Secure Route Discovery Node and Policing Mechanism
    102.
    发明申请
    Secure Route Discovery Node and Policing Mechanism 审中-公开
    安全路由发现节点和管理机制

    公开(公告)号:US20110066851A1

    公开(公告)日:2011-03-17

    申请号:US12558744

    申请日:2009-09-14

    IPC分类号: H04L9/00 G06F15/173

    摘要: A computer implemented method and computer program product for obtaining a secure route. A trusted host sets a node security association for a trusted host. The trusted host receives, at the trusted host, a client communication request directed to a destination host. The trusted host builds a secure route query comprising a trusted host address, a destination host address, and at least one security level, to form at least one secure route. The trusted host sends packets from the trusted host to the destination host based on the at least one secure route. The packets are responsive to the client communication request, and the packets each have a security label that matches the security level.

    摘要翻译: 一种用于获得安全路线的计算机实现的方法和计算机程序产品。 可信主机为可信主机设置节点安全关联。 可信主机在受信任的主机处接收指向目的地主机的客户端通信请求。 可信主机构建包括可信主机地址,目的主机地址和至少一个安全级别的安全路由查询,以形成至少一个安全路由。 可信主机基于至少一个安全路由将信息包从可信主机发送到目的地主机。 分组响应于客户端通信请求,并且分组各自具有与安全级别匹配的安全标签。

    Receiving and transmitting devices for providing fragmentation at a transport level along a transmission path
    103.
    发明授权
    Receiving and transmitting devices for providing fragmentation at a transport level along a transmission path 失效
    接收和发送设备,用于沿着传输路径在传输层提供分片

    公开(公告)号:US07804780B2

    公开(公告)日:2010-09-28

    申请号:US12275689

    申请日:2008-11-21

    IPC分类号: G01R31/08 H04L12/28 H04J3/16

    摘要: The present invention provides receiving and transmitting devices for providing fragmentation at a transport level along a transmission path. The transmitting device comprises an interface and a control unit coupled to the interface. The control unit is adapted to negotiate a packet size with a remote device. The control unit is also adapted to transmit a data packet of up to the negotiated size. The control unit is further adapted to receive acknowledgments from the remote device associated with one or more fragments, fragmented at the transport-level, of the transmitted data packet. The receiving device comprises an interface and a control unit coupled to the interface. The control unit is adapted to receive two or more fragments of a data packet transmitted by a remote device. The control unit is also adapted to transmit one or more acknowledgments to the remote device based on the received fragments.

    摘要翻译: 本发明提供了一种用于在沿着传输路径的传输层提供分段的接收和传输设备。 发送设备包括接口和耦合到接口的控制单元。 控制单元适于与远程设备协商分组大小。 控制单元还适于发送高达协商尺寸的数据分组。 所述控制单元还适于从所述远程设备接收与传输数据分组的传输级分段的一个或多个片段相关联的确认。 接收设备包括接口和耦合到接口的控制单元。 控制单元适于接收由远程设备发送的数据分组的两个或多个分段。 控制单元还适于基于接收到的片段向远程设备发送一个或多个确认。

    METHOD FOR ADJUSTING MSS OR PACKETS SENT TO A BRIDGE DEVICE POSITIONED BETWEEN VIRTUAL AND PHYSICAL LANS
    104.
    发明申请
    METHOD FOR ADJUSTING MSS OR PACKETS SENT TO A BRIDGE DEVICE POSITIONED BETWEEN VIRTUAL AND PHYSICAL LANS 失效
    将MSS或分组调整到位于虚拟和物理区域之间的桥接设备的方法

    公开(公告)号:US20090135840A1

    公开(公告)日:2009-05-28

    申请号:US11945651

    申请日:2007-11-27

    IPC分类号: H04L12/66

    摘要: A method and apparatus are provided for use with a SEA or other bridge device, which is positioned between virtual and physical LANS and is adapted to monitor connection setup packets. If the SEA detects such a packet, it determines whether it can accommodate the MSS value listed in the packet. In one embodiment, a method is provided for implementation by a bridge device positioned to transfer data packets between a specified LPAR system arid a specified host. The method comprises the step of detecting a packet that is transmitted to the bridge device, in order to set up a connection between the LPAR system and the host. The method further comprises determining whether the detected packet indicates an initial MSS value for the connection that is greater than a prespecified MSS value. Upon determining that the detected packet indicates an initial MSS value that exceeds the prespecified MSS value, the packet is altered to establish the prespecified MSS value as the MSS value for the connection.

    摘要翻译: 提供了一种与SEA或其他桥接设备一起使用的方法和设备,该设备位于虚拟LAN和物理LAN之间,并且适于监视连接建立分组。 如果SEA检测到这样的分组,则它确定它是否可以适应分组中列出的MSS值。 在一个实施例中,提供了一种用于由定位成在指定的LPAR系统和指定的主机之间传送数据分组的网桥设备来实现的方法。 该方法包括检测发送到网桥设备的分组的步骤,以便建立LPAR系统和主机之间的连接。 所述方法还包括确定检测到的分组是否指示连接的初始MSS值大于预先指定的MSS值。 在确定检测到的分组指示超过预先指定的MSS值的初始MSS值时,改变分组以建立预先指定的MSS值作为连接的MSS值。

    Method and apparatus for preventing network outages
    106.
    发明授权
    Method and apparatus for preventing network outages 失效
    防止网络中断的方法和装置

    公开(公告)号:US07526706B2

    公开(公告)日:2009-04-28

    申请号:US11334677

    申请日:2006-01-18

    IPC分类号: H04L1/18 G01R31/08

    摘要: A computer implemented method, apparatus, and computer usable program code to determine whether an acknowledgment packet from an end point acknowledges receipt of unsent data in response to receiving the acknowledgement packet over a connection with the end point. A determination is made as to whether acknowledgement packets for unsent data have been received sequentially a selected number of times over the connection in response to the acknowledgement packet being for unsent data. The acknowledgment packet is dropped if acknowledgement packets have been received sequentially the selected number of times over the connection.

    摘要翻译: 计算机实现的方法,装置和计算机可用程序代码,用于确定来自端点的确认分组是否响应于通过与终点的连接接收到确认分组来确认未发送数据的接收。 确定响应于对于未发送数据的确认分组,是否已经通过连接顺序地接收到选定次数的未发送数据的确认分组。 如果在连接上已经顺序地接收到选定次数的确认分组,则确认分组被丢弃。

    Method for multicast tunneling for mobile devices
    107.
    发明授权
    Method for multicast tunneling for mobile devices 失效
    移动设备组播隧道方法

    公开(公告)号:US07512085B2

    公开(公告)日:2009-03-31

    申请号:US10875897

    申请日:2004-06-24

    摘要: The present invention provides a method and apparatus for multicast tunneling for mobile devices. The method comprises receiving a multicast packet directed to a plurality of mobile nodes, the mobile nodes being associated with a home subnet and identifying if any of the plurality of the mobile nodes are coupled to a subnet other than the home subnet, wherein each of the identified mobile nodes has an associated transmission path through which that mobile node can be reached. The method further provides that in response to determining that at least some of the mobile nodes are coupled to the subnet other than the home subnet, determining which of the identified mobile nodes has a common next hop in their associated transmission path and generating a packet including at least a portion of the multicast packet and including in the packet a list of mobile nodes that have the common next hop. The method further provides for transmitting the generated packet to the common next hop.

    摘要翻译: 本发明提供一种用于移动设备的组播隧道的方法和装置。 所述方法包括:接收指向多个移动节点的多播分组,所述移动节点与归属子网相关联,并且识别所述多​​个所述移动节点中的任一个是否耦合到除所述归属子网之外的子网,其中, 识别的移动节点具有相关联的传输路径,通过该路径可以到达该移动节点。 该方法进一步规定,响应于确定至少一些移动节点被耦合到除了​​归属子网之外的子网,确定所识别的移动节点中哪一个在其相关联的传输路径中具有共同的下一跳,并且生成包括 所述多播分组的至少一部分并且在分组中包括具有公共下一跳的移动节点的列表。 该方法进一步提供将生成的分组发送到公共下一跳。

    Method and Apparatus for an Improved Bulk Read Socket Call
    108.
    发明申请
    Method and Apparatus for an Improved Bulk Read Socket Call 失效
    改进的批量读取套接字呼叫的方法和装置

    公开(公告)号:US20090070481A1

    公开(公告)日:2009-03-12

    申请号:US12274031

    申请日:2008-11-19

    IPC分类号: G06F15/16

    CPC分类号: H04L49/90

    摘要: An apparatus and method for an improved bulk read socket call are provided. With the apparatus and method, a new field, so_rcvlen, is added to the socket structure that identifies the bulk read size requested by the user. The kernel of the prior art recv( ) function is also modified so that it sets the so_rcvlen to the size requested by the user prior to the recv( ) function going to sleep and waiting for the full data size requested by the user. A new flag, SP_MSGWAITALL, is also provided in the socket structure. In the TCP input processing, when data is received for a particular socket, the current setting of the SP_MSGWAITALL is checked. If the SP_MSGWAITALL flag is set, it is determined whether the amount of data stored in the socket receive buffer is less than the value of so_rcvlen. If not, the TCP input processing does not wake up the recv( ) thread. However, for every alternate segment, the TCP input processing sends back an acknowledgment (ACK). In the TCP output processing, when the SP_MSGWAITALL flag is set and the amount of data in the socket receive buffer is less than so_rcvlen, the full window is advertised. Once the TCP input processing determines that there is at least an amount of data in the socket receive buffer equal to the value of so_rcvlen, the TCP input processing will wake up the recv( ) thread and the SP_MSGWAITALL flag is reset.

    摘要翻译: 提供了一种改进的大容量读取插座呼叫的装置和方法。 使用设备和方法,将新字段so_rcvlen添加到标识用户请求的批量读取大小的套接字结构中。 现有技术recv()函数的内核也被修改,以便在recv()函数进入休眠状态并等待用户请求的完整数据大小之前,将so_rcvlen设置为用户请求的大小。 插座结构中还提供了一个新标志SP_MSGWAITALL。 在TCP输入处理中,当为特定套接字收到数据时,将检查SP_MSGWAITALL的当前设置。 如果设置了SP_MSGWAITALL标志,则确定存储在套接字接收缓冲区中的数据量是否小于so_rcvlen的值。 如果没有,TCP输入处理不会唤醒recv()线程。 然而,对于每个备用段,TCP输入处理发回确认(ACK)。 在TCP输出处理中,当设置了SP_MSGWAITALL标志并且套接字接收缓冲区中的数据量小于so_rcvlen时,将通告完整窗口。 一旦TCP输入处理确定套接字接收缓冲区中至少有一定数量的数据等于so_rcvlen的值,则TCP输入处理将唤醒recv()线程,并重置SP_MSGWAITALL标志。

    Method for faster detection and retransmission of lost TCP segments
    109.
    发明授权
    Method for faster detection and retransmission of lost TCP segments 失效
    快速检测和重传丢失的TCP段的方法

    公开(公告)号:US07496038B2

    公开(公告)日:2009-02-24

    申请号:US11301103

    申请日:2005-12-12

    IPC分类号: H04J1/16

    CPC分类号: H04L69/16 H04L69/163

    摘要: A method, network receiver and TCP network that enables a receiver-side triggering of the fast retransmit mechanism when a TCP packet/segment is lost or received out-of sequencing order. The receiver is enhanced with a Fast Retransmit Support (FRS) utility that monitors when a next received packet is out-of-order and responds by transmitting a duplicate acknowledgment (ACK) response that includes therein the same window value as the previous ACK. By including the previous clock time, even when the current window value has advanced, the fast retransmit algorithm at the transmitter is triggering before the timeout period.

    摘要翻译: 一种方法,网络接收机和TCP网络,当TCP分组/分段丢失或接收到排序顺序时,使得接收机侧触发快速重传机制。 使用快速重传支持(FRS)实现增强接收机,该实用程序监视下一个接收到的分组是否处于无序状态,并通过发送其中包含与先前ACK相同的窗口值的重复确认(ACK)响应进行响应。 通过包括先前的时钟时间,即使当前窗口值已经提前,发射机的快速重传算法在超时时间之前被触发。