METHOD AND DEVICE FOR MIGRATING A STATEFUL FUNCTION

    公开(公告)号:EP3493058A1

    公开(公告)日:2019-06-05

    申请号:EP17306699.4

    申请日:2017-12-04

    Abstract: A first salient idea is to keep the traffic flowing though the migrating stateful function, without freezing any connection as the traffic is steered, and to process the data traffic by the first instance as the migration is ongoing when the data traffic corresponds to an existing state and does not require any state update. A second salient idea is to forward the data traffic received by the first instance to the second instance when the data traffic corresponds to a new state created or an existing state updated by the first instance as the migration is ongoing. The first instance will process the traffic with or without forwarding to the second instance as long as it receives any data traffic. The migration terminates when the first instance no longer receives any data traffic. The data traffic, forwarded by the first instance to the second instance, is forwarded together with a metadata describing the new state creation or the existing state update, allowing the second instance to process both the data traffic resulting from a traffic steered from to the second instance and the traffic still buffered by the first instance after the migration started, resulting in a data loss less migration. Processing the data traffic by the first instance for existing states without forwarding to the second instance and forwarding the data traffic from the first instance to the second instance along with a metadata allows to keep a high level of performance of the stateful function by maintaining the data processing by the first instance while the second instance is starting, and to avoid any data loss during the migration by forwarding the data traffic received and processed, after the migration started, by the first instance, along with the metadata for any new state to the second instance.

    METHOD AND DEVICE FOR SECURELY ACCESSING A WEB SERVICE
    3.
    发明公开
    METHOD AND DEVICE FOR SECURELY ACCESSING A WEB SERVICE 审中-公开
    方法和设备安全访问到Web服务

    公开(公告)号:EP2898654A1

    公开(公告)日:2015-07-29

    申请号:EP13762509.1

    申请日:2013-09-16

    Abstract: The invention relates to a method for securely accessing a web service by a browser running a web application on a user device through a network, wherein the web service is hosted by a local device. The method is remarkable in that the local device comprises a global name that uniquely identifies the local device and a certificate associated to its global name and in that the method further comprises a step of sending by the web application to the network a request for accessing a generic name addressing the web service; a step of receiving from the network to the web application a response to the request comprising the global name identifying the local device hosting the web service; a step of verifying by the web application that the received global name is comprised in a list, called white list, wherein the white list comprises global names of local devices being trusted for hosting the web service; and when the verification is successful, a step of sending by the web application to the network a request for securely accessing the global name addressing the web service authenticated by the certificate, the certificate being checked by the browser during the connection.

    DEVICES AND METHODS FOR CLIENT DEVICE AUTHENTICATION

    公开(公告)号:EP3413508A1

    公开(公告)日:2018-12-12

    申请号:EP17305661.5

    申请日:2017-06-06

    CPC classification number: H04L9/3228 H04L9/3242 H04L9/3271

    Abstract: A device (220, 230) stores a main password and at least one temporary password for client authentication. In one embodiment, directed to Wi-Fi, the device is an access point (220) that begins a device insertion protocol without knowing which password the user input. The access point (220) generates (S318) PMKs for the passwords it stores and then generates (S320) from the PMKs PTKs that are used to verify (S322) a MIC1 received from the client (210). The PTK that checks the MIC1 is then used to generate (S324) a GTK and a MIC2 that are sent (S326) to the client (210). A similar solution is provided for password-based WPA2 Enterprise. The solutions enable ordinary users to use the main password and a guest to use a temporary password, for example valid for a specific day only, without giving any information about the main password to the guest.

    PLENOPTIC SUB APERTURE VIEW SHUFFLING FOR A RICHER COLOR SAMPLING
    5.
    发明公开
    PLENOPTIC SUB APERTURE VIEW SHUFFLING FOR A RICHER COLOR SAMPLING 审中-公开
    PLENOPTIC子孔径视图舒适的颜色取样

    公开(公告)号:EP3264755A1

    公开(公告)日:2018-01-03

    申请号:EP16305822.5

    申请日:2016-06-30

    Abstract: A system and method for generating multiple images with rich color acquisition using a plenoptic camera having a main lens disposed in front of a micro array of lenses, a mosaic color filter array and an image sensor, characterized in that it comprises: capturing a first set of images using an ordinary state of an electrically controllable birefringent medium being disposed between said main lens and said micro array of lenses, said ordinary state providing an ordinary ray to each pixel; capturing a second set of images using an extraordinary state of said electrically controllable birefringent medium, said extraordinary state splitting the light from said main lens into an ordinary ray and a extraordinary ray respectively impinging on two adjacent pixels of different colors, said extraordinary ray being shifted by distance of one pixel on said image sensor; performing a weighted subtraction of information about said second set of images from information about said first set of images; and generating a final set of images with rich color information from said weighted subtraction and said first set of images.

    Abstract translation: 一种系统和方法,用于使用具有布置在微透镜阵列前面的主透镜,马赛克滤色器阵列和图像传感器的全光照相机来生成具有丰富色彩采集的多个图像,其特征在于,所述系统和方法包括:捕获第一组 使用电可控双折射介质的普通状态的图像设置在所述主透镜和所述透镜微阵列之间,所述普通状态为每个像素提供寻常光线; 使用所述电可控双折射介质的非常态来捕获第二组图像,所述非常态将来自所述主透镜的光分成普通光线和非常光线,分别照射在不同颜色的两个相邻像素上,所述非常光线被移动 通过所述图像传感器上的一个像素的距离; 从关于所述第一组图像的信息中执行关于所述第二组图像的信息的加权减法; 以及从所述加权减法和所述第一组图像中生成具有丰富色彩信息的最终图像组。

    Network system and method for checking plausibility of a value returned by a device
    7.
    发明公开
    Network system and method for checking plausibility of a value returned by a device 审中-公开
    网络系统和方法已被从设备返回的值的可信度检查

    公开(公告)号:EP2999192A1

    公开(公告)日:2016-03-23

    申请号:EP14306449.1

    申请日:2014-09-19

    Abstract: A network system and a method for checking plausibility of value returned by a device in the network system are provided. The network system comprises a plurality of devices. The method for checking plausibility of value returned by a device comprises: computing, by the device, a first hash address in a distributed hash table based on network addressing information and a current output value of the device; determining, by the device, a plurality of current neighbors in the distributed hash table; advertizing, by the device, the current output value of the device and a previous output value of the device to the determined plurality of current neighbors; and checking, by each of the determined plurality of current neighbors, the plausibility of value returned by the device.

    Abstract translation: 本发明提供一种网络系统和用于检查的由设备在网络系统中返回的值真实性的方法。 该网络系统包含设备的多元性。 用于检查的由设备返回的值的合理性,该方法包括:计算由所述装置,在基于网络寻址信息和装置的电流输出值的分布式哈希表的第一散列地址; 确定性挖掘,由所述装置在所述分布式哈希表中的当前邻居的多元性; 刊登广告,由该装置,该装置和该装置当前邻居的确定性开采多个先前输出值的电流输出值; 和检查,由每个当前邻居的确定性开采多个,的值的合理性由设备返回。

    METHOD FOR MANAGING SERVICES CHAINING AT A NETWORK EQUIPMENT, CORRESPONDING NETWORK EQUIPMENT

    公开(公告)号:EP3484109A1

    公开(公告)日:2019-05-15

    申请号:EP17306555.8

    申请日:2017-11-09

    Abstract: A network equipment configured to operate a plurality of network functions (111) and to receive data packets from at least one device (10) at an input classifier (112), comprises one output classifier (112, 113) configured to perform:
    - receiving, after processing by one or several network functions (111) operated at the network equipment (100), a first data packet belonging to a data flow untracked yet by the output classifier (113), the first data packet comprising services chaining information and identification information of the untracked data flow;
    - obtaining, from the services chaining information of the first data packet, a reverse services path to be applied to a further data packet received in response to the first data packet and belonging to the untracked data flow;
    - storing the identification information of the untracked data flow along with the obtained reverse services path.
    Network equipment (100)

Patent Agency Ranking