Decoupling access control from key management in a network
    21.
    发明授权
    Decoupling access control from key management in a network 有权
    将访问控制从网络中的密钥管理中解耦

    公开(公告)号:US07336790B1

    公开(公告)日:2008-02-26

    申请号:US09458020

    申请日:1999-12-10

    IPC分类号: H04L9/32

    CPC分类号: H04L63/0272

    摘要: Methods and systems consistent with the present invention provide a Supernet, a private network constructed out of components from a public-network infrastructure. Supernet nodes can be located on virtually any device in the public network (e.g., the Internet), and both their communication and utilization of resources occur in a secure manner. As a result, the users of a Supernet benefit from their network infrastructure being maintained for them as part of the public-network infrastructure, while the level of security they receive is similar to that of a private network. The Supernet has an access control component and a key management component which are decoupled. The access control component implements an access control policy that determines which users are authorized to use the network, and the key management component implements the network's key management policies, which indicate when keys are generated and what encryption algorithm is used. Both access control and key management are separately configurable. Thus, the Supernet provides great flexibility by allowing different key management policies to be used with the same access control component.

    摘要翻译: 与本发明一致的方法和系统提供了一种Supernet,一种由公共网络基础设施的组件构成的私有网络。 超网络节点可以位于公共网络(例如,因特网)中的几乎任何设备上,并且资源的通信和利用都以安全的方式发生。 因此,Supernet的用户受益于其网络基础架构,作为公共网络基础架构的一部分,而其接收的安全级别与私有网络的安全级别相似。 Supernet具有访问控制组件和分离的密钥管理组件。 访问控制组件实现访问控制策略,其确定哪些用户被授权使用网络,并且密钥管理组件实现网络的密钥管理策略,其指示生成密钥以及使用什么加密算法。 访问控制和密钥管理都可以单独配置。 因此,通过允许不同的密钥管理策略与相同的访问控制组件一起使用,Supernet提供了极大的灵活性。

    Performing message payload processing functions in a network element on behalf of an application
    23.
    发明申请
    Performing message payload processing functions in a network element on behalf of an application 有权
    代表应用程序在网络元素中执行消息有效负载处理功能

    公开(公告)号:US20060123467A1

    公开(公告)日:2006-06-08

    申请号:US11005978

    申请日:2004-12-06

    IPC分类号: H04L9/32

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element receives user-specified input that indicates a particular message classification. The network element also receives one or more data packets. Based on the data packets, the network element determines that an application layer message, which is collectively contained in payload portions of the data packets, matches the particular message classification. The network element processes at least a portion of the message by performing, on behalf of the application to which the message is directed, and relative to at least the portion of the message, one or more actions that are (a) specified in the user-specified input and (b) associated with the particular message classification.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件接收指示特定消息分类的用户指定的输入。 网元还接收一个或多个数据包。 基于数据分组,网元确定在数据分组的有效载荷部分中共同包含的应用层消息与特定消息分类相匹配。 网络元件通过代表消息所针对的应用程序并相对于消息的至少一部分执行一个或多个动作(a)在用户中指定的处理消息的至少一部分 指定的输入和(b)与特定消息分类相关联。

    Mold apparatus
    24.
    发明授权
    Mold apparatus 有权
    模具设备

    公开(公告)号:US06494704B1

    公开(公告)日:2002-12-17

    申请号:US09539549

    申请日:2000-03-31

    IPC分类号: B29C4334

    摘要: Mold press apparatus for use in the manufacture of molded articles, particularly starch-bound containers and other articles. The mold press apparatus includes a planar array of female mold halves and a corresponding planar array of male mold halves. The planar array of mold halves remain substantially coplanar throughout the process of selectively mating and separating the male and female mold halves. When used to manufacture molded articles from aqueous starch-based compositions, the molds are equipped with venting means, such as vent holes and/or a vent gap, which allow for the escape of water vapor from the mold cavities defined by the mated male/female mold pairs. A suction removal system may be used to remove the molded articles from the mold press apparatus, typically from the female mold halves. The demolded articles are deposited on a conveyor system equipped with individual nests for each article.

    摘要翻译: 用于制造模制品,特别是淀粉结合容器和其它制品的模压机。 模压设备包括阴半模的平面阵列和相应的阳半模的平面阵列。 半模的平面阵列在选择性地配合和分离阳模半模和阴半模的整个过程中保持基本共面。 当用于由水性淀粉基组合物制造模塑制品时,模具配备有通气装置,例如通气孔和/或排气间隙,其允许水蒸汽从由配合的阳/ 女模对。 可以使用抽吸移除系统来从模压机装置(通常从阴模半部分)去除模制品。 脱模的物品被放置在配备有每个物品的单独巢的输送系统上。

    Biomass to biochar conversion in subcritical water
    26.
    发明授权
    Biomass to biochar conversion in subcritical water 有权
    生物质在亚临界水中生物炭转化

    公开(公告)号:US08637718B2

    公开(公告)日:2014-01-28

    申请号:US12875549

    申请日:2010-09-03

    IPC分类号: C07C1/00

    摘要: A method and system of converting biomass to biochar in a hydrothermal carbonization apparatus wherein subcritical water at a temperature of 230-350° C. and 500-3000 psi is reacted with the biomass to form biochar, biocrude and gases. The method and system include recycling the biocrude back to the hydrothermal carbonization apparatus which improves biochar yield and provides water for the biomass reaction to occur.

    摘要翻译: 在水热碳化装置中将生物量转化为生物炭的方法和系统,其中在230-350℃和500-3000psi温度下的亚临界水与生物质反应以形成生物炭,生物重油和气体。 该方法和系统包括将生物原料循环回水热碳化装置,其提高生物炭产率并提供生物反应发生的水。

    Limited slip differential using face gears and a pinion housing
    27.
    发明授权
    Limited slip differential using face gears and a pinion housing 有权
    使用面齿轮和小齿轮壳体的有限滑差

    公开(公告)号:US08353800B2

    公开(公告)日:2013-01-15

    申请号:US12760988

    申请日:2010-04-15

    IPC分类号: F16H48/06

    摘要: A differential includes a differential case; a side gear comprising a helical face gear; a helical pinion configured for meshing engagement with the side gear; and a pinion housing configured to support the helical pinion. The pinion housing includes a first face; a second face opposing the first face; a first projection located on the first face; and a second projection located on the second face. In some embodiments, the differential further comprises an actuator configured for engagement with the pinion housing and a plurality of friction plates disposed between the actuator and the differential case. The pinion housing also includes an aperture or hole extending radially inwardly from an outer radial surface of the generally annular ring; and a channel extending from the first face to the second face, wherein the channel is substantially radially aligned with the aperture or hole.

    摘要翻译: 差速器包括差速器壳体; 包括螺旋面齿轮的侧齿轮; 构造成与所述侧齿轮啮合的螺旋小齿轮; 以及构造成支撑所述螺旋小齿轮的小齿轮壳体。 小齿轮壳体包括第一面; 与第一面相对的第二面; 位于第一面上的第一突出部; 以及位于所述第二面上的第二突出部。 在一些实施例中,差速器还包括构造成用于与小齿轮壳体接合的致动器和设置在致动器和差速器壳体之间的多个摩擦板。 小齿轮壳体还包括从大致环形环的外径向表面径向向内延伸的孔或孔; 以及从所述第一面延伸到所述第二面的通道,其中所述通道与所述孔或孔基本上径向对准。

    Identity brokering in a network element
    28.
    发明授权
    Identity brokering in a network element 有权
    身份代理网络元素

    公开(公告)号:US08266327B2

    公开(公告)日:2012-09-11

    申请号:US11455011

    申请日:2006-06-15

    摘要: A network infrastructure element such as a router or switch performs brokering network user identity and credential information. An application or administrative user can declare a policy for user identity information extraction, authentication and authorization. Based on the policy, the network element extracts user identity information or credentials from a transport-layer message header, application-layer message header, and message body. Based on the policy, the network element performs one or more authentication or authorization operations with the user identity information or credentials. As a result, a network element can broker identity information among incompatible applications and perform identity operations for the applications.

    摘要翻译: 诸如路由器或交换机之类的网络基础设施元件执行代理网络用户身份和证书信息。 应用程序或管理用户可以声明用户身份信息提取,身份验证和授权的策略。 基于该策略,网元从传输层消息头,应用层消息头和消息体提取用户身份信息或凭证。 基于该策略,网络元件使用用户身份信息或凭证执行一个或多个认证或授权操作。 因此,网络元素可以在不兼容的应用程序之间代理身份信息,并为应用程序执行身份操作。

    EFFICIENT CACHING FOR DYNAMIC WEBSERVICE QUERIES USING CACHABLE FRAGMENTS
    29.
    发明申请
    EFFICIENT CACHING FOR DYNAMIC WEBSERVICE QUERIES USING CACHABLE FRAGMENTS 有权
    使用可缓存片段进行动态网页查询的高效缓存

    公开(公告)号:US20110270989A1

    公开(公告)日:2011-11-03

    申请号:US13105746

    申请日:2011-05-11

    IPC分类号: G06F15/173

    CPC分类号: G06F17/30902

    摘要: A method and apparatus for intelligent caching is provided. A thin layer of business logic on a web server receives URL requests sent to the web server from clients and resolves the URLs into URLs corresponding to component parts of the requested document according to the rules of a rule set. Thus only the component resources of a composite document are cached in the web server's caching layer. The rule set defines a format for the requests sent to the web server, the manner in which properly formatted requests should be resolved, and the manner in which the component resources should be assembled into the composite document.

    摘要翻译: 提供了智能缓存的方法和装置。 Web服务器上的一薄层业务逻辑接收从客户端发送到Web服务器的URL请求,并根据规则集的规则将URL解析为对应于所请求文档的组成部分的URL。 因此,只有复合文档的组件资源被缓存在Web服务器的缓存层中。 规则集定义了发送到Web服务器的请求的格式,应解析格式正确的请求的方式以及将组件资源组装到复合文档中的方式。

    Performing Message Payload Processing Functions In A Network Element On Behalf Of An Application
    30.
    发明申请
    Performing Message Payload Processing Functions In A Network Element On Behalf Of An Application 有权
    在应用程序的网络元素中执行消息有效负载处理功能

    公开(公告)号:US20110208867A1

    公开(公告)日:2011-08-25

    申请号:US13100144

    申请日:2011-05-03

    IPC分类号: G06F15/16

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element intercepts data packets comprising network layer or transport layer headers having an address of a destination which destination differs from the network element. The network element determines whether information contained in layer 2-4 headers of the data packet satisfies specified criteria. If the information satisfies the specified criteria, the network element directs the data packets to a blade of the network element that performs processing based on an application layer message at least partially contained in the data packets. If the information does not satisfy the specified criteria, the network element forwards the data packets towards the destination without sending them to the blade.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件拦截包括网络层或传输层报头的数据分组,其具有目的地与网络元素不同的目的地地址。 网元确定包含在数据包的第2-4层头中的信息是否满足指定的标准。 如果信息满足指定的标准,则网络元件将数据分组引导到基于至少部分地包含在数据分组中的应用层消息执行处理的网元的叶片。 如果信息不符合规定的标准,则网络单元将数据包转发到目的地,而不将其发送到刀片。