Walled garden providing access to one or more websites that incorporate content from other websites
    42.
    发明授权
    Walled garden providing access to one or more websites that incorporate content from other websites 有权
    围墙花园可以访问包含其他网站内容的一个或多个网站

    公开(公告)号:US09363236B2

    公开(公告)日:2016-06-07

    申请号:US13868675

    申请日:2013-04-23

    发明人: David T. Ong

    摘要: A cleared sites list includes one or more hostname descriptors. A firewall includes rules associated with a cleared IP list including cleared IP addresses, and permits transfer of a cleared HTTP request from a user device to a cleared destination IP address that matches one of the cleared IP addresses. A controller examines a non-cleared HTTP request from the user device to a non-cleared destination IP address that does not match one of the cleared IP addresses, and acts as a transparent proxy between the user device and the non-cleared destination IP address when a destination host header of the non-cleared HTTP request matches a hostname descriptor of the cleared sites list. The controller further acts as a transparent proxy between the user device and the non-cleared destination IP address when a referrer header of the non-cleared HTTP request matches a hostname descriptor of the cleared sites list.

    摘要翻译: 已清除的网站列表包含一个或多个主机名描述符。 防火墙包括与清除的IP列表相关联的规则,包括已清除的IP地址,并允许将清除的HTTP请求从用户设备传输到与清除的IP地址匹配的已清除目标IP地址。 控制器将用户设备的未清除的HTTP请求检查到与清除的IP地址不匹配的未清除的目标IP地址,并在用户设备和未清除的目标IP地址之间充当透明代理 当未清除的HTTP请求的目标主机头匹配清除的站点列表的主机名描述符时。 当未清除的HTTP请求的引用标头与已清除的站点列表的主机名描述符相匹配时,控制器还充当用户设备和未清除的目标IP地址之间的透明代理。

    BANDWIDTH ZONES IN SYSTEM HAVING NETWORK INTERFACE COUPLED TO NETWORK WITH WHICH A FIXED TOTAL AMOUNT OF BANDWIDTH PER UNIT TIME CAN BE TRANSFERRED
    43.
    发明申请
    BANDWIDTH ZONES IN SYSTEM HAVING NETWORK INTERFACE COUPLED TO NETWORK WITH WHICH A FIXED TOTAL AMOUNT OF BANDWIDTH PER UNIT TIME CAN BE TRANSFERRED 有权
    网络接口网络中的带宽区域,每个单位时间内固定的带宽总数可以被转移到网络

    公开(公告)号:US20160021027A1

    公开(公告)日:2016-01-21

    申请号:US14867237

    申请日:2015-09-28

    发明人: David T. Ong

    摘要: A bandwidth management system includes a plurality of queues respectively corresponding to a plurality of zones. An enqueuing module receives network traffic from one or more incoming network interfaces, determines a belonging zone to which the network traffic belongs, and enqueues the network traffic on a queue corresponding to the belonging zone. A dequeuing module selectively dequeues data from the queues and passes the data to one or more outgoing network interfaces. When dequeuing data from the queues the dequeuing module dequeues an amount of data from a selected queue, and the amount of data dequeued from the selected queue is determined according to user load of a zone to which the selected queue corresponds.

    摘要翻译: 带宽管理系统包括分别对应于多个区域的多个队列。 入队模块从一个或多个传入网络接口接收网络流量,确定网络流量所属的所属区域,并对与归属区域对应的队列进行排队。 出队模块选择性地将队列中的数据排队,并将数据传递到一个或多个输出网络接口。 当队列中的数据出队时,出队模块从所选择的队列中取出数据量,并且根据所选队列对应的区域的用户负载来确定从所选队列中出队的数据量。

    CAPTIVE PORTAL THAT MODIFIES CONTENT RETRIEVED FROM DESIGNATED WEB PAGE TO SPECIFY BASE DOMAIN FOR RELATIVE LINK AND SENDS TO CLIENT IN RESPONSE TO REQUEST FROM CLIENT FOR UNAUTHORIZED WEB PAGE
    45.
    发明申请
    CAPTIVE PORTAL THAT MODIFIES CONTENT RETRIEVED FROM DESIGNATED WEB PAGE TO SPECIFY BASE DOMAIN FOR RELATIVE LINK AND SENDS TO CLIENT IN RESPONSE TO REQUEST FROM CLIENT FOR UNAUTHORIZED WEB PAGE 有权
    修改从指定网页检索内容的权力门户,以指定相关领域的相关链接和客户端,以响应客户要求的未经授权的网页

    公开(公告)号:US20140090030A1

    公开(公告)日:2014-03-27

    申请号:US14093279

    申请日:2013-11-29

    发明人: David T. Ong

    IPC分类号: G06F21/60

    摘要: The described captive portal techniques cause client devices to render and display designated web pages. One designated web page may be different than a requested web page such as when a client is not authorized to access the requested page and is instead caused to display a login portal. The captive portal may modify the designated web page to ensure that relative links lacking base domains now have specified base domains pointing to an authorized web server. The modified content is sent from the captive portal to the client device for display. Client web browser security measures related to redirection messages are thereby bypassed and load on the captive portal is minimal. Another designated web page may be the same as the requested web page such as when the requested page is an authorized page even for non-logged in clients. Authorized pages may be modified to add a login link.

    摘要翻译: 所描述的俘获门户技术导致客户端设备呈现和显示指定的网页。 一个指定的网页可以不同于所请求的网页,例如当客户端没有被授权访问所请求的页面时,而是引起显示登录门户。 强制门户可以修改指定的网页,以确保缺少基础域的相关链接现在具有指向授权Web服务器的指定基础域。 修改后的内容从强制门户发送到客户端设备进行显示。 因此,与重定向消息相关的客户端Web浏览器安全措施因此被绕过,并且强制门户上的负载极小。 另一个指定的网页可能与所请求的网页相同,例如当所请求的页面是授权页面时,即使对于未登录的客户端也是如此。 可以修改授权页面以添加登录链接。

    Walled garden system with cleared IPS list automatically generated from DNS queries

    公开(公告)号:US11115384B2

    公开(公告)日:2021-09-07

    申请号:US15796382

    申请日:2017-10-27

    发明人: David T. Ong

    IPC分类号: H04L29/06 H04L29/12

    摘要: A walled garden system includes a firewall controlling access between a first network and a second network at least by allowing connection requests originating from a user device on the first network to a destination IP address on the second network in response to determining that the destination IP address matches a cleared IP address on a cleared IP addresses list. A controller receives a domain name service (DNS) reply from a DNS server on the second network, and determines whether a domain name specified within the DNS reply matches a cleared domain name on a cleared domain names list. In response to determining that the domain name specified within the DNS reply matches the cleared domain name on the cleared domain names list, the controller adds a resolved IP address specified in the DNS reply to the cleared IP addresses list as a new cleared IP address.

    ALLOCATING BANDWIDTH BETWEEN BANDWIDTH ZONES ACCORDING TO USER LOAD

    公开(公告)号:US20210006501A1

    公开(公告)日:2021-01-07

    申请号:US16933350

    申请日:2020-07-20

    发明人: David T. Ong

    摘要: A bandwidth management system includes a plurality of queues respectively corresponding to a plurality of zones. An enqueuing module receives network traffic from one or more incoming network interfaces, determines a belonging zone to which the network traffic belongs, and enqueues the network traffic on a queue corresponding to the belonging zone. A dequeuing module selectively dequeues data from the queues and passes the data to one or more outgoing network interfaces. When dequeuing data from the queues the dequeuing module dequeues an amount of data from a selected queue, and the amount of data dequeued from the selected queue is determined according to user load of a zone to which the selected queue corresponds.

    Allocating bandwidth between bandwidth zones according to user load

    公开(公告)号:US10721176B2

    公开(公告)日:2020-07-21

    申请号:US15835091

    申请日:2017-12-07

    发明人: David T. Ong

    摘要: A bandwidth management system includes a plurality of queues respectively corresponding to a plurality of zones. An enqueuing module receives network traffic from one or more incoming network interfaces, determines a belonging zone to which the network traffic belongs, and enqueues the network traffic on a queue corresponding to the belonging zone. A dequeuing module selectively dequeues data from the queues and passes the data to one or more outgoing network interfaces. When dequeuing data from the queues the dequeuing module dequeues an amount of data from a selected queue, and the amount of data dequeued from the selected queue is determined according to user load of a zone to which the selected queue corresponds.