Methods And Apparatus Supporting Access To Physical And Virtual Trusted Platform Modules
    63.
    发明申请
    Methods And Apparatus Supporting Access To Physical And Virtual Trusted Platform Modules 有权
    支持访问物理和虚拟可信平台模块的方法和设备

    公开(公告)号:US20090165117A1

    公开(公告)日:2009-06-25

    申请号:US11963336

    申请日:2007-12-21

    IPC分类号: G06F9/00

    摘要: A data processing system features a hardware trusted platform module (TPM), and a virtual TPM (vTPM) manager. When executed, the vTPM manager detects a first request from a service virtual machine (VM) in the processing system, the first request to involve access to the hardware TPM (hTPM). In response, the vTPM manager automatically determines whether the first request should be allowed, based on filter rules identifying allowed or disallowed operations for the hTPM. The vTPM manager may also detect a second request to involve access to a software TPM (sTPM) in the processing system. In response, the vTPM manager may automatically determine whether the second request should be allowed, based on a second filter list identifying allowed or disallowed operations for the sTPM. Other embodiments are described and claimed.

    摘要翻译: 数据处理系统具有硬件可信平台模块(TPM)和虚拟TPM(vTPM)管理器。 当执行时,vTPM管理器检测来自处理系统中的服务虚拟机(VM)的第一请求,第一请求涉及访问硬件TPM(hTPM)。 作为响应,基于识别hTPM的允许或不允许操作的过滤器规则,vTPM管理器自动确定是否应允许第一个请求。 vTPM管理器还可以检测第二请求以涉及访问处理系统中的软件TPM(sTPM)。 作为响应,基于识别sTPM的允许或不允许的操作的第二过滤器列表,vTPM管理器可以自动确定是否应允许第二请求。 描述和要求保护其他实施例。

    Method and apparatus for packet classification using a forest of hash tables data structure
    66.
    发明授权
    Method and apparatus for packet classification using a forest of hash tables data structure 有权
    使用散列表数据结构森林进行数据包分类的方法和装置

    公开(公告)号:US07394809B2

    公开(公告)日:2008-07-01

    申请号:US10404202

    申请日:2003-03-31

    IPC分类号: H04L12/28

    摘要: A packet classifier having a forest of hash tables data structure. The forest of hash tables data structure includes a number of hash tables, each hash table having a bit mask corresponding to an equivalent set of rules. Each hash table includes a number of entries, wherein an entry of a hash table may correspond to a rule. One or more of the hash tables may include a marker in one entry, wherein the marker identifies another one of the hash tables. The hash table identified by the marker is a descendant of the hash table in which the marker is placed.

    摘要翻译: 具有散列表数据结构森林的分组分类器。 散列表数据结构森林包括多个哈希表,每个散列表具有对应于等效的规则集的位掩码。 每个散列表包括多个条目,其中散列表的条目可以对应于规则。 一个或多个散列表可以包括一个条目中的标记,其中标记标识另一个散列表。 由标记识别的散列表是放置标记的哈希表的后代。

    System and method for coupling users to a retail computer system with low risk of eavesdropping
    67.
    发明授权
    System and method for coupling users to a retail computer system with low risk of eavesdropping 有权
    将用户连接到低偷听风险的零售计算机系统的系统和方法

    公开(公告)号:US07352996B2

    公开(公告)日:2008-04-01

    申请号:US10112318

    申请日:2002-03-29

    申请人: Alok Kumar

    发明人: Alok Kumar

    IPC分类号: H04B5/00

    摘要: A system reduces the risk of eavesdropping on data used to access an establishment's computer network. In one embodiment, a system includes a personal area network (PAN) access device that couples a low power, low frequency modulated signal to a wearer, the PAN access device including a data storage unit for storing personal identification data including biometric data and a modulator for modulating a low power, low frequency signal with the personal identification data, a personal area network (PAN) receiver for receiving the modulated signal, a database for storing purchasing data for a plurality of customers, a memory including instructions which, when executed, associate the received personal identification data with the stored shopping data for one of the plurality of customers and a microprocessor for executing the stored instructions.

    摘要翻译: 系统降低了窃听用于访问企业的计算机网络的数据的风​​险。 在一个实施例中,系统包括将低功率,低频调制信号耦合到佩戴者的个人区域网络(PAN)接入设备,所述PAN接入设备包括用于存储包括生物测定数据的个人识别数据的数据存储单元和调制器 用于通过个人识别数据调制低功率,低频信号,用于接收调制信号的个人局域网(PAN)接收机,用于存储多个客户的购买数据的数据库,包括指令的存储器,当被执行时, 将接收到的个人识别数据与用于多个客户中的一个的所存储的购物数据相关联,以及用于执行所存储的指令的微处理器。

    Method and apparatus to implement a very efficient random early detection algorithm in the forwarding path
    68.
    发明申请
    Method and apparatus to implement a very efficient random early detection algorithm in the forwarding path 审中-公开
    在转发路径中实现非常有效的随机早期检测算法的方法和装置

    公开(公告)号:US20070070907A1

    公开(公告)日:2007-03-29

    申请号:US11238474

    申请日:2005-09-29

    申请人: Alok Kumar Uday Naik

    发明人: Alok Kumar Uday Naik

    IPC分类号: H04J1/16 H04L12/56

    摘要: A method and apparatus for implementing a very efficient random early detection algorithm in the forwarding path of a network device. Under one embodiment of the method flows are associated with corresponding Weighted Random Early Detection (WRED) drop profile parameters, and a flow queue is allocated to each of multiple flows. Estimated drop probability values are repeatedly generated for the flow queues based on existing flow queue state data in combination with WRED drop profile parameters. In parallel, various packet forwarding operations are performed, including packet classification, which assigns a packet to a flow queue for enqueing. In conjunction with this, a determination is made to whether to enqueue the packet in the flow queue or drop it by comparing the estimated drop probability value for the flow queue with a random number that is generated in the forwarding path.

    摘要翻译: 一种用于在网络设备的转发路径中实现非常有效的随机早期检测算法的方法和装置。 在该方法的一个实施例下,流与相应的加权随机早期检测(WRED)丢弃简档参数相关联,并且将流队列分配给多个流中的每一个。 基于现有流队列状态数据与WRED丢弃配置文件参数相结合,针对流队列重复生成估计丢弃概率值。 并行地,执行各种分组转发操作,包括分组分类,其将分组分配给用于进入的流队列。 结合这一点,确定是否排入流队列中的分组或通过将流队列的估计丢弃概率值与在转发路径中生成的随机数进行比较来丢弃它。

    Using locks to coordinate processing of packets in a flow
    69.
    发明申请
    Using locks to coordinate processing of packets in a flow 审中-公开
    使用锁来协调流中数据包的处理

    公开(公告)号:US20070014240A1

    公开(公告)日:2007-01-18

    申请号:US11180938

    申请日:2005-07-12

    IPC分类号: H04L12/26

    摘要: In general, in one aspect, the disclosure describes a method that includes accessing a first set of bits from data associated with a flow identifier of a packet and accessing flow data based on the first set of bits. The method also includes accessing a second set of bits from the data associated with the flow identifier of the packet and accessing lock data based on the second set of bits.

    摘要翻译: 一般来说,一方面,本发明描述了一种方法,其包括从与分组的流标识符相关联的数据访问第一组位,并且基于第一组位访问流数据。 该方法还包括从与分组的流标识符相关联的数据中访问第二组位,并且基于第二组位访问锁定数据。

    Methods for performing packet classification via prefix pair bit vectors
    70.
    发明申请
    Methods for performing packet classification via prefix pair bit vectors 审中-公开
    通过前缀对比特向量执行分组分类的方法

    公开(公告)号:US20060221956A1

    公开(公告)日:2006-10-05

    申请号:US11170230

    申请日:2005-06-28

    IPC分类号: H04L12/28

    摘要: Methods for performing packet classification via prefix pair bit vectors. Unique prefix pairs in an access control list (ACL) are identified, with each prefix pair comprising a unique combination of a source prefix and a destination prefix. Corresponding prefix pair bit vectors (PPBVs) are defined for each unique source prefix and unique destination prefix in the ACL, with each PPBV including a string of bits and each bit position in the string associated with a corresponding prefix pair. A list of transport field value combinations are associated with each prefix pair based on corresponding entries in the ACL. During packet-processing operations, PPBV lookups are made using the source and destination prefix header values, and the PPBVs are logically ANDed to identify applicable prefix pairs. A search is then performed on transport field value combinations corresponding to the prefix pairs and the packet header to identify a highest priority rule.

    摘要翻译: 通过前缀对比特向量执行分组分类的方法。 标识访问控制列表(ACL)中的唯一前缀对,每个前缀对包含源前缀和目标前缀的唯一组合。 为ACL中的每个唯一的源前缀和唯一的目的地前缀定义相应的前缀对比特向量(PPBV),其中每个PPBV包括与一个对应的前缀对相关联的比特串和每个比特位置。 根据ACL中的相应条目,传输字段值组合的列表与每个前缀对相关联。 在分组处理操作期间,使用源和目标前缀头值进行PPBV查找,并且PPBV在逻辑上进行AND运算以识别适用的前缀对。 然后对与前缀对和分组报头相对应的传输字段值组合执行搜索以识别最高优先级规则。