RECOMMENDER SYSTEM
    61.
    发明申请
    RECOMMENDER SYSTEM 审中-公开
    推荐系统

    公开(公告)号:US20130211950A1

    公开(公告)日:2013-08-15

    申请号:US13369318

    申请日:2012-02-09

    IPC分类号: G06Q30/00

    CPC分类号: G06Q30/0631

    摘要: Embodiments of the invention provide methods and apparatus for recommending items from a catalog of items to a user by parsing the catalog of items into a plurality of catalog clusters of related items and recommending catalog items to the user from catalog clusters to which items previously preferred by the user belong.

    摘要翻译: 本发明的实施例提供了通过将项目目录解析为相关项目的多个目录集合并将目录项目从目录集合向目标群组推荐给先前优先选择的项目的方法和装置, 用户属于

    Information protection applied by an intermediary device
    62.
    发明授权
    Information protection applied by an intermediary device 有权
    中介设备应用的信息保护

    公开(公告)号:US08341720B2

    公开(公告)日:2012-12-25

    申请号:US12350974

    申请日:2009-01-09

    IPC分类号: G06F21/00

    CPC分类号: H04L63/0227 H04L63/102

    摘要: Methods, systems, and computer-readable media are disclosed for applying information protection. A particular method includes receiving a data file at a gateway coupled to a network. The data file is to be sent to a destination device that is external to the network. The method also includes selectively applying information protection to the data file at the gateway prior to sending the data file to the destination device. The information protection is selectively applied based on information associated with the destination device, information associated with the data file, and information associated with a user of the destination device.

    摘要翻译: 公开了用于应用信息保护的方法,系统和计算机可读介质。 一种特定的方法包括在耦合到网络的网关处接收数据文件。 数据文件将发送到网络外部的目标设备。 该方法还包括在将数据文件发送到目的地设备之前,有选择地将信息保护应用于网关上的数据文件。 基于与目的地设备相关联的信息,与数据文件相关联的信息以及与目的地设备的用户相关联的信息来选择性地应用信息保护。

    Array-based routing of data packets
    64.
    发明授权
    Array-based routing of data packets 有权
    数据包的基于阵列的路由

    公开(公告)号:US07957399B2

    公开(公告)日:2011-06-07

    申请号:US12339109

    申请日:2008-12-19

    IPC分类号: H04L12/28 G06F15/16

    摘要: A method of load balancing data packets at an array is disclosed. The method includes receiving a data packet encoded in a first format at an input of the array. The received data packet is assigned to an assigned element of the array, and the data packet is routed to a device. A message encoded in a second format is received from the device at the array. Information is extracted from a payload portion of the message, and the message is assigned to the assigned element of the array based on the information extracted from the payload portion of the message.

    摘要翻译: 公开了一种在阵列上负载平衡数据分组的方法。 该方法包括在阵列的输入处接收以第一格式编码的数据分组。 接收的数据分组被分配给阵列的分配的元素,数据分组被路由到设备。 从阵列中的设备接收以第二格式编码的消息。 从消息的有效载荷部分提取信息,并且基于从消息的有效载荷部分提取的信息将消息分配给阵列的分配的元素。

    USING SERVER TYPE TO OBTAIN NETWORK ADDRESS
    65.
    发明申请
    USING SERVER TYPE TO OBTAIN NETWORK ADDRESS 有权
    使用服务器类型来获取网络地址

    公开(公告)号:US20100217890A1

    公开(公告)日:2010-08-26

    申请号:US12389409

    申请日:2009-02-20

    IPC分类号: G06F15/16

    摘要: Aspects of the subject matter described herein relate to using server type to obtain a network address. In aspects, a gateway that sits between a single network protocol client and a server receives a request from the client for a network address of the server. The gateway issues multiple name resolution requests and waits for a first response. Depending on various factors, the gateway determines whether or not to wait for additional responses before responding to the client. If needed, the gateway may obtain an address of a translating device to assist the client in communicating with the server.

    摘要翻译: 本文描述的主题的方面涉及使用服务器类型来获得网络地址。 在方面,位于单个网络协议客户端和服务器之间的网关从客户端接收服务器的网络地址的请求。 网关发出多个名称解析请求并等待第一个响应。 根据各种因素,网关将在响应客户端之前确定是否等待其他响应。 如果需要,网关可以获得翻译设备的地址,以帮助客户端与服务器进行通信。

    REMOTE ACCESS TO PRIVATE NETWORK RESOURCES FROM OUTSIDE THE NETWORK
    66.
    发明申请
    REMOTE ACCESS TO PRIVATE NETWORK RESOURCES FROM OUTSIDE THE NETWORK 有权
    远程访问从网络外部私有网络资源

    公开(公告)号:US20100186079A1

    公开(公告)日:2010-07-22

    申请号:US12356152

    申请日:2009-01-20

    IPC分类号: G06F21/00 G06F15/16

    摘要: In some embodiments of the invention, techniques may make private identifiers for private network resources usable to establish connections to those private network resources from computing devices connected to an outside network. For example, when a computing device is connected to an outside network and attempting to contact a private network resource, DNS may be used to resolve a domain name for the private network resource to an IP address for an edge resource of the private network. Communications may be passed between the computing device and the edge resource according to protocols which embed the identifier originally used to identify the private network resource. The edge resource of the private network may analyze communications over the connection to determine this identifier, and use it to pass the communication to the desired private network resource.

    摘要翻译: 在本发明的一些实施例中,技术可以使私有网络资源的专用标识符可用于从连接到外部网络的计算设备建立到那些专用网络资源的连接。 例如,当计算设备连接到外部网络并尝试联系专用网络资源时,可以使用DNS将专用网络资源的域名解析为专用网络的边缘资源的IP地址。 根据最初用于标识专用网络资源的标识符的协议,可以在计算设备和边缘资源之间传递通信。 私有网络的边缘资源可以分析通过连接的通信以确定该标识符,并且使用它来将通信传递到期望的专用网络资源。

    LOAD BALANCING
    67.
    发明申请
    LOAD BALANCING 有权
    负载均衡

    公开(公告)号:US20100157799A1

    公开(公告)日:2010-06-24

    申请号:US12339109

    申请日:2008-12-19

    IPC分类号: H04L12/56

    摘要: A method of load balancing data packets at an array is disclosed. The method includes receiving a data packet encoded in a first format at an input of the array. The received data packet is assigned to an assigned element of the array, and the data packet is routed to a device. A message encoded in a second format is received from the device at the array. Information is extracted from a payload portion of the message, and the message is assigned to the assigned element of the array based on the information extracted from the payload portion of the message.

    摘要翻译: 公开了一种在阵列上负载平衡数据分组的方法。 该方法包括在阵列的输入处接收以第一格式编码的数据分组。 接收的数据分组被分配给阵列的分配的元素,数据分组被路由到设备。 从阵列中的设备接收以第二格式编码的消息。 从消息的有效载荷部分提取信息,并且基于从消息的有效载荷部分提取的信息将消息分配给阵列的分配的元素。

    AUTHENTICATION IN A NETWORK USING CLIENT HEALTH ENFORCEMENT FRAMEWORK
    68.
    发明申请
    AUTHENTICATION IN A NETWORK USING CLIENT HEALTH ENFORCEMENT FRAMEWORK 有权
    使用客户端健康执行框架的网络认证

    公开(公告)号:US20100115578A1

    公开(公告)日:2010-05-06

    申请号:US12338268

    申请日:2008-12-18

    IPC分类号: G06F21/20 H04L9/32 G06F17/00

    摘要: A network with authentication implemented using a client health enforcement framework. The framework is adapted to receive plug-ins on clients that generate health information. Corresponding plug-ins on a server validate that health information. Based on the results of validation, the server may instruct the client to remediate or may authorize an underlying access enforcement mechanism to allow access. A client plug-in that generates authentication information formatted as a statement of health may be incorporated into such a framework. Similarly, on the server, a validator to determine, based on the authentication information, whether the client should be granted network access can be incorporated into the framework. Authentication can be simply applied or modified by changing the plug-ins, while relying on the framework to interface with an enforcement mechanism. Functions of the health enforcement framework can be leveraged to provide authentication-based functionality, such as revoking authorized access after a period of user inactivity or in response to a user command.

    摘要翻译: 使用客户端健康执行框架实施认证的网络。 该框架适用于在生成健康信息的客户端上接收插件。 服务器上的相应插件验证该健康信息。 基于验证的结果,服务器可以指示客户端修复或者可以授权底层访问执行机制以允许访问。 生成格式为健康声明的认证信息的客户端插件可以并入到这样的框架中。 类似地,在服务器上,验证器根据认证信息来确定客户端是否被授予网络访问可以并入到框架中。 可以通过更改插件来简单地应用或修改身份验证,同时依靠框架与强制机制进行交互。 可以利用健康执行框架的功能来提供基于身份验证的功能,例如在用户不活动期间或响应于用户命令之后撤销授权访问。

    SEAMLESS LOCATION AWARE NETWORK CONNECTIVITY
    69.
    发明申请
    SEAMLESS LOCATION AWARE NETWORK CONNECTIVITY 审中-公开
    无缝位置识别网络连接

    公开(公告)号:US20090327497A1

    公开(公告)日:2009-12-31

    申请号:US12163046

    申请日:2008-06-27

    IPC分类号: G06F15/16

    CPC分类号: H04L47/70 H04W76/10

    摘要: Described is a technology by which a seamless automatic connection to an (e.g., corporate) network is made for a client device. Upon detecting a need for a connection to a network, such as by intercepting a communication directed towards a network destination, a list of available connection methods is automatically obtained based on the device's current location data (e.g., LAN or remote) and policy information. An available connection method from the list is selected, e.g., in order, and an attempt is made to establish a connection via that connection method. If the attempt fails, another attempt is made with a different connection method, and so on, until a connection method succeeds. Additional seamlessness from the user's perspective is provided via a credentials vault, by which stored credentials may be retrieved and used in association with the access method being attempted.

    摘要翻译: 描述了一种技术,通过该技术,为客户端设备进行到(例如,公司)网络的无缝自动连接。 当检测到需要连接到网络时,例如通过截取针对网络目的地的通信,可以基于设备的当前位置数据(例如,LAN或远程)和策略信息自动获得可用连接方法的列表。 从列表中选择可用的连接方法,例如按顺序,并且尝试通过该连接方法建立连接。 如果尝试失败,则尝试使用不同的连接方法,等等,直到连接方法成功。 通过凭证保险库来提供从用户的角度来看附加的无缝性,通过该证书保管库可以与尝试的访问方法相关联地检索和使用存储的凭证。

    Authentication delegation based on re-verification of cryptographic evidence
    70.
    发明申请
    Authentication delegation based on re-verification of cryptographic evidence 有权
    基于重新验证加密证据的认证授权

    公开(公告)号:US20080134311A1

    公开(公告)日:2008-06-05

    申请号:US11607720

    申请日:2006-12-01

    IPC分类号: H04L9/32 G06F21/00

    摘要: The method of delegating authentication, within a chain of entities, relies upon a recording of at least a portion of a TLS handshake between a gateway device and user, in which the user needs access to a desired server. The method then relies upon re-verification of cryptographic evidence in the recorded portion of the TLS handshake, which is forwarded either (1) to the server to which access is desired, in which case the server re-verifies the recorded portion to confirm authentication, or, (2) to a third party entity, in which case the third party entity confirms authentication and provides credentials to the gateway server which then uses the credentials to authenticate to the server as the user.

    摘要翻译: 在实体链中委托认证的方法依赖于在网关设备和用户之间的至少一部分TLS握手的记录,其中用户需要访问期望的服务器。 然后,该方法依赖于在TLS握手的记录部分中重新验证加密证据,TLS握手被转发到(1)到需要访问的服务器,在这种情况下,服务器重新验证记录部分以确认认证 ,或者(2)到第三方实体,在这种情况下,第三方实体确认认证,并向网关服务器提供凭证,然后网关服务器使用凭证作为用户对服务器进行认证。