Sequencing packets from multiple threads
    1.
    发明授权
    Sequencing packets from multiple threads 有权
    对多个线程的数据包进行排序

    公开(公告)号:US08379647B1

    公开(公告)日:2013-02-19

    申请号:US11877146

    申请日:2007-10-23

    IPC分类号: H04L12/28 H04L12/56

    CPC分类号: H04L47/34 H04L45/74

    摘要: A device may reserve a slot for a received packet in a packet ordering queue (POQ), convey the packet to one of a plurality of threads for processing, obtain the packet from the one of the plurality of threads after the packet has been processed, organize the packet in the POQ in accordance with a position of the reserved slot, and release the packet from the POQ if the reserved slot is a head of the POQ.

    摘要翻译: 设备可以在分组排序队列(POQ)中为接收到的分组预留时隙,将分组传送到多个线程中的一个进行处理,在分组被处理之后从多个线程中的一个线程获得分组, 根据保留时隙的位置在POQ中组织分组,如果保留的时隙是POQ的头,则从POQ释放分组。

    Layer two firewall with active-active high availability support
    2.
    发明授权
    Layer two firewall with active-active high availability support 有权
    第二层防火墙,主动主动高可用性支持

    公开(公告)号:US07941837B1

    公开(公告)日:2011-05-10

    申请号:US11751731

    申请日:2007-05-22

    IPC分类号: G06F9/00

    CPC分类号: H04L63/0209 H04L63/0236

    摘要: Techniques are described to enable two or more layer two (L2) firewall devices to be configured as a high availability (HA) cluster in an active-active configuration. A first layer two (L2) firewall and a second L2 firewall are positioned within the same L2 network. The first L2 firewall and the second L2 firewall are concurrently configured with active virtual security devices (VSDs) within the L2 network, and concurrently apply L2 firewall services to packets within the L2 network. A VSD of one of the L2 firewalls automatically switches to an active VSD status for a VSD group in place of a VSD of another L2 firewall when the other L2 firewall fails.

    摘要翻译: 描述技术以使得两个或多个第二层(L2)防火墙设备能够被配置为主动 - 主动配置中的高可用性(HA)群集。 第一层二层(L2)防火墙和第二层L2防火墙位于同一L2网络内。 第一个L2防火墙和第二个L2防火墙同时配置在L2网络内的主动虚拟安全设备(VSD),并对L2网络内的报文同时应用L2防火墙业务。 当另一个L2防火墙发生故障时,其中一个L2防火墙的VSD自动切换到VSD组的主动VSD状态,代替另一个L2防火墙的VSD。

    Packet forwarding using feedback controlled weighted queues dynamically adjusted based on processor utilization
    3.
    发明授权
    Packet forwarding using feedback controlled weighted queues dynamically adjusted based on processor utilization 有权
    使用基于处理器利用率动态调整的反馈控制加权队列的分组转发

    公开(公告)号:US08208406B1

    公开(公告)日:2012-06-26

    申请号:US12111996

    申请日:2008-04-30

    IPC分类号: H04L12/28

    CPC分类号: H04L47/623

    摘要: In general, techniques are described for dynamically managing weighted queues. In accordance with the techniques, a network security device comprises a queue management module that assigns, for each queue of a plurality of queues, a quota desirable to a user that a processor of the network security device consumes to service each queue. The queue management module determines, based on the desirable quotas, a queue weight for each queue and computes. Based on the computation, the queue management module dynamically adjusts one or more of the weights such that subsequent amounts of processing time actually required to process the number of packets defined by each of the queue weights more accurately reflects the desirable quotas assigned to each of the queues. The network device outputs the number of packets in accordance with the adjusted weights.

    摘要翻译: 一般来说,描述了用于动态管理加权队列的技术。 根据这些技术,网络安全设备包括队列管理模块,其为多个队列的每个队列分配对网络安全设备的处理器消耗对每个队列服务的用户所需的配额。 队列管理模块基于所需的配额来确定每个队列的队列权重并进行计算。 基于该计算,队列管理模块动态地调整一个或多个权重,使得实际需要处理由每个队列权重定义的分组数量的后续处理时间量更准确地反映分配给每个队列权重的所需配额 队列 网络设备根据调整的权重输出数据包数。

    Providing non-interrupt failover using a link aggregation mechanism
    4.
    发明授权
    Providing non-interrupt failover using a link aggregation mechanism 有权
    使用链路聚合机制提供非中断故障转移

    公开(公告)号:US09100329B1

    公开(公告)日:2015-08-04

    申请号:US13536419

    申请日:2012-06-28

    摘要: A device receives traffic; identifies an address associated with the traffic; determines whether the address is associated with an aggregate interface, the aggregate interface being associated with a first port and a second port. The first port corresponds to a first node in a first state, that indicates that the first node is available to forward the traffic, and the second port corresponds to a second node in a second state, that indicates that that the second node is not available to forward the traffic. The device transmits the traffic to the first node via the first port and to the second node, via the second port, when the address is associated with the aggregate interface. Transmitting the traffic enables the second node to forward the traffic when the first node changes from the first state to the second state.

    摘要翻译: 设备接收流量; 识别与流量相关联的地址; 确定地址是否与聚合接口相关联,聚合接口与第一端口和第二端口相关联。 第一端口对应于处于第一状态的第一节点,其指示第一节点可用于转发业务,并且第二端口对应于处于第二状态的第二节点,其指示第二节点不可用 转发流量。 当地址与聚合接口相关联时,设备经由第一端口向第一节点传送流量,并经由第二端口将流量发送到第二节点。 当第一节点从第一状态改变到第二状态时,发送流量使得第二节点能够转发流量。

    Fully integrated switching and routing in a security device
    5.
    发明授权
    Fully integrated switching and routing in a security device 有权
    在安全设备中完全集成的交换和路由

    公开(公告)号:US09021547B1

    公开(公告)日:2015-04-28

    申请号:US13333439

    申请日:2011-12-21

    IPC分类号: G06F17/00 G06F7/04 H04L29/06

    摘要: This disclosure is directed toward an integrated switching and routing security device that provides zone-based security directly between layer two (L2) interfaces of L2 bridge domains and/or layer three (L3) interfaces of L3 routing instances within the security device. The integrated switching and routing security device supports both switching and routing functionalities for packets on L2 and L3 interfaces, and supports security within and between L2 bridge domains and L3 routing instances. The integrated switching and routing security device configures L2 security zones for one or more L2 interfaces and configures L3 security zones for one or more L3 interfaces. The integrated switching and routing security device then applies security policies to incoming packets according to the L2 security zones and/or the L3 security zones associated with the incoming interface and an outgoing interface for the packets to provide end-to-end security within the security device.

    摘要翻译: 本公开涉及集成的交换和路由安全设备,其直接在L2网桥域的第二层(L2)接口和/或L3路由实例的第三层(L3)接口之间提供基于区域的安全性。 集成交换和路由安全设备支持L2和L3接口上的数据包的交换和路由功能,并支持L2桥接域和L3路由实例之间的安全性。 集成交换路由安全设备为一个或多个L2接口配置L2安全区域,并为一个或多个L3接口配置L3安全区域。 集成交换和路由安全设备然后根据与入局接口相关联的L2安全区域和/或L3安全区域对传入的分组应用安全策略,以及用于分组的输出接口,以提供安全性内的端到端安全性 设备。

    Thin film transistor array substrate having polysilicon
    6.
    发明授权
    Thin film transistor array substrate having polysilicon 有权
    具有多晶硅的薄膜晶体管阵列基板

    公开(公告)号:US08884304B2

    公开(公告)日:2014-11-11

    申请号:US12337583

    申请日:2008-12-17

    摘要: A thin film transistor array substrate includes a substrate, a plurality of poly-silicon islands and a plurality of gates. The substrate has a display region, a gate driver region and a source driver region. Each poly-silicon island disposed on the substrate has a source region, a drain region and a channel region disposed therebetween. The poly-silicon islands include several first poly-silicon islands and several second poly-silicon islands. The first poly-silicon islands having main grain boundaries and sub grain boundaries are only disposed within the display region and the gate driver region. The main grain boundaries of the first poly-silicon islands are only disposed within the source regions and/or the drain regions. The second poly-silicon islands are disposed in the source driver region. Grain sizes of the first poly-silicon islands are substantially different from those of the second poly-silicon islands. Gates corresponding to the channel regions are disposed on the substrate.

    摘要翻译: 薄膜晶体管阵列基板包括基板,多个多晶硅岛和多个栅极。 衬底具有显示区域,栅极驱动器区域和源极驱动器区域。 设置在基板上的每个多硅岛具有源极区域,漏极区域和设置在其间的沟道区域。 多晶硅岛包括几个第一多晶硅岛和几个第二多晶硅岛。 具有主晶粒边界和子晶界的第一多晶硅岛仅设置在显示区域和栅极驱动器区域内。 第一多晶硅岛的主晶粒边界仅设置在源区和/或漏区内。 第二多晶硅岛设置在源极驱动器区域中。 第一多晶硅岛的晶粒尺寸与第二多晶硅岛的晶粒尺寸基本不同。 对应于沟道区的栅极设置在衬底上。

    Time-based secure key synchronization
    7.
    发明授权
    Time-based secure key synchronization 有权
    基于时间的安全密钥同步

    公开(公告)号:US08634560B1

    公开(公告)日:2014-01-21

    申请号:US12879570

    申请日:2010-09-10

    IPC分类号: H04K1/00 H04L9/08

    摘要: A server device initiates a traffic encapsulation key (TEK) re-key sequence for a group virtual private network (VPN), based on an upcoming expiration time for an existing TEK. The server device sends, via a push message during a first time period immediately after the initiating, a new TEK to members of the group VPN. The server device receives, during a second time period that immediately follows the first time period, a pull request, for the new TEK, from one of the members of the group VPN, and sends, to the one of the members, the new TEK, where the re-key sequence transitions all the members of the group VPN from the existing TEK key to the new TEK key before the expiration time for the existing TEK.

    摘要翻译: 基于现有TEK的即将到期的时间,服务器设备为组虚拟专用网(VPN)发起流量封装密钥(TEK)重新键序列。 服务器设备在发起之后的第一时间段内通过推送消息将新的TEK发送到组VPN的成员。 服务器设备在紧随第一时间段的第二时间段内接收来自组VPN中的一个成员的针对新TEK的拉取请求,并向该成员之一发送新的TEK ,其中重新键序列将组VPN的所有成员从现有TEK密钥转换到现有TEK的到期时间之前的新TEK密钥。

    METHOD FOR FABRICATING LIGHT EMITTING DIODE CHIP
    9.
    发明申请
    METHOD FOR FABRICATING LIGHT EMITTING DIODE CHIP 有权
    用于制造发光二极管芯片的方法

    公开(公告)号:US20110318855A1

    公开(公告)日:2011-12-29

    申请号:US13220693

    申请日:2011-08-30

    IPC分类号: H01L33/44

    摘要: A method for fabricating a light emitting diode chip is provided. Firstly, a semiconductor device layer is formed on a substrate. Afterwards, a current spreading layer is formed on a portion of the semiconductor device layer. Then, a current blocking layer and a passivation layer are formed on a portion of the semiconductor device layer not covered by the current spreading layer. Finally, a first electrode is formed on the current blocking layer and the current spreading layer. Moreover, a second electrode is formed on the semiconductor device layer.

    摘要翻译: 提供一种制造发光二极管芯片的方法。 首先,在基板上形成半导体器件层。 之后,在半导体器件层的一部分上形成电流扩散层。 然后,在未被电流扩展层覆盖的半导体器件层的一部分上形成电流阻挡层和钝化层。 最后,在电流阻挡层和电流扩展层上形成第一电极。 此外,在半导体器件层上形成第二电极。

    Pixel structure of LCD and fabrication method thereof
    10.
    发明授权
    Pixel structure of LCD and fabrication method thereof 有权
    LCD的像素结构及其制作方法

    公开(公告)号:US08058084B2

    公开(公告)日:2011-11-15

    申请号:US12844166

    申请日:2010-07-27

    IPC分类号: H01L21/00

    摘要: In this pixel structure, a metal layer/a dielectric layer/a heavily doped silicon layer constitutes a bottom electrode/a capacitor dielectric layer/a top electrode of a storage capacitor. At the same time, a metal shielding layer is formed under the thin film transistor to decrease photo-leakage-current.

    摘要翻译: 在该像素结构中,金属层/电介质层/重掺杂硅层构成存储电容器的底部电极/电容器电介质层/顶部电极。 同时,在薄膜晶体管下方形成金属屏蔽层,以降低光漏电流。