Extensible authentication and authorization of identities in an application message on a network device
    21.
    发明授权
    Extensible authentication and authorization of identities in an application message on a network device 有权
    在网络设备上的应用消息中可扩展认证和身份认证

    公开(公告)号:US08613056B2

    公开(公告)日:2013-12-17

    申请号:US11441594

    申请日:2006-05-26

    IPC分类号: H04L29/06

    CPC分类号: H04L63/08 H04L63/104

    摘要: User credentials are validated within a network infrastructure element such as a packet data router or switch. The network element has authentication and authorization logic for receiving one or more packets representing an input application message logically associated with OSI network model Layer 5 or above; extracting user credentials from the one or more packets; authenticating an identity associated with the user credentials; authorizing privileges to the identity; and forwarding the application message to an intended destination if the identity is successfully authenticated and/or authorized. The authentication and authorization logic in the network element can invoke extension authentication and authorization methods that may be provisioned after the network element is deployed in a networked system.

    摘要翻译: 用户凭证在诸如分组数据路由器或交换机的网络基础设施元件内被验证。 网元具有用于接收表示与OSI网络模型层5或更高逻辑地相关联的输入应用消息的一个或多个分组的认证和授权逻辑; 从一个或多个分组提取用户凭证; 认证与用户凭证相关联的身份; 授权身份的特权; 并且如果身份被成功地认证和/或授权,则将应用消息转发到预期目的地。 网络元素中的认证和授权逻辑可以调用在网络元件部署在网络系统中之后可以配置的扩展认证和授权方法。

    System and method for enabling scalable security in a virtual private network
    23.
    发明授权
    System and method for enabling scalable security in a virtual private network 有权
    用于实现虚拟专用网络中的可扩展安全性的系统和方法

    公开(公告)号:US07765581B1

    公开(公告)日:2010-07-27

    申请号:US09457914

    申请日:1999-12-10

    IPC分类号: H04L9/00

    摘要: Methods and systems consistent with the present invention provide dynamic security policies that change the granularity of the security at the node level, process level, or socket level. Specifically, a channel number and virtual address are associated with various processes included in a process table. Since a security policy is required for all processes, secure and insecure processes located on the same channel may communicate with one another. Moreover, processes located on different channels may communicate with one another by a gateway that connects both channels. This scalable blanketing security approach provides an institutionalized method for securing any process, node or socket by providing a unique mechanism for policy enforcement at runtime or by changing the security policies.

    摘要翻译: 与本发明一致的方法和系统提供动态安全策略,其改变节点级别,过程级别或套接字级别的安全性的粒度。 具体地,通道号和虚拟地址与包括在处理表中的各种处理相关联。 由于所有进程都需要安全策略,因此位于同一通道上的安全和不安全进程可能会相互通信。 此外,位于不同信道上的进程可以通过连接两个信道的网关彼此通信。 这种可扩展的覆盖安全方法提供了一种制度化的方法,用于通过在运行时或通过更改安全策略提供用于策略实施的唯一机制来保护任何进程,节点或套接字。

    Flexible field based energy efficient multimedia processor architecture and method
    24.
    发明申请
    Flexible field based energy efficient multimedia processor architecture and method 审中-公开
    灵活场效能多媒体处理器架构与方法

    公开(公告)号:US20090238263A1

    公开(公告)日:2009-09-24

    申请号:US12322721

    申请日:2009-02-06

    IPC分类号: H04N7/30 H04N7/26

    摘要: A programmable energy efficient codec system is provided for encoding and decoding a plurality of application environments. A camera Codec and control system for an HD camera is provided for encoding uncompressed HD-SDI video signals into an MPEG-2 transport stream. A stand-alone encoder decoder system is provided in a network configuration allowing for remote display and editing of HD-SDI video. At least one plurality of HD-SDI transport streams is generated from HD-Cameras encoded into MPEG-2 transport streams and output into a DVD-ASI signal and a TS/IP packet stream further provided is a decoder which accepts MPEG-2-TS/IP packet streams from a routed IP network which are decoded into an uncompressed HD-SDI transport stream for display. A set top box is provided for decoding audio and video HD-TV. A first HDMI interface into the decoder allows acceptance of an MPEG-2-TS from local storage media. Connection to an IP routed network is provided. The set top box may also request product specific decoder algorithms from a centralized manager. A kernel is provided in software which enables dramatic power reduction and ease of system update.

    摘要翻译: 提供了一种用于对多个应用环境进行编码和解码的可编程节能编解码器系统。 提供了一种用于高清摄像机的编解码器和控制系统,用于将未压缩的HD-SDI视频信号编码为MPEG-2传输流。 提供了一种独立的编码器解码器系统,其网络配置允许HD-SDI视频的远程显示和编辑。 从被编码为MPEG-2传输流的HD相机产生至少多个HD-SDI传输流,并输出到DVD-ASI信号,并且进一步提供的TS / IP分组流是接受MPEG-2-TS 来自路由IP网络的IP分组流,其被解码为未压缩的HD-SDI传输流以进行显示。 提供机顶盒,用于解码音视频HD-TV。 解码器中的第一HDMI接口允许从本地存储介质接受MPEG-2-TS。 提供与IP路由网络的连接。 机顶盒还可以从集中管理器请求产品特定的解码器算法。 软件中提供内核,可实现显着的功耗降低和系统更新的便利性。

    MANAGEMENT OF APPLICATION SPECIFIC DATA TRAFFIC
    26.
    发明申请
    MANAGEMENT OF APPLICATION SPECIFIC DATA TRAFFIC 审中-公开
    应用特定数据业务管理

    公开(公告)号:US20080148342A1

    公开(公告)日:2008-06-19

    申请号:US11609943

    申请日:2006-12-13

    IPC分类号: G06F15/173 H04L9/00

    CPC分类号: H04L12/462 H04L12/4641

    摘要: A system and/or method that enables hosting entities, such as application service providers (ASPs) to identify target sources (e.g. domains) for data traffic is provided. Additionally, data traffic can be segmented as a function of available sources and subsequently directed to specific hosting environments thereby affording the ASP ability to efficiently scale resources. Further, the segmented data traffic and corresponding environments enable the ASP to more effectively secure client resources and data by applying back-end filters and other suitable security mechanisms that correspond with a traffic-specific security policy that can be tagged to the traffic for use throughout distribution.

    摘要翻译: 提供了使诸如应用服务提供商(ASP)等托管实体识别用于数据业务的目标源(例如域)的系统和/或方法。 另外,数据流量可以作为可用源的函数进行分段,并且随后指向特定的托管环境,从而提供ASP有效地扩展资源的能力。 此外,分段数据流量和相应的环境使得ASP能够通过应用后端过滤器和其他适合的安全机制来更有效地保护客户端资源和数据,这些安全机制与特定于流量的安全策略相对应,该安全策略可被标记到流量上以供整个使用 分配。

    Decoupling access control from key management in a network
    27.
    发明授权
    Decoupling access control from key management in a network 有权
    将访问控制从网络中的密钥管理中解耦

    公开(公告)号:US07336790B1

    公开(公告)日:2008-02-26

    申请号:US09458020

    申请日:1999-12-10

    IPC分类号: H04L9/32

    CPC分类号: H04L63/0272

    摘要: Methods and systems consistent with the present invention provide a Supernet, a private network constructed out of components from a public-network infrastructure. Supernet nodes can be located on virtually any device in the public network (e.g., the Internet), and both their communication and utilization of resources occur in a secure manner. As a result, the users of a Supernet benefit from their network infrastructure being maintained for them as part of the public-network infrastructure, while the level of security they receive is similar to that of a private network. The Supernet has an access control component and a key management component which are decoupled. The access control component implements an access control policy that determines which users are authorized to use the network, and the key management component implements the network's key management policies, which indicate when keys are generated and what encryption algorithm is used. Both access control and key management are separately configurable. Thus, the Supernet provides great flexibility by allowing different key management policies to be used with the same access control component.

    摘要翻译: 与本发明一致的方法和系统提供了一种Supernet,一种由公共网络基础设施的组件构成的私有网络。 超网络节点可以位于公共网络(例如,因特网)中的几乎任何设备上,并且资源的通信和利用都以安全的方式发生。 因此,Supernet的用户受益于其网络基础架构,作为公共网络基础架构的一部分,而其接收的安全级别与私有网络的安全级别相似。 Supernet具有访问控制组件和分离的密钥管理组件。 访问控制组件实现访问控制策略,其确定哪些用户被授权使用网络,并且密钥管理组件实现网络的密钥管理策略,其指示生成密钥以及使用什么加密算法。 访问控制和密钥管理都可以单独配置。 因此,通过允许不同的密钥管理策略与相同的访问控制组件一起使用,Supernet提供了极大的灵活性。

    Mold apparatus
    28.
    发明授权
    Mold apparatus 有权
    模具设备

    公开(公告)号:US06494704B1

    公开(公告)日:2002-12-17

    申请号:US09539549

    申请日:2000-03-31

    IPC分类号: B29C4334

    摘要: Mold press apparatus for use in the manufacture of molded articles, particularly starch-bound containers and other articles. The mold press apparatus includes a planar array of female mold halves and a corresponding planar array of male mold halves. The planar array of mold halves remain substantially coplanar throughout the process of selectively mating and separating the male and female mold halves. When used to manufacture molded articles from aqueous starch-based compositions, the molds are equipped with venting means, such as vent holes and/or a vent gap, which allow for the escape of water vapor from the mold cavities defined by the mated male/female mold pairs. A suction removal system may be used to remove the molded articles from the mold press apparatus, typically from the female mold halves. The demolded articles are deposited on a conveyor system equipped with individual nests for each article.

    摘要翻译: 用于制造模制品,特别是淀粉结合容器和其它制品的模压机。 模压设备包括阴半模的平面阵列和相应的阳半模的平面阵列。 半模的平面阵列在选择性地配合和分离阳模半模和阴半模的整个过程中保持基本共面。 当用于由水性淀粉基组合物制造模塑制品时,模具配备有通气装置,例如通气孔和/或排气间隙,其允许水蒸汽从由配合的阳/ 女模对。 可以使用抽吸移除系统来从模压机装置(通常从阴模半部分)去除模制品。 脱模的物品被放置在配备有每个物品的单独巢的输送系统上。

    Biomass to biochar conversion in subcritical water
    30.
    发明授权
    Biomass to biochar conversion in subcritical water 有权
    生物质在亚临界水中生物炭转化

    公开(公告)号:US08637718B2

    公开(公告)日:2014-01-28

    申请号:US12875549

    申请日:2010-09-03

    IPC分类号: C07C1/00

    摘要: A method and system of converting biomass to biochar in a hydrothermal carbonization apparatus wherein subcritical water at a temperature of 230-350° C. and 500-3000 psi is reacted with the biomass to form biochar, biocrude and gases. The method and system include recycling the biocrude back to the hydrothermal carbonization apparatus which improves biochar yield and provides water for the biomass reaction to occur.

    摘要翻译: 在水热碳化装置中将生物量转化为生物炭的方法和系统,其中在230-350℃和500-3000psi温度下的亚临界水与生物质反应以形成生物炭,生物重油和气体。 该方法和系统包括将生物原料循环回水热碳化装置,其提高生物炭产率并提供生物反应发生的水。