Communication system, control device, communication method, and program
    22.
    发明授权
    Communication system, control device, communication method, and program 有权
    通讯系统,控制装置,通讯方式及程序

    公开(公告)号:US09215237B2

    公开(公告)日:2015-12-15

    申请号:US14119827

    申请日:2012-05-22

    IPC分类号: H04L29/06

    摘要: A communication system includes an information acquisition unit that acquires information for determining an isolation level to which a user terminal belongs, from the user terminal; an isolation level determination unit that determines an isolation level to which the user terminal belongs, based on the acquired information; an isolation level information storage unit that defines whether or not access is possible to respective access destinations for each isolation level; an access control unit that causes a forwarding node(s) to implement forwarding or dropping of a packet, in accordance with whether or not access is possible to the respective access destinations; and a forwarding node(s) that forwards a packet in accordance with control of the access control unit. Stepwise access control is realized using isolation levels.

    摘要翻译: 通信系统包括从用户终端获取用于确定用户终端所属的隔离级别的信息的信息获取单元; 隔离级别确定单元,基于获取的信息确定用户终端所属的隔离级别; 隔离级别信息存储单元,其定义对于每个隔离级别是否可以访问相应的访问目的地; 访问控制单元,其使得转发节点根据是否可以访问相应的访问目的地来实现分组的转发或丢弃; 以及根据访问控制单元的控制转发分组的转发节点。 使用隔离级别实现逐步访问控制。

    COMMUNICATION CONTROL APPARATUS, COMMUNICATION CONTROL METHOD, AND PROGRAM
    25.
    发明申请
    COMMUNICATION CONTROL APPARATUS, COMMUNICATION CONTROL METHOD, AND PROGRAM 有权
    通信控制装置,通信控制方法和程序

    公开(公告)号:US20140123215A1

    公开(公告)日:2014-05-01

    申请号:US14126744

    申请日:2012-06-15

    IPC分类号: H04L29/06

    摘要: A communication control apparatus controls communication between a first apparatus and a second apparatus connected to the first apparatus via a plurality of relay apparatuses. The communication control apparatus comprises: a communication path generation unit that refers to a control policy including access control and supplementary control that is other than the access control from the first apparatus to the second apparatus and refers to network configuration information about a network configuration among the first apparatus, the second apparatus, and the plurality of relay apparatuses and generates a communication path that matches the control policy from the first apparatus to the second apparatus and goes through at least one of the plurality of relay apparatuses; and a communication path control unit that instructs a relay apparatus(es) on the communication path among the plurality of relay apparatuses to execute the access control and the supplementary control included in the control policy.

    摘要翻译: 通信控制装置经由多个中继装置控制第一装置与连接到第一装置的第二装置之间的通信。 通信控制装置包括:通信路径产生单元,其参考包括从第一设备到第二设备的访问控制以外的访问控制和辅助控制的控制策略,并且参考关于网络配置的网络配置信息 第一装置,第二装置和多个中继装置,并且生成与来自第一装置的控制策略相匹配的通信路径到第二装置,并且通过多个中继装置中的至少一个; 以及通信路径控制单元,其指示所述多个中继装置中的所述通信路径上的中继装置执行所述控制策略中包括的所述访问控制和所述辅助控制。

    COMMUNICATION SYSTEM, CONTROL DEVICE, POLICY MANAGEMENT DEVICE, COMMUNICATION METHOD, AND PROGRAM
    26.
    发明申请
    COMMUNICATION SYSTEM, CONTROL DEVICE, POLICY MANAGEMENT DEVICE, COMMUNICATION METHOD, AND PROGRAM 有权
    通信系统,控制设备,策略管理设备,通信方法和程序

    公开(公告)号:US20130322257A1

    公开(公告)日:2013-12-05

    申请号:US13980029

    申请日:2011-08-30

    IPC分类号: H04L12/801

    摘要: A communication system includes a control device; a forwarding node that processes, in accordance with a processing rule set by control device, a packet transmitted from a user terminal; and a policy management device that manages communication policy and notifies the control device of communication policy that corresponds to a user for whom authentication has succeeded; a setting request transmission permitting unit that, based on notification from the policy management device, sets to a forwarding node that receives a packet from the user terminal a first processing rule causing the forwarding node to make a setting request of processing rule with regard to a packet transmitted from the user terminal; and a path control unit that determines path from user terminal to access destination and sets to forwarding node along the path the second processing rule that corresponds to the path.

    摘要翻译: 通信系统包括控制装置; 转发节点,其根据由控制装置设置的处理规则处理从用户终端发送的分组; 以及管理通信策略并向所述控制设备通知与认证成功的用户对应的通信策略的策略管理设备; 设置请求发送许可单元,其基于来自所述策略管理装置的通知,对从所述用户终端接收到分组的转发节点设置使得所述转发节点针对a的处理规则进行设定请求的第一处理规则 从用户终端发送的报文; 以及路径控制单元,其确定从用户终端到接入目的地的路径,并且沿着路径将对应于路径的第二处理规则设置为转发节点。

    NETWORK MANAGEMENT SERVICE SYSTEM, CONTROL APPARATUS, METHOD, AND PROGRAM
    27.
    发明申请
    NETWORK MANAGEMENT SERVICE SYSTEM, CONTROL APPARATUS, METHOD, AND PROGRAM 有权
    网络管理服务系统,控制装置,方法和程序

    公开(公告)号:US20140247751A1

    公开(公告)日:2014-09-04

    申请号:US14343711

    申请日:2012-09-07

    IPC分类号: H04L12/24

    CPC分类号: H04L41/0893 H04L41/5064

    摘要: A network management service system includes a policy management apparatus that receives updating of a communication policy from an user and manages the communication policy for each user; a control apparatus that generates a of a packet associated with the communication policy of the user, in response to a request from the user, and sets the generated in a forwarding node(s); and the forwarding node(s) that processes the packet using the generated by the control apparatus.

    摘要翻译: 网络管理服务系统包括:策略管理装置,其从用户接收通信策略的更新,并管理每个用户的通信策略; 控制装置,响应于来自用户的请求,生成与用户的通信策略相关联的分组,并设置在转发节点中生成的分组; 以及使用由控制装置生成的分组来处理分组的转发节点。

    Network management service system, control apparatus, method, and program
    29.
    发明授权
    Network management service system, control apparatus, method, and program 有权
    网络管理服务系统,控制装置,方法和程序

    公开(公告)号:US09544194B2

    公开(公告)日:2017-01-10

    申请号:US14343711

    申请日:2012-09-07

    IPC分类号: H04L12/26 H04L12/28 H04L12/24

    CPC分类号: H04L41/0893 H04L41/5064

    摘要: A network management service system includes a policy management apparatus that receives updating of a communication policy from an user and manages the communication policy for each user; a control apparatus that generates a packet handling operation of a packet associated with the communication policy of the user, in response to a request from the user, and sets the generated packet handling operation in a forwarding node(s); and the forwarding node(s) that processes the packet using the packet handling operation generated by the control apparatus.

    摘要翻译: 网络管理服务系统包括:策略管理装置,其从用户接收通信策略的更新,并管理每个用户的通信策略; 响应于来自用户的请求,生成与用户的通信策略相关联的分组的分组处理操作的控制装置,并且将所生成的分组处理操作设置在转发节点中; 以及使用由控制装置生成的分组处理操作来处理分组的转发节点。