMin HuangShi Wan
    • H04L29/06
    • H04L12/4675H04L29/12254H04L61/2038H04L63/0272H04L63/166
    • In the field of communications technology, a method and a system for forwarding data between private networks are provided, which can enable terminals in different private networks to securely communicate with each other by using private network addresses. The method includes the following steps. A Secure Socket Layer (SSL) tunnel to an SSL Virtual Private Network (VPN) device in another private network is established. Address allocation information of the another private network is received through the SSL tunnel. The address allocation information and a mapping relation between the address allocation information and a public network IP address of the SSL VPN device transmitting the address allocation information and a session ID of the SSL tunnel transmitting the address allocation information are saved. A data packet whose destination address belongs to the another private network is forwarded to the SSL VPN device of the private network to which the destination address belongs, according to the address allocation information and the mapping relation. Through the method, the SSL VPN device can resolve private network addresses of other private networks.
    • 在通信技术领域中,提供了一种用于在专用网络之间转发数据的方法和系统,其可以使不同专用网络中的终端能够通过使用专用网络地址彼此安全地进行通信。 该方法包括以下步骤。 建立到另一个专用网络中的SSL虚拟专用网(VPN)设备的安全套接层(SSL)隧道。 通过SSL隧道接收另一个专网的地址分配信息。 地址分配信息和地址分配信息与发送地址分配信息的SSL VPN设备的公网IP地址和发送地址分配信息的SSL隧道的会话ID之间的映射关系被保存。 根据地址分配信息和映射关系,将目的地址属于另一个专网的数据包转发到目的地址所属专用网的SSL VPN设备。 通过该方法,SSL VPN设备可以解析其他专用网络的私网地址。
    • 8. 发明申请
    • METHOD AND SYSTEM FOR DETECTING ACCESSING HOST CONTAINED IN NETWORK, AND STATISTIC AND ANALYZING SERVER
    • 用于检测网络中接入主机的方法和系统,以及统计和分析服务器
    • US20100017376A1
    • 2010-01-21
    • US12569459
    • 2009-09-29
    • Yang XINLifeng LiuZhibin ZhengHongliang ZhuKai ZhaoYixian Yang
    • Yang XINLifeng LiuZhibin ZhengHongliang ZhuKai ZhaoYixian Yang
    • G06F15/177G06F17/30
    • H04L41/142H04L29/12509H04L43/028H04L61/2567H04L69/22
    • A detecting method is provided, which includes extracting an Internet Protocol Identifier value from an obtained data packet. The detecting method may further include searching in a record table containing a correspondence relationship between an Internet Protocol Identifier value and a terminal serial number to determine whether the record table contains an adjacent Internet Protocol Identifier value smaller than the extracted Internet Protocol Identifier value and modifying the adjacent Internet Protocol Identifier value that is smaller than the extracted Internet Protocol Identifier value to be the extracted Internet Protocol Identifier value if the record table contains the adjacent Internet Protocol Identifier value smaller than the extracted Internet Protocol Identifier value. Otherwise, the detecting method may also include, adding a new record of the extracted Internet Protocol Identifier value and the corresponding terminal serial number into the record table. When a notification is received, the detecting method may calculate the number of terminal serial numbers in the record table and output the number of terminal serial numbers as the number of hosts. The provided detecting method may further provide a corresponding statistic and analyzing server and a detecting system.
    • 提供一种检测方法,其包括从获得的数据分组提取因特网协议标识符值。 检测方法还可以包括在包含因特网协议标识符值和终端序列号之间的对应关系的记录表中​​进行搜索,以确定记录表是否包含比所提取的因特网协议标识符值小的相邻互联网协议标识符值,并修改 相邻的因特网协议标识符值小于作为所提取的因特网协议标识符值的提取的因特网协议标识符值,如果记录表包含比所提取的因特网协议标识符值小的相邻互联网协议标识符值。 否则,检测方法还可以包括:将所提取的因特网协议标识符值和相应的终端序列号的新记录添加到记录表中。 当接收到通知时,检测方法可以计算记录表中的终端序列号,并输出终端序列号作为主机数。 所提供的检测方法还可以提供相应的统计和分析服务器和检测系统。