Federation among services for supporting virtual-network overlays
    53.
    发明授权
    Federation among services for supporting virtual-network overlays 有权
    支持虚拟网络覆盖的服务之间的联合

    公开(公告)号:US08688994B2

    公开(公告)日:2014-04-01

    申请号:US12823891

    申请日:2010-06-25

    摘要: Computerized methods, systems, and computer-readable media for promoting cooperation between a first and second virtual network overlay (“overlay”) are provided. The first overlay is governed by a first authority domain and includes members assigned virtual IP addresses from a first address range. The second overlay is governed by a second authority domain, which is associated with a second federation mechanism, for negotiating on behalf of the second overlay. The second federation mechanism is capable of negotiating with, or soliciting delegation of authority from, a first federation mechanism that is associated with the first authority domain. When negotiations are successful or authority is delegated, the second federation mechanism establishes a communication link between the second overlay and the first overlay or joins a member of the second overlay to the first overlay. Joining involves allocating a guest IP address from the first address range to the member.

    摘要翻译: 提供了用于促进第一和第二虚拟网络覆盖(“覆盖”)之间的协作的计算机化方法,系统和计算机可读介质。 第一个覆盖由第一个授权域管理,并包括从第一个地址范围分配虚拟IP地址的成员。 第二重叠由第二权限域管理,第二权限域与第二联合机制相关联,用于代表第二重叠进行协商。 第二个联邦机制能够与第一个与第一个权威机构相关联的第一个联合机制进行谈判或者征集授权。 当谈判成功或授权被授权时,第二联合机制在第二重叠和第一覆盖之间建立通信链接,或者将第二覆盖的成员连接到第一重叠。 加入涉及将访客IP地址从第一个地址范围分配给该成员。

    NETWORK TOPOLOGY DETECTION USING A SERVER
    54.
    发明申请
    NETWORK TOPOLOGY DETECTION USING A SERVER 审中-公开
    网络拓扑检测使用服务器

    公开(公告)号:US20120047253A1

    公开(公告)日:2012-02-23

    申请号:US13285694

    申请日:2011-10-31

    IPC分类号: G06F15/173

    CPC分类号: H04L12/4625

    摘要: Various technologies and techniques are disclosed for automatically detecting whether a local network that a computer is connected to is a public or private network by utilizing a trusted online service and/or heuristics. Techniques are also described for detecting whether or not two computers are connected to the same local area network.

    摘要翻译: 公开了各种技术和技术,用于通过利用可靠的在线服务和/或启发式自动检测计算机连接的本地网络是公共或专用网络。 还描述了用于检测两台计算机是否连接到同一局域网的技术。

    Persistent and reliable session securely traversing network components using an encapsulating protocol
    55.
    发明授权
    Persistent and reliable session securely traversing network components using an encapsulating protocol 有权
    持久可靠的会话使用封装协议安全地遍历网络组件

    公开(公告)号:US07984157B2

    公开(公告)日:2011-07-19

    申请号:US10711719

    申请日:2004-09-30

    IPC分类号: G06F15/16

    摘要: The invention relates to systems and methods for reestablishing client communications by securely traversing network components using an encapsulating communication protocol to provide session persistence and reliability. A first protocol that encapsulates a plurality of secondary protocols is used to communicate over a network to provide session persistence and a reliable connection between a client and a host service via a first protocol service. A ticket authority generates a first ticket and a second ticket associated with the client. The first ticket is provided to the client and the client uses the first ticket to establish a communication session with the first protocol service. The second ticket is provided to the first protocol service and the first protocol service uses the second ticket to establish a communication session with the host service.

    摘要翻译: 本发明涉及通过使用封装通信协议安全地遍历网络组件来重新建立客户端通信以提供会话持续性和可靠性的系统和方法。 封装多个辅助协议的第一协议用于通过网络进行通信,以经由第一协议服务来提供会话持久性和客户端与主机服务之间的可靠连接。 售票机关生成与客户端相关联的第一张票和第二张票。 第一张票被提供给客户端,客户端使用第一张票与第一个协议服务建立通信会话。 向第一协议服务提供第二票,第一协议服务使用第二票与主服务建立通信会话。

    IP SECURITY CERTIFICATE EXCHANGE BASED ON CERTIFICATE ATTRIBUTES
    56.
    发明申请
    IP SECURITY CERTIFICATE EXCHANGE BASED ON CERTIFICATE ATTRIBUTES 有权
    基于证书属性的知识产权安全证书交换

    公开(公告)号:US20110113481A1

    公开(公告)日:2011-05-12

    申请号:US12616789

    申请日:2009-11-12

    IPC分类号: G06F21/20

    摘要: Architecture that provides Internet Protocol security (IPsec) certificate exchange based on certificate attributes. An IPsec endpoint can validate the security context of another IPsec endpoint certificate by referencing certificate attributes. By facilitating IPsec certificate exchange using certificate attributes rather than solely certificate roots, it is now possible to build multiple isolated network zones using a single certificate authority rather than requiring one certificate authority per zone. Moreover, the ability to use certificate attributes during the IPsec certificate exchange can be leveraged for more focused communications such as QoS (quality of service). Certificate attributes can be utilized to identify the security context of the endpoint. The IPsec certificate use can be locked down to a single IP or group of IPs.

    摘要翻译: 基于证书属性提供Internet协议安全(IPsec)证书交换的体系结构。 IPsec端点可以通过引用证书属性来验证另一个IPsec端点证书的安全上下文。 通过使用证书属性而不仅仅是证书根源来促进IPsec证书交换,现在可以使用单个证书颁发机构构建多个隔离网络区域,而不是每个区域需要一个证书颁发机构。 此外,在IPsec证书交换期间使用证书属性的能力可以用于更集中的通信,如QoS(服务质量)。 可以使用证书属性来识别端点的安全上下文。 IPsec证书使用可以锁定到单个IP或一组IP。

    Interacting with software applications displayed in a web page
    60.
    发明授权
    Interacting with software applications displayed in a web page 有权
    与网页中显示的软件应用程序进行交互

    公开(公告)号:US06950991B2

    公开(公告)日:2005-09-27

    申请号:US10068461

    申请日:2002-02-06

    摘要: The invention enables the display of application-output data within application-output windows embedded in a web browser window. The application-output windows can be dynamically moved, resized and otherwise manipulated within the web browser window even when the application program providing the source of the application-output data is non-web enabled (e.g., legacy applications). The invention receives window attribute information associated with the application-output windows via a first virtual channel and displays application-output data received via a second virtual channel within the application-output windows, which are formed and/or modified using the window attribute information.

    摘要翻译: 本发明能够在嵌入在web浏览器窗口中的应用输出窗口内显示应用输出数据。 即使提供应用程序输出数据的源的应用程序是非Web启用的(例如传统应用程序),应用程序输出窗口也可以在Web浏览器窗口中动态移动,调整大小并以其他方式处理。 本发明经由第一虚拟信道接收与应用输出窗口相关联的窗口属性信息,并且显示通过使用窗口属性信息形成和/或修改的应用输出窗口内经由第二虚拟频道接收的应用输出数据。