System and method for securely providing a configuration file over and open network
    21.
    发明申请
    System and method for securely providing a configuration file over and open network 有权
    安全地提供配置文件和打开网络的系统和方法

    公开(公告)号:US20060174018A1

    公开(公告)日:2006-08-03

    申请号:US11049468

    申请日:2005-02-02

    IPC分类号: G06F15/16 G06F15/177

    摘要: A method for securely provisioning a device for operation within a service provider infrastructure over an open network comprises the device establishing physical and data link layer network connections for communication on at least a subnet of the open network and obtaining a network configuration data such as an IP address and a subnet mask from a provisioning server that responds to a network configuration broadcast request. A device establishes a secure hypertext transport protocol connection to a first provisioning server that corresponds to one of: i) and IP address and port number; and ii) a fully qualified domain name stored in a non-volatile memory of the device. After mutual authentication, the first provisioning server provides at least one of: i) a configuration file; and ii) identification of a second provisioning server and a cipher key through the secure connection. If the first provisioning server provided identification of a second provisioning server, the device establishes a transport connection to the identified second provisioning server. The second provisioning server provides an encrypted file which, when decrypted using the cipher key yields the configuration information needed by the device for operation with the service provider infrastructure.

    摘要翻译: 一种用于在开放网络上安全地配置服务提供商基础设施内的设备的方法包括建立用于在开放网络的至少子网上进行通信的物理和数据链路层网络连接的设备,并且获得网络配置数据,例如IP 地址和来自响应网络配置广播请求的配置服务器的子网掩码。 设备建立到第一配置服务器的安全超文本传输​​协议连接,其对应于以下之一:i)和IP地址和端口号; 和ii)存储在设备的非易失性存储器中的完全限定域名。 在相互认证之后,第一供应服务器提供以下至少一个:i)配置文件; 以及ii)通过安全连接识别第二供应服务器和密码密钥。 如果第一供应服务器提供了第二供应服务器的标识,则设备建立到所识别的第二供应服务器的传输连接。 第二配置服务器提供加密文件,当使用密钥解密时,加密文件产生设备所需的配置信息以便与服务提供商基础架构一起操作。

    System and method for determining a connectionless communication path for communicating audio data through an address and port translation device
    24.
    发明授权
    System and method for determining a connectionless communication path for communicating audio data through an address and port translation device 有权
    用于确定用于通过地址和端口转换装置传送音频数据的无连接通信路径的系统和方法

    公开(公告)号:US06928082B2

    公开(公告)日:2005-08-09

    申请号:US09819492

    申请日:2001-03-28

    摘要: A method of audio communication utilizing media datagrams between a first telephony client located behind a network address translation (NAT) server and a remote second telephony client is disclosed. Each client utilizes a single port number for both sending and receiving media datagrams. A media datagram is sent from the first telephony client to the second telephony client on a UDP/IP channel utilizing a destination IP address and port number provided by the second telephony client. The second telephony client extracts the source IP address and source port number from the received media datagram to determine if the first telephony client is located behind a NAT server. If the first telephony client is located behind a NAT server, the extracted source IP address and port number are stored and used to send media datagrams to the first telephony client located behind the NAT server.

    摘要翻译: 公开了一种在位于网络地址转换(NAT)服务器和远程第二电话客户端之后的第一电话客户端之间利用媒体数据报的音频通信的方法。 每个客户端都使用单个端口号来发送和接收媒体数据报。 使用由第二电话客户端提供的目的地IP地址和端口号,在UDP / IP信道上将媒体数据报从第一电话客户端发送到第二电话客户端。 第二电话客户端从接收到的媒体数据报中提取源IP地址和源端口号,以确定第一电话客户端是否位于NAT服务器后面。 如果第一电话客户端位于NAT服务器后面,则提取的源IP地址和端口号被存储并用于向位于NAT服务器后面的第一电话客户端发送媒体数据报。

    Network address and port translation gateway with real-time media channel management
    25.
    发明申请
    Network address and port translation gateway with real-time media channel management 审中-公开
    具有实时媒体频道管理的网络地址和端口转换网关

    公开(公告)号:US20050117605A1

    公开(公告)日:2005-06-02

    申请号:US10724312

    申请日:2003-11-28

    IPC分类号: H04L29/06 H04L29/12 H04J3/22

    摘要: A gateway comprises a router module coupled between a local area network interface and a wide area network interface. The router module receives an outbound IP frame from the local area network interface and provides a corresponding translated outbound IP frame to the wide area network interface. The router module comprises a transport layer translation module for performing network address and port translation on an IP header of the outbound IP frame. The router module further comprises an application layer translation module for detecting the presence of media session signaling information within payload of the outbound IP frame and performing network address translation and port translation of source network address information identified in the media session signaling information. Both the network address and port translation of the IP header and the network address and port translation of the source network address information are recorded in a translation table such that inbound frames may be reverse translated.

    摘要翻译: 网关包括耦合在局域网接口和广域网接口之间的路由器模块。 路由器模块从局域网接口接收出站IP帧,并向广域网接口提供相应的转出出站IP帧。 路由器模块包括传输层转换模块,用于在出站IP帧的IP报头上执行网络地址和端口转换。 路由器模块还包括应用层转换模块,用于检测在出站IP帧的有效载荷内的媒体会话信令信息的存在,并执行在媒体会话信令信息中标识的源网络地址信息的网络地址转换和端口转换。 IP报头的网络地址和端口转换以及源网络地址信息的网络地址和端口转换记录在转换表中,使得入站帧可以被反向翻译。

    Firewall penetration system and method for real time media communications
    26.
    发明申请
    Firewall penetration system and method for real time media communications 有权
    防火墙渗透系统和实时媒体通信方法

    公开(公告)号:US20050033985A1

    公开(公告)日:2005-02-10

    申请号:US10627594

    申请日:2003-07-26

    IPC分类号: H04L9/00 H04L29/06

    CPC分类号: H04L63/0236 H04L63/029

    摘要: A system for initiating and maintaining a real time audio or video media session between two clients, at least one of which has a private network IP address and is supported by a NAT firewall, comprises a proxy server serving each client and a relay server. The first proxy server may receive an invite message from a caller client to initiate a media session with a callee client. The invite message will identify the IP address and media port number of the caller client. The proxy server queries the relay server to obtain a port number of the relay server that may be used for relaying the media session between the caller client and the callee client. The proxy server will replace the IP address and port number of the caller client with the IP address and port number of the relay server in the invite message before forwarding to the callee client. When the callee client generates a response message that includes the IP address and media port number of the callee client, the proxy server will replace the IP address and media port number of the callee client in the response message before forwarding the response message to the caller client.

    摘要翻译: 一种用于在两个客户端之间启动和维护实时音频或视频媒体会话的系统,其中至少一个具有专用网络IP地址并由NAT防火墙支持,该系统包括为每个客户端和中继服务器提供服务的代理服务器。 第一代理服务器可以从呼叫者客户端接收邀请消息以发起与被叫方客户端的媒体会话。 邀请消息将标识呼叫者客户端的IP地址和媒体端口号。 代理服务器查询中继服务器以获取中继服务器的端口号,该端口号可用于在呼叫者客户端和被叫客户端之间中继媒体会话。 代理服务器将在转发给被叫方客户端之前,将邀请消息中的中继服务器的IP地址和端口号替换为主叫方客户端的IP地址和端口号。 当被叫客户端生成包含被叫方客户端的IP地址和媒体端口号的响应消息时,代理服务器将在响应消息中替换被叫方客户端的IP地址和媒体端口号,然后将响应消息转发给呼叫方 客户。

    Network access module for supporting a stand alone multi-media terminal adapter
    27.
    发明申请
    Network access module for supporting a stand alone multi-media terminal adapter 有权
    网络访问模块,用于支持独立的多媒体终端适配器

    公开(公告)号:US20040160963A1

    公开(公告)日:2004-08-19

    申请号:US10403469

    申请日:2003-03-31

    IPC分类号: H04L012/28

    摘要: A network access module interconnects a stand alone multi-media terminal adapter with a network controller of a frame switched network. The network access module comprises a frame switched network interface coupled to the frame switched network for communicating with the network controller. The network access module further comprises a communication link interface for communicating with the stand alone-multi media terminal adapter. A service flow module is coupled to the frame switched network interface and coupled to the communication link interface. The service flow module receives a plurality of frames of IP traffic from the multi-media terminal adapter and sorts the frames such that each frame is delivered to the frame switched network interface at a time that corresponds to a time division logical channel which corresponds to the frame. A QoS module is coupled to the service flow module and coupled to communication link interface. The QoS module generates a quality of service request for transmission to the network controller in response to receipt of a bandwidth management instruction from the multi-media terminal adapter.

    摘要翻译: 网络访问模块将独立的多媒体终端适配器与帧交换网络的网络控制器互连。 网络接入模块包括耦合到帧交换网络以与网络控制器进行通信的帧交换网络接口。 网络访问模块还包括用于与独立多媒体终端适配器通信的通信链路接口。 服务流模块耦合到帧交换网络接口并耦合到通信链路接口。 服务流模块从多媒体终端适配器接收多个IP流量帧,并对这些帧进行排序,使得每个帧在对应于对应于时间分配逻辑信道的时分逻辑信道的时间被传送到帧交换网络接口 帧。 QoS模块耦合到业务流模块并耦合到通信链路接口。 响应于从多媒体终端适配器接收到带宽管理指令,QoS模块产生用于传输到网络控制器的服务质量请求。

    Network communication system with a stand alone multi-media terminal adapter
    28.
    发明申请
    Network communication system with a stand alone multi-media terminal adapter 审中-公开
    网络通信系统具有独立的多媒体终端适配器

    公开(公告)号:US20040160945A1

    公开(公告)日:2004-08-19

    申请号:US10365876

    申请日:2003-02-13

    IPC分类号: H04L012/28

    摘要: A stand-alone multi-media terminal adapter controls a dynamic quality of service management system of a broad band network access module. The multi-media terminal adapter provides the dynamic quality of service management system with instructions to reserve, commit, and release time division logical channels on a broad band network as well as discrimination identification to be used by the network access module for identifying IP traffic that corresponds to a time division logical channel. The multi-media terminal adapter receives acknowledgement of a time division logical channel that comprises identification of a frame frequency and a frame size. The multi-media terminal adapter encapsulates compressed digital audio data representing a VoIP session into IP frames with a frame size, frame frequency, and discrimination identification that corresponds to the time division logical channel.

    摘要翻译: 独立的多媒体终端适配器控制宽带网络接入模块的动态服务质量管理系统。 多媒体终端适配器提供动态服务质量管理系统,其具有在宽带网络上保留,提交和释放时分逻辑信道的指令以及由网络接入模块用于识别IP流量的辨别识别 对应于时分逻辑信道。 多媒体终端适配器接收包括帧频和帧大小的识别的时分逻辑信道的确认。 多媒体终端适配器将表示VoIP会话的压缩数字音频数据封装成具有对应于时分逻辑信道的帧大小,帧频和鉴别识别的IP帧。

    Efficient method for multiplication over galois fields
    29.
    发明申请
    Efficient method for multiplication over galois fields 有权
    有效的方法在伽罗瓦地区乘法

    公开(公告)号:US20030128841A1

    公开(公告)日:2003-07-10

    申请号:US10005291

    申请日:2001-12-04

    发明人: Jing Zheng Ouyang

    IPC分类号: H04L009/06

    CPC分类号: G06F7/724

    摘要: The improved AES processing method provides an efficient alternative to both Mips intensive multiplication and to conventional table lookup, used to multiply terms over a Galois field (GF). The improved method takes advantage of the fact that in the GF, any non zero element X can be represented by a power of a primitive element P. The improved method thereby results in a 2 by 256 table. The log base P of the terms being multiplied are looked up and summed, and the anti-log of the sum is looked up in the same table.

    摘要翻译: 改进的AES处理方法为Mips密集乘法和常规表查找提供了有效的替代方法,用于在伽罗瓦域(GF)上乘法。 改进的方法利用了以下事实:在GF中,任何非零元素X可以由原始元素P的幂表示。因此,改进的方法导致2×256的表。 查询和求和所乘的项目的日志基数P,并且在同一表中查找和的反对数。