Systems and methods for cookie proxy jar management across cores in a multi-core system
    11.
    发明授权
    Systems and methods for cookie proxy jar management across cores in a multi-core system 有权
    在多核系统中跨多核的cookie代理jar管理的系统和方法

    公开(公告)号:US08484287B2

    公开(公告)日:2013-07-09

    申请号:US12851449

    申请日:2010-08-05

    IPC分类号: G06F15/16

    摘要: The present solution is directed towards systems and methods for managing cookies by a multi-core device. The device is intermediary to a client and one or more servers. A first core of a multi-core device receives a response from a server to a request of the client through a user session. The response comprises a cookie. The first core removes the cookie from the response and stores the cookie in a corresponding storage for the session. The first core forwards the response without the cookie to the client. A second core then receives via a session, a second request from the client. The second core determines the identification of the first core as owner of the session from the second request. The second core then communicates to the first core a third request for cookie information for the session.

    摘要翻译: 目前的解决方案涉及用于通过多核设备管理Cookie的系统和方法。 该设备是客户端和一个或多个服务器的中介。 多核设备的第一核心通过用户会话接收从服务器到客户端的请求的响应。 响应包括一个cookie。 第一个核心从响应中删除cookie,并将cookie存储在会话的相应存储中。 第一个核心将没有cookie的响应转发给客户端。 然后,第二核心经由会话接收来自客户端的第二请求。 第二核确定第一个核心作为第二个请求中的会话的所有者的标识。 然后,第二个核心向第一个核心传达第三个会话Cookie信息请求。

    Systems and methods for fine grain policy driven clientless SSL VPN access
    12.
    发明授权
    Systems and methods for fine grain policy driven clientless SSL VPN access 有权
    细粒度策略驱动客户端SSL VPN访问的系统和方法

    公开(公告)号:US08893259B2

    公开(公告)日:2014-11-18

    申请号:US12359982

    申请日:2009-01-26

    IPC分类号: H04L29/06 H04L29/08

    摘要: The present disclosure provides solutions that may enable an enterprise providing services to a number of clients to determine whether to establish a client based SSL VPN session or a clientless SSL VPN session with a client based on an information associated with the client. An intermediary establishing SSL VPN sessions between clients and servers may receive a request from a client to access a server. The intermediary may identify a session policy based on the request. The session policy may indicate whether to establish a client based SSL VPN session or clientless SSL VPN session with the server. The intermediary may determine, responsive to the policy, to establish a clientless or client based SSL VPN session between the client and the server.

    摘要翻译: 本公开提供了可以使得能够向多个客户端提供服务的企业基于与客户端相关联的信息来确定是否建立与客户端的基于客户端的SSL VPN会话或客户端SSL VPN会话的解决方案。 在客户端和服务器之间建立SSL VPN会话的中间件可以接收客户端访问服务器的请求。 中介可以根据请求识别会话策略。 会话策略可以指示是否与服务器建立基于客户端的SSL VPN会话或客户端SSL VPN会话。 中介可以根据策略确定在客户端和服务器之间建立基于客户端或客户端的SSL VPN会话。

    SYSTEMS AND METHODS FOR COOKIE PROXY JAR MANAGEMENT ACROSS CORES IN A MULTI-CORE SYSTEM
    13.
    发明申请
    SYSTEMS AND METHODS FOR COOKIE PROXY JAR MANAGEMENT ACROSS CORES IN A MULTI-CORE SYSTEM 有权
    用于多核系统中COROKIE代理管理的系统和方法

    公开(公告)号:US20120036178A1

    公开(公告)日:2012-02-09

    申请号:US12851449

    申请日:2010-08-05

    IPC分类号: G06F15/16

    摘要: The present solution is directed towards systems and methods for managing cookies by a multi-core device. The device is intermediary to a client and one or more servers. A first core of a multi-core device receives a response from a server to a request of the client through a user session. The response comprises a cookie. The first core removes the cookie from the response and stores the cookie in a corresponding storage for the session. The first core forwards the response without the cookie to the client. A second core then receives via a session, a second request from the client. The second core determines the identification of the first core as owner of the session from the second request. The second core then communicates to the first core a third request for cookie information for the session.

    摘要翻译: 目前的解决方案涉及用于通过多核设备管理Cookie的系统和方法。 该设备是客户端和一个或多个服务器的中介。 多核设备的第一核心通过用户会话接收从服务器到客户端的请求的响应。 响应包括一个cookie。 第一个核心从响应中删除cookie,并将cookie存储在会话的相应存储中。 第一个核心将没有cookie的响应转发给客户端。 然后,第二核心经由会话接收来自客户端的第二请求。 第二核确定第一个核心作为第二个请求中的会话的所有者的标识。 然后,第二个核心向第一个核心传达第三个会话Cookie信息请求。

    SYSTEMS AND METHODS FOR FINE GRAIN POLICY DRIVEN CLIENTLESS SSL VPN ACCESS
    14.
    发明申请
    SYSTEMS AND METHODS FOR FINE GRAIN POLICY DRIVEN CLIENTLESS SSL VPN ACCESS 有权
    精细粒度政策驱动客户端SSL VPN访问的系统和方法

    公开(公告)号:US20090193498A1

    公开(公告)日:2009-07-30

    申请号:US12359982

    申请日:2009-01-26

    IPC分类号: H04L9/00

    摘要: The present disclosure provides solutions that may enable an enterprise providing services to a number of clients to determine whether to establish a client based SSL VPN session or a clientless SSL VPN session with a client based on an information associated with the client. An intermediary establishing SSL VPN sessions between clients and servers may receive a request from a client to access a server. The intermediary may identify a session policy based on the request. The session policy may indicate whether to establish a client based SSL VPN session or clientless SSL VPN session with the server. The intermediary may determine, responsive to the policy, to establish a clientless or client based SSL VPN session between the client and the server.

    摘要翻译: 本公开提供了可以使得能够向多个客户端提供服务的企业基于与客户端相关联的信息来确定是否建立与客户端的基于客户端的SSL VPN会话或客户端SSL VPN会话的解决方案。 在客户端和服务器之间建立SSL VPN会话的中间件可以接收客户端访问服务器的请求。 中介可以根据请求识别会话策略。 会话策略可以指示是否与服务器建立基于客户端的SSL VPN会话或客户端SSL VPN会话。 中介可以根据策略确定在客户端和服务器之间建立基于客户端或客户端的SSL VPN会话。

    Systems and methods for proxying cookies for SSL VPN clientless sessions
    16.
    发明授权
    Systems and methods for proxying cookies for SSL VPN clientless sessions 有权
    用于代理SSL VPN无客户端会话的Cookie的系统和方法

    公开(公告)号:US08769660B2

    公开(公告)日:2014-07-01

    申请号:US12360019

    申请日:2009-01-26

    IPC分类号: G06F15/16

    摘要: The present application enables the enterprise to configure various policies to address various subsets of the traffic based on various information relating the client, the server, or the details and nature of the interactions between the client and the server. An intermediary deployed between clients and servers may establish an SSL VPN session between a client and a server. The intermediary may receiving a response from a server to a request of a client via the clientless SSL VPN session. The response may comprise one or more cookies. The intermediary may identify an access profile for the clientless SSL VPN session. The access profile may identify one or more policies for proxying cookies. The intermediary may determine, responsive to the one or more policies of the access profile, whether to proxy or bypass proxying for the client the one or more cookies.

    摘要翻译: 本应用使得企业能够基于与客户端,服务器或客户端与服务器之间的交互的细节和性质相关的各种信息来配置各种策略来处理流量的各种子集。 部署在客户端和服务器之间的中介可以在客户端和服务器之间建立SSL VPN会话。 中间人可以通过无客户端SSL VPN会话从服务器接收到客户端的请求的响应。 响应可以包括一个或多个cookie。 中介可以识别无客户端SSL VPN会话的访问配置文件。 访问配置文件可以标识用于代理Cookie的一个或多个策略。 中介可以响应于访问简档的一个或多个策略来确定是否为客户端代理或绕过代理一个或多个cookie。

    Systems and methods for fine grain policy driven cookie proxying
    17.
    发明授权
    Systems and methods for fine grain policy driven cookie proxying 有权
    细粒度政策驱动的Cookie代理的系统和方法

    公开(公告)号:US08090877B2

    公开(公告)日:2012-01-03

    申请号:US12360014

    申请日:2009-01-26

    IPC分类号: G07F15/16

    摘要: The present solution enables a client that is not configured to use cookies to access resources of the server that uses cookies for communications with the clients. An intermediary deployed between a client and a server intercepts and modifies transmissions between the client and the server to compensate for the mismatch in configuration of the cookies between the client and the server. The present disclosure relates to a method for managing cookies by an intermediary for a client. An intermediary receives a response from a server to a request of a client. The response may comprise a uniform resource locator (URL) and a cookie. The intermediary may modify the response by removing the cookie from the response and inserting a unique client identifier into the URL. The intermediary may store the removed cookie in association with the unique client identifier and forward the modified response to the client.

    摘要翻译: 本解决方案使未配置为使用Cookie的客户端访问使用Cookie与客户端通信的服务器的资源。 部署在客户端和服务器之间的中间人拦截并修改客户端和服务器之间的传输,以补偿客户端和服务器之间的Cookie配置不匹配。 本公开涉及一种用于由客户端的中间人管理cookie的方法。 中介从服务器接收到客户端请求的响应。 响应可以包括统一的资源定位符(URL)和cookie。 中间人可以通过从响应中删除cookie并将唯一的客户端标识符插入到URL中来修改响应。 中介可以将删除的cookie与唯一的客户端标识符相关联地存储,并将修改的响应转发给客户端。

    Systems and Methods for For Proxying Cookies for SSL VPN Clientless Sessions
    18.
    发明申请
    Systems and Methods for For Proxying Cookies for SSL VPN Clientless Sessions 有权
    用于代理SSL VPN客户端会话的Cookie的系统和方法

    公开(公告)号:US20090199285A1

    公开(公告)日:2009-08-06

    申请号:US12360019

    申请日:2009-01-26

    IPC分类号: H04L9/32

    摘要: The present application enables the enterprise to configure various policies to address various subsets of the traffic based on various information relating the client, the server, or the details and nature of the interactions between the client and the server. An intermediary deployed between clients and servers may establish an SSL VPN session between a client and a server. The intermediary may receiving a response from a server to a request of a client via the clientless SSL VPN session. The response may comprise one or more cookies. The intermediary may identify an access profile for the clientless SSL VPN session. The access profile may identify one or more policies for proxying cookies. The intermediary may determine, responsive to the one or more policies of the access profile, whether to proxy or bypass proxying for the client the one or more cookies.

    摘要翻译: 本应用使得企业能够基于与客户端,服务器或客户端与服务器之间的交互的细节和性质相关的各种信息来配置各种策略来处理流量的各种子集。 部署在客户端和服务器之间的中介可以在客户端和服务器之间建立SSL VPN会话。 中间人可以通过无客户端SSL VPN会话从服务器接收到客户端的请求的响应。 响应可以包括一个或多个cookie。 中介可以识别无客户端SSL VPN会话的访问配置文件。 访问配置文件可以标识用于代理Cookie的一个或多个策略。 中介可以响应于访问简档的一个或多个策略来确定是否为客户端代理或绕过代理一个或多个cookie。

    Systems and Methods for Fine Grain Policy Driven Cookie Proxying
    19.
    发明申请
    Systems and Methods for Fine Grain Policy Driven Cookie Proxying 有权
    细粒度政策驱动的Cookie代理的系统和方法

    公开(公告)号:US20090193129A1

    公开(公告)日:2009-07-30

    申请号:US12360014

    申请日:2009-01-26

    IPC分类号: G06F15/16

    摘要: The present solution enables a client that is not configured to use cookies to access resources of the server that uses cookies for communications with the clients. An intermediary deployed between a client and a server intercepts and modifies transmissions between the client and the server to compensate for the mismatch in configuration of the cookies between the client and the server. The present disclosure relates to a method for managing cookies by an intermediary for a client. An intermediary receives a response from a server to a request of a client. The response may comprise a uniform resource locator (URL) and a cookie. The intermediary may modify the response by removing the cookie from the response and inserting a unique client identifier into the URL. The intermediary may store the removed cookie in association with the unique client identifier and forward the modified response to the client.

    摘要翻译: 本解决方案使未配置为使用Cookie的客户端访问使用Cookie与客户端通信的服务器的资源。 部署在客户端和服务器之间的中间人拦截并修改客户端和服务器之间的传输,以补偿客户端和服务器之间的Cookie配置不匹配。 本公开涉及一种用于由客户端的中间人管理cookie的方法。 中介从服务器接收到客户端请求的响应。 响应可以包括统一的资源定位符(URL)和cookie。 中间人可以通过从响应中删除cookie并将唯一的客户端标识符插入到URL中来修改响应。 中介可以将删除的cookie与唯一的客户端标识符相关联地存储,并将修改的响应转发给客户端。

    Generic offload architecture
    20.
    发明授权
    Generic offload architecture 有权
    通用卸载架构

    公开(公告)号:US09043450B2

    公开(公告)日:2015-05-26

    申请号:US12580094

    申请日:2009-10-15

    IPC分类号: G06F15/177 G06F9/50 H04L29/08

    摘要: An system comprising an ingress device configured to receive and process data, wherein the ingress device comprises a plurality of processing stages configured to process the data, wherein a configurable subset of the stages comprises a selectable tap point, and wherein the ingress device is further configured to, upon reaching a selected tap point, suspend processing and send at least a portion of the data to another device; an offload engine device configured to receive data from the ingress device, after the selected tap point has been reached, and to provide additional processing of the data, which the ingress device is not configured to provide; an egress device configured to transmit the data that has been additionally processed by the offload engine device.

    摘要翻译: 一种包括被配置为接收和处理数据的入口设备的系统,其中所述入口设备包括被配置为处理所述数据的多个处理级,其中所述级的可配置子集包括可选择的抽头点,并且其中所述入口设备被进一步配置 在到达所选择的分接点之后,暂停处理并将至少一部分数据发送到另一设备; 卸载引擎装置,其被配置为在到达所选择的分接点之后从所述入口设备接收数据,并且为所述数据提供附加处理,所述数据是入口设备未被配置为提供的; 被配置为发送由卸载引擎设备另外处理的数据的出口设备。