Scalable replay counters for network security
    1.
    发明授权
    Scalable replay counters for network security 有权
    可扩展的重播计数器,用于网络安全

    公开(公告)号:US09077772B2

    公开(公告)日:2015-07-07

    申请号:US13451897

    申请日:2012-04-20

    摘要: In one embodiment, an authenticator in a communication network maintains a persistent authenticator epoch value that increments each time the authenticator restarts. The authenticator also maintains a persistent per-supplicant value for each supplicant of the authenticator, each per-supplicant value set to a current value of the authenticator epoch value each time the corresponding supplicant establishes a new security association with the authenticator. To communicate messages from the authenticator to a particular supplicant, each message uses a per-supplicant replay counter having a security association epoch counter and a message counter specific to the particular supplicant. In particular, the security association epoch counter for each message is set as a difference between the authenticator epoch value and the per-supplicant value for the particular supplicant when the message is communicated, while the message counter is incremented for each message communicated.

    摘要翻译: 在一个实施例中,通信网络中的认证器维护持续认证器时期值,其在每次验证器重新启动时递增。 认证者还为认证者的每个请求者维护持续的每个请求者的值,每次请求方的值都被设置为每次请求方与认证者建立新的安全关联时的认证者时期值的当前值。 为了将来自认证者的消息传递给特定的请求者,每个消息使用具有安全关联时计数器和特定请求者特定的消息计数器的每个请求者重播计数器。 特别地,当消息被传送时,每个消息的安全关联时代计数器被设置为特定请求者的认证者时期值和每个请求者的值之间的差异,同时消息计数器对于传达的每个消息而增加。

    SCALABLE REPLAY COUNTERS FOR NETWORK SECURITY
    2.
    发明申请
    SCALABLE REPLAY COUNTERS FOR NETWORK SECURITY 有权
    网络安全的可扩展的重置计数器

    公开(公告)号:US20130283347A1

    公开(公告)日:2013-10-24

    申请号:US13451897

    申请日:2012-04-20

    IPC分类号: H04L29/06

    摘要: In one embodiment, an authenticator in a communication network maintains a persistent authenticator epoch value that increments each time the authenticator restarts. The authenticator also maintains a persistent per-supplicant value for each supplicant of the authenticator, each per-supplicant value set to a current value of the authenticator epoch value each time the corresponding supplicant establishes a new security association with the authenticator. To communicate messages from the authenticator to a particular supplicant, each message uses a per-supplicant replay counter having a security association epoch counter and a message counter specific to the particular supplicant. In particular, the security association epoch counter for each message is set as a difference between the authenticator epoch value and the per-supplicant value for the particular supplicant when the message is communicated, while the message counter is incremented for each message communicated.

    摘要翻译: 在一个实施例中,通信网络中的认证器维护持续认证器时期值,其在每次验证器重新启动时递增。 认证者还为认证者的每个请求者维护持续的每个请求者的值,每次请求方的值都被设置为每次请求方与认证者建立新的安全关联时的认证者时期值的当前值。 为了将来自认证者的消息传递给特定的请求者,每个消息使用具有安全关联时计数器和特定请求者特定的消息计数器的每个请求者重播计数器。 特别地,当消息被传送时,每个消息的安全关联时代计数器被设置为特定请求者的认证者时期值和每个请求者的值之间的差异,同时消息计数器对于传达的每个消息而增加。

    FLEXIBLE TIME STAMPING
    3.
    发明申请
    FLEXIBLE TIME STAMPING 有权
    灵活时间戳

    公开(公告)号:US20090190589A1

    公开(公告)日:2009-07-30

    申请号:US12020836

    申请日:2008-01-28

    IPC分类号: H04L12/02

    摘要: In an example embodiment, an apparatus comprising a physical layer processing device that comprises logic configured to process a packet received from a physical layer interface is disclosed. The physical layer processing device logic is further configured to determine a preamble portion of the packet and a data portion of the packet. The physical layer processing device logic is further configured to insert a timestamp into the preamble portion of the packet. The physical layer processing device logic forwards the packet with the timestamp inserted into the preamble.

    摘要翻译: 在示例实施例中,公开了一种包括物理层处理设备的设备,其包括被配置为处理从物理层接口接收的分组的逻辑。 物理层处理设备逻辑还被配置为确定分组的前导码部分和分组的数据部分。 物理层处理设备逻辑还被配置为将时间戳插入到分组的前导码部分中。 物理层处理设备逻辑转发具有插入到前同步码中的时间戳的分组。

    Apparatus and method for conversion of data between different formats
    4.
    发明授权
    Apparatus and method for conversion of data between different formats 有权
    用于在不同格式之间转换数据的装置和方法

    公开(公告)号:US06411395B1

    公开(公告)日:2002-06-25

    申请号:US09183494

    申请日:1998-10-30

    IPC分类号: H04N712

    CPC分类号: H03M7/46

    摘要: Apparatus and method for performing hierarchial type mask encoding and data transformation includes locating a data source, loading the data source into a temporary storage, encoding heuristics for buffer transformation, and delivery of data for transformation and scalar type encoding, reduction, compression, iteration, type extension and versioning if required.

    摘要翻译: 用于执行层次型掩模编码和数据变换的装置和方法包括定位数据源,将数据源加载到临时存储器中,用于缓冲器变换的编码启发式和用于转换和标量类型编码,缩减,压缩,迭代的数据的传递, 如果需要,请输入扩展名和版本。

    Apparatus and method for conversion of structured data between different
formats
    5.
    发明授权
    Apparatus and method for conversion of structured data between different formats 失效
    用于在不同格式之间转换结构化数据的装置和方法

    公开(公告)号:US6021259A

    公开(公告)日:2000-02-01

    申请号:US898745

    申请日:1997-07-23

    IPC分类号: H03M7/46 H04N7/12

    CPC分类号: H03M7/46

    摘要: Apparatus and method for performing hierarchial type mask encoding and data transformation includes locating a data source, loading the data source into a temporary storage, encoding hierarchical heuristics for buffer transformation, and delivery of data for transformation and scalar type encoding, reduction, compression, iteration, type extension and versioning if required.

    摘要翻译: 用于执行层次型掩模编码和数据变换的装置和方法包括定位数据源,将数据源加载到临时存储器中,编码用于缓冲器变换的分级启发式,以及用于转换和标量类型编码,缩减,压缩,迭代的数据传送 ,如果需要,键入扩展和版本控制。

    Distributed group temporal key (GTK) state management
    6.
    发明授权
    Distributed group temporal key (GTK) state management 有权
    分布式时间密钥(GTK)状态管理

    公开(公告)号:US08800010B2

    公开(公告)日:2014-08-05

    申请号:US13451918

    申请日:2012-04-20

    IPC分类号: H04L9/16

    CPC分类号: H04L63/08 H04L9/0866

    摘要: In one embodiment, each security protocol supplicant in a computer network determines its group temporal key (GTK) state, and exchanges the GTK state with one or more neighbor supplicants in the computer network. Based on the exchange, a supplicant may determine whether any inconsistencies exist in its GTK state, and in response to any inconsistencies in the GTK state, may perform a GTK state synchronization with a security protocol authenticator by indicating to the authenticator what is needed to resolve the inconsistent GTK state at the particular supplicant. In another embodiment, the authenticator, which is configured to not store per-supplicant GTK state, may transmit beacons containing GTK identifiers (IDs) of GTKs currently enabled on the authenticator, and also responds to supplicants having inconsistent GTK states with one or more needed GTKs as indicated by the supplicants.

    摘要翻译: 在一个实施例中,计算机网络中的每个安全协议请求者确定其组时间密钥(GTK)状态,并且与计算机网络中的一个或多个邻居请求者交换GTK状态。 基于交换,请求者可以确定其GTK状态中是否存在任何不一致,并且响应于GTK状态中的任何不一致,可以通过向认证者指示需要解决什么来执行与安全协议认证器的GTK状态同步 特定请求方的GTK状态不一致。 在另一个实施例中,被配置为不存储每个请求者GTK状态的认证器可以传送包含认证器当前启用的GTK的GTK标识符(ID)的信标,并且还响应具有不一致的GTK状态的请求者,其中一个或多个需要 请求者指出的GTK。

    DISTRIBUTED GROUP TEMPORAL KEY (GTK) STATE MANAGEMENT
    7.
    发明申请
    DISTRIBUTED GROUP TEMPORAL KEY (GTK) STATE MANAGEMENT 有权
    分布式时区(GTK)状态管理

    公开(公告)号:US20130283360A1

    公开(公告)日:2013-10-24

    申请号:US13451918

    申请日:2012-04-20

    IPC分类号: G06F21/20

    CPC分类号: H04L63/08 H04L9/0866

    摘要: In one embodiment, each security protocol supplicant in a computer network determines its group temporal key (GTK) state, and exchanges the GTK state with one or more neighbor supplicants in the computer network. Based on the exchange, a supplicant may determine whether any inconsistencies exist in its GTK state, and in response to any inconsistencies in the GTK state, may perform a GTK state synchronization with a security protocol authenticator by indicating to the authenticator what is needed to resolve the inconsistent GTK state at the particular supplicant. In another embodiment, the authenticator, which is configured to not store per-supplicant GTK state, may transmit beacons containing GTK identifiers (IDs) of GTKs currently enabled on the authenticator, and also responds to supplicants having inconsistent GTK states with one or more needed GTKs as indicated by the supplicants.

    摘要翻译: 在一个实施例中,计算机网络中的每个安全协议请求者确定其组时间密钥(GTK)状态,并且与计算机网络中的一个或多个邻居请求者交换GTK状态。 基于交换,请求者可以确定其GTK状态中是否存在任何不一致,并且响应于GTK状态中的任何不一致,可以通过向认证者指示需要解决什么来执行与安全协议认证器的GTK状态同步 特定请求方的GTK状态不一致。 在另一个实施例中,被配置为不存储每个请求者GTK状态的认证器可以传送包含认证器当前启用的GTK的GTK标识符(ID)的信标,并且还响应具有不一致的GTK状态的请求者,其中一个或多个需要 请求者指出的GTK。

    Flexible time stamping
    8.
    发明授权
    Flexible time stamping 有权
    弹性时间戳

    公开(公告)号:US07860125B2

    公开(公告)日:2010-12-28

    申请号:US12020836

    申请日:2008-01-28

    IPC分类号: H04J3/16

    摘要: In an example embodiment, an apparatus comprising a physical layer processing device that comprises logic configured to process a packet received from a physical layer interface is disclosed. The physical layer processing device logic is further configured to determine a preamble portion of the packet and a data portion of the packet. The physical layer processing device logic is further configured to insert a timestamp into the preamble portion of the packet. The physical layer processing device logic forwards the packet with the timestamp inserted into the preamble.

    摘要翻译: 在示例实施例中,公开了一种包括物理层处理设备的设备,其包括被配置为处理从物理层接口接收的分组的逻辑。 物理层处理设备逻辑还被配置为确定分组的前导码部分和分组的数据部分。 物理层处理设备逻辑还被配置为将时间戳插入到分组的前导码部分中。 物理层处理设备逻辑转发具有插入到前同步码中的时间戳的分组。

    Method to dynamically change cluster or distributed system configuration
    9.
    发明授权
    Method to dynamically change cluster or distributed system configuration 有权
    动态更改集群或分布式系统配置的方法

    公开(公告)号:US06748429B1

    公开(公告)日:2004-06-08

    申请号:US09480330

    申请日:2000-01-10

    IPC分类号: G06F15177

    摘要: Method for enabling the dynamic modification of cluster configurations, and apparatus including software to perform the method. To enable this dynamic modification, cluster configuration data is stored as a table in a cluster configuration repository that is accessible from all nodes in the cluster. Accordingly, the present invention enables the modification of the cluster configuration from any node in the cluster dynamically. When a reconfiguration command is given, the configuration table is changed and all the nodes in the cluster are notified of the changed configuration in parallel. Following the notification by the nodes of the changed cluster configuration, the changes to the cluster are implemented dynamically as specified by the command.

    摘要翻译: 用于实现群集配置的动态修改的方法,以及包括执行该方法的软件的设备。 要启用此动态修改,集群配置数据将作为表存储在可从集群中的所有节点访问的集群配置存储库中。 因此,本发明能够动态地从集群中的任何节点修改集群配置。 当给出重新配置命令时,更改配置表,并并行地向群集中的所有节点通知已更改的配置。 在节点通知更改的集群配置后,对集群的更改将按照命令的规定动态实现。