Methods and devices for qualifying a client machine to access a network
    2.
    发明授权
    Methods and devices for qualifying a client machine to access a network 有权
    限定客户机访问网络的方法和设备

    公开(公告)号:US08065712B1

    公开(公告)日:2011-11-22

    申请号:US11138855

    申请日:2005-05-25

    摘要: Methods and devices for qualifying a client machine to access a network, based on policies governing required protective measures, such as virus checking and operating system updates, are disclosed. A client machine must pass various checks to qualify for access. A client machine may be redirected to remediation resources that support efforts to bring the client machine into compliance with applicable network access requirements. A policy repository is updated regularly by vendors of protective measures. An administrator establishes user roles that are mapped to policy rule sets retrieved from the policy repository. The policy rule sets govern qualification of client machines for access to the network in accordance with the roles of the users of the machines. An access server is an intermediary between a client machine and the access manager. A client agent runs on the client machine and carries out checks, and reports the results via the access server to the access manager.

    摘要翻译: 公开了基于管理所需保护措施(例如病毒检查和操作系统更新)的策略来限定客户机访问网络的方法和设备。 客户端机器必须通过各种检查以符合访问条件。 可以将客户端机器重定向到补救资源,以支持使客户端计算机符合适用的网络访问要求的努力。 保护措施的供应商定期更新政策库。 管理员建立映射到从策略存储库检索的策略规则集的用户角色。 策略规则根据机器用户的角色管理客户机访问网络的资格。 访问服务器是客户机和访问管理器之间的中介。 客户机代理在客户机上运行并执行检查,并通过访问服务器将结果报告给访问管理器。

    Methods and devices to support mobility of a client across VLANs and subnets, while preserving the client's assigned IP address
    3.
    发明授权
    Methods and devices to support mobility of a client across VLANs and subnets, while preserving the client's assigned IP address 有权
    支持客户端跨VLAN和子网的移动性的方法和设备,同时保留客户端分配的IP地址

    公开(公告)号:US07720031B1

    公开(公告)日:2010-05-18

    申请号:US10966818

    申请日:2004-10-15

    IPC分类号: H04W4/00 H04L12/28 H04W36/00

    摘要: The present invention relates to methods and devices that support mobility of a client across a campus, particularly mobility across VLANs and subnets, while preserving the client's assigned IP address. Both layer 2 and layer 3 packets are supported. Mobility support most clearly applies to wireless clients, but could apply to other kinds of mobile connections, even to wired connections. A smart server is adapted to support multiple VLANs and to modify and redirect packets in sessions with a client that moves from one VLAN to another, preserving the client's assigned IP address. Two or more smart servers, in cooperation with a smart manger, modify packets and tunnel them between smart servers when a client that moves from one VLAN to another and from one smart server to another, again preserving the client's assigned IP address. A similar approach applies to support mobility of a client that moves between subnets that are supervised by two smart servers, with the second smart server acting on behalf of the first smart server and tunneling packets back and forth to the first smart server. Particular aspects of the present invention are described in the claims, specification and drawings.

    摘要翻译: 本发明涉及支持客户端跨校园移动性的方法和设备,特别是跨VLAN和子网的移动性,同时保留客户端分配的IP地址。 支持第二层和第三层数据包。 移动性支持最明显适用于无线客户端,但可应用于其他类型的移动连接,甚至适用于有线连接。 智能服务器适用于支持多个VLAN,并修改和重定向与从一个VLAN移动到另一个VLAN的客户端的会话中的数据包,保留客户端分配的IP地址。 与智能管理员合作,两台或多台智能服务器会在从一个VLAN移动到另一个VLAN并从一个智能服务器移动到另一个智能服务器的客户端之间修改数据包并在智能服务器之间进行隧道传输,并再次保留客户端分配的IP地址。 类似的方法适用于支持在由两个智能服务器监督的子网之间移动的客户机的移动性,第二智能服务器代表第一智能服务器起作用并且将数据包前后传送到第一智能服务器。 在权利要求书,说明书和附图中描述了本发明的特定方面。

    Symbol parsing architecture
    4.
    发明授权
    Symbol parsing architecture 失效
    符号解析架构

    公开(公告)号:US07478223B2

    公开(公告)日:2009-01-13

    申请号:US11365051

    申请日:2006-02-28

    IPC分类号: G06F7/00

    摘要: A devices and method for parsing a data stream comprises a parser stack configured to store one or more parsing symbols, each parsing symbol representing a different state of data stream parsing, a table interface configured to retrieve one or more production rules from a production rule table according to the parsing symbols, and a state machine configured to control the parsing of a data stream according to the retrieved production rules.

    摘要翻译: 用于解析数据流的设备和方法包括被配置为存储一个或多个解析符号的解析器栈,每个解析符号表示不同的数据流解析状态,配置成从生产规则表中检索一个或多个生产规则的表接口 根据解析符号,以及状态机,被配置为根据所检索的生产规则来控制数据流的解析。

    Memory DMA interface with checksum
    6.
    发明申请
    Memory DMA interface with checksum 审中-公开
    内存DMA接口与校验和

    公开(公告)号:US20070022225A1

    公开(公告)日:2007-01-25

    申请号:US11187055

    申请日:2005-07-21

    IPC分类号: G06F13/28

    CPC分类号: G06F13/28 G06F11/1004

    摘要: A system and method comprising a direct memory access (DMA) circuit configured to directly access a memory, and a checksum adder configured to determine a checksum for data transferred between the DMA circuit and the memory.

    摘要翻译: 一种包括被配置为直接访问存储器的直接存储器访问(DMA)电路的系统和方法,以及配置为确定在DMA电路和存储器之间传送的数据的校验和的校验和加法器。

    Efficient hardware allocation of processes to processors
    7.
    发明申请
    Efficient hardware allocation of processes to processors 审中-公开
    将处理器的高效硬件分配到处理器

    公开(公告)号:US20070016906A1

    公开(公告)日:2007-01-18

    申请号:US11184424

    申请日:2005-07-18

    IPC分类号: G06F9/46

    CPC分类号: G06F9/5027 G06F9/4843

    摘要: A dispatcher module has a queue to store task requests. The dispatcher also has a task arbiter to select a current task for assignment from the task requests and a unit arbiter to identify and assign the task to an available processing unit, such that the current task is not assigned to a previously-assigned processing unit.

    摘要翻译: 分派器模块具有存储任务请求的队列。 调度员还具有任务仲裁器,用于从任务请求中选择当前任务进行分配以及单元仲裁器,以将任务识别并分配给可用的处理单元,使得当前任务未被分配给先前分配的处理单元。

    Method and apparatus for transmitting cells across a switch in unicast and multicast modes
    9.
    发明授权
    Method and apparatus for transmitting cells across a switch in unicast and multicast modes 失效
    用于以单播和组播模式在交换机上传输小区的方法和装置

    公开(公告)号:US06963563B1

    公开(公告)日:2005-11-08

    申请号:US09566603

    申请日:2000-05-08

    IPC分类号: H04L12/18 H04L12/28 H04L12/56

    摘要: The present apparatus and method of use comprises a system that enables a cell of data to be transmitted one time over a high speed data bus to an switch system where it is then distributed to each of the destinations for which it is intended. A fabric access device and a multiplex devices are each formed to have groups of buffers for buffering signals according to type. The first group of buffers is for temporarily storing data that is to be delivered to only one destination. The second group of buffers is for holding the cells that are to be transmitted to a plurality of devices. In those embodiments in which the unicast and multicast cells are transmitted over the same line or bus a parsing unit examines a field within the header portion of each cell to determine whether the cell is a unicast or multicast cell. If the cell is a unicast cell, it is temporarily stored within the unicast receive buffer set. If the cell is a multicast cell, then it is temporarily stored in the multicast buffer set. A memory whose contents include a table that is used for addressing purposes for the multicast cells.

    摘要翻译: 本发明的装置和使用方法包括使数据单元能够通过高速数据总线一次发送到交换系统的系统,然后将交换机系统分配到其所期望的每个目的地。 结构接入设备和复用设备各自被形成为具有用于根据类型缓冲信号的缓冲器组。 第一组缓冲区用于临时存储要传送到一个目的地的数据。 第二组缓冲器用于保持要发送到多个设备的单元。 在单播和多播小区通过相同的线路或总线发送的那些实施例中,解析单元检查每个小区的报头部分内的一个字段,以确定该小区是单播还是多播小区。 如果小区是单播小区,则它暂时存储在单播接收缓冲区中。 如果单元是多播单元,则临时存储在多播缓冲区中。 其内容包括用于多播单元的寻址目的的表的存储器。