Method, apparatus and system for enabling roaming mobile nodes to utilize private home IP addresses
    1.
    发明申请
    Method, apparatus and system for enabling roaming mobile nodes to utilize private home IP addresses 审中-公开
    用于使漫游移动节点能够利用私人家庭IP地址的方法,装置和系统

    公开(公告)号:US20050136924A1

    公开(公告)日:2005-06-23

    申请号:US10728553

    申请日:2003-12-04

    摘要: A method, apparatus and system extend a mobile home agent functionality to enable mobile nodes to use private address to correspond with nodes having public addresses. Specifically, according to an embodiment of the present invention, a home agent may be configured to assign a private address to a mobile node according to predetermined policies. In one embodiment, the packets from the mobile node may be destined for other mobile nodes that belong to the same administrative domain as the home agent. If so, the home agent may decapsulate and forward the packet directly to the destination mobile node. In an alternate embodiment, the packets from the mobile node may be destined for mobile nodes belonging to a different administrative domain than the home agent. If so, the home agent may decapsulate and perform address and port translation on the packet prior to transmission.

    摘要翻译: 方法,装置和系统扩展移动归属代理功能以使得移动节点能够使用专用地址来对应具有公共地址的节点。 具体地,根据本发明的实施例,家庭代理可以被配置为根据预定策略向移动节点分配专用地址。 在一个实施例中,来自移动节点的分组可以发往属于与归属代理相同的管理域的其他移动节点。 如果是这样,归属代理可以将分组解封装并转发到目的移动节点。 在替代实施例中,来自移动节点的分组可以发往属于与归属代理不同的管理域的移动节点。 如果是这样,归属代理可以在传输之前对分组进行解封装并执行地址和端口转换。

    Method, apparatus and system for context-based registrations based on intelligent location detection
    2.
    发明申请
    Method, apparatus and system for context-based registrations based on intelligent location detection 审中-公开
    基于智能位置检测的基于上下文的注册的方法,装置和系统

    公开(公告)号:US20050113109A1

    公开(公告)日:2005-05-26

    申请号:US10723814

    申请日:2003-11-25

    摘要: A method, apparatus and system enable mobile nodes to determine their location and register with an appropriate home agent to provide seamless roaming between disparate networks. More specifically, according to one embodiment, a mobile node may include a policy engine, which may select one of a plurality of location modules. The mobile node may apply the selected location module to determine its location with respect to a corporate demilitarized zone (“DMZ”). If the mobile node determines that it is located on an intranet behind the corporate DMZ, it may register with an internal home agent on the intranet. If the mobile node determines that it is located on an external network, it may register with an external home agent on the external network and/or the corporate DMZ, establish a Virtual Private Network (“VPN”) tunnel to the corporate DMZ, and register with the internal home agent via the tunnel.

    摘要翻译: 一种方法,装置和系统使得移动节点能够确定其位置并且向适当的归属代理注册以在不同网络之间提供无缝漫游。 更具体地,根据一个实施例,移动节点可以包括可以选择多个位置模块之一的策略引擎。 移动节点可以应用所选择的位置模块来确定其相对于公司非军事区(“DMZ”)的位置。 如果移动节点确定它位于公司DMZ后面的内部网上,则它可以向内部网上的内部归属代理注册。 如果移动节点确定它位于外部网络上,则可以向外部网络和/或公司DMZ上的外部归属代理注册,建立到公司DMZ的虚拟专用网(“VPN”)隧道,以及 通过隧道向内部归属代理机构注册。

    Method, apparatus and system for intelligently and dynamically routing mobile internet protocol packets
    3.
    发明申请
    Method, apparatus and system for intelligently and dynamically routing mobile internet protocol packets 审中-公开
    用于智能和动态路由移动互联网协议报文的方法,装置和系统

    公开(公告)号:US20050111454A1

    公开(公告)日:2005-05-26

    申请号:US10723916

    申请日:2003-11-25

    IPC分类号: H04L12/56

    CPC分类号: H04L12/56

    摘要: A mobile node may dynamically and intelligently route mobile IP packets. In one embodiment of the present invention, a method, apparatus and system are disclosed whereby a mobile node may include a policy manager to determine how to route mobile IP packets. Specifically, the policy manager may include various filters that provide information to a mobile IP driver on the mobile node to enable the driver to determine whether to apply mobile IP headers to outgoing packets prior to transmission.

    摘要翻译: 移动节点可以动态地和智能地路由移动IP分组。 在本发明的一个实施例中,公开了一种方法,装置和系统,由此移动节点可以包括策略管理器以确定如何路由移动IP分组。 具体地,策略管理器可以包括向移动节点上的移动IP驱动程序提供信息的各种过滤器,以使驾驶员能够在传输之前确定是否将移动IP报头应用于输出分组。

    Method, apparatus and system for mobile nodes to dynamically discover configuration information
    4.
    发明申请
    Method, apparatus and system for mobile nodes to dynamically discover configuration information 审中-公开
    用于移动节点动态发现配置信息的方法,装置和系统

    公开(公告)号:US20050111380A1

    公开(公告)日:2005-05-26

    申请号:US10723813

    申请日:2003-11-25

    摘要: A method, apparatus and system enable a mobile node to dynamically discover configuration information while roaming. In one embodiment, Dynamic Host Control Protocol (“DHCP”) servers may respond to a mobile node DHCP request with information pertaining to home agents. The mobile node may register with the home agent and receive a registration reply. Based on extensions within the registration reply, the mobile node may determine whether it is roaming on an internal or an external network. The mobile node may then utilize and/or store other information contained within the registration reply extensions to ensure that the mobile node is registered with the appropriate home agent.

    摘要翻译: 一种方法,装置和系统使移动节点能够在漫游时动态地发现配置信息。 在一个实施例中,动态主机控制协议(“DHCP”)服务器可以利用与归属代理相关的信息来响应移动节点DHCP请求。 移动节点可以向归属代理注册并且接收注册回复。 基于注册答复内的扩展,移动节点可以确定它是否在内部或外部网络上漫游。 然后,移动节点可以利用和/或存储包含在注册应答扩展中的其他信息,以确保移动节点向适当的归属代理注册。

    Method, apparatus and system for obtaining and retaining a mobile node home address
    5.
    发明申请
    Method, apparatus and system for obtaining and retaining a mobile node home address 失效
    用于获取和保留移动节点归属地址的方法,装置和系统

    公开(公告)号:US20050094606A1

    公开(公告)日:2005-05-05

    申请号:US10702865

    申请日:2003-11-05

    摘要: A method, apparatus and system which enable a mobile node to request dynamic allocation of a home address and to maintain that home address when roaming between a home subnet and a foreign subnet. According to one embodiment, the mobile node may acquire a home address from its home agent by using a Network Access Identifier (“NAI”) extension in a registration request. The mobile node may send out this registration request when it first starts up, regardless of whether it is on its home subnet or a foreign subnet. Additionally, the mobile node may set a bit in the registration request to inform the home agent that it is on its home network. If the bit is not set, the home agent may deduce that the mobile node is on a foreign network. In either instance, the mobile node may continue to use its originally acquired home address.

    摘要翻译: 一种使移动节点能够请求家庭地址的动态分配并且在归属子网和外部子网之间漫游时维护家庭地址的方法,装置和系统。 根据一个实施例,移动节点可以通过在注册请求中使用网络接入标识符(“NAI”)扩展从其归属代理获取归属地址。 移动节点首次启动时可以发出此注册请求,无论是在其本地子网还是外部子网。 此外,移动节点可以在注册请求中设置一个位以通知归属代理它在其归属网络上。 如果该位未设置,则归属代理可以推断移动节点在外部网络上。 在任一实例中,移动节点可以继续使用其原始获取的归属地址。

    Secure credential management
    6.
    发明申请
    Secure credential management 有权
    安全凭证管理

    公开(公告)号:US20090006848A1

    公开(公告)日:2009-01-01

    申请号:US11823985

    申请日:2007-06-29

    IPC分类号: H04L9/00 H04L9/32

    摘要: Apparatus and methods associated with providing secure credential management are described. One apparatus embodiment includes a data store to store authentication data and an authentication supplicant (AS) logic to provide a response to an authentication communication (ACM) received from an authentication process. An authentication management (AM) logic may receive the ACM from a connection management (CM) logic associated with a host operating system (HOS), provide the ACM to the AS logic, and provide the response back to the CM logic. The apparatus may include a device management (DM) client logic to provide a secure connection to an operator DM server associated with the authentication process and to store authentication data provided by the operator DM server in the data store. The AS logic, AM logic, and DM logic may reside in firmware that is not accessible to the HOS.

    摘要翻译: 描述了与提供安全凭证管理相关联的装置和方法。 一个设备实施例包括用于存储认证数据的数据存储器和用于向从认证过程接收的认证通信(ACM)提供响应的认证请求者(AS)逻辑。 认证管理(AM)逻辑可以从与主机操作系统(HOS)相关联的连接管理(CM)逻辑接收ACM,将ACM提供给AS逻辑,并将响应提供给CM逻辑。 该设备可以包括设备管理(DM)客户端逻辑,以向与认证过程相关联的操作者DM服务器提供安全连接,并将由操作者DM服务器提供的认证数据存储在数据存储器中。 AS逻辑,AM逻辑和DM逻辑可能驻留在HOS不可访问的固件中。

    Secure credential management
    7.
    发明授权

    公开(公告)号:US08510553B2

    公开(公告)日:2013-08-13

    申请号:US11823985

    申请日:2007-06-29

    IPC分类号: H04L29/06

    摘要: Apparatus and methods associated with providing secure credential management are described. One apparatus embodiment includes a data store to store authentication data and an authentication supplicant (AS) logic to provide a response to an authentication communication (ACM) received from an authentication process. An authentication management (AM) logic may receive the ACM from a connection management (CM) logic associated with a host operating system (HOS), provide the ACM to the AS logic, and provide the response back to the CM logic. The apparatus may include a device management (DM) client logic to provide a secure connection to an operator DM server associated with the authentication process and to store authentication data provided by the operator DM server in the data store. The AS logic, AM logic, and DM logic may reside in firmware that is not accessible to the HOS.

    Method and apparatus for secured embedded device communication
    9.
    发明授权
    Method and apparatus for secured embedded device communication 有权
    用于安全嵌入式设备通信的方法和装置

    公开(公告)号:US08091123B2

    公开(公告)日:2012-01-03

    申请号:US12059354

    申请日:2008-03-31

    IPC分类号: G06F17/00 G06F17/30

    摘要: In a computing device that includes a host operating system and a management engine separate from the host operating system, if the primary operating system is not operating, a management engine may obtain from a credential server via a first network connection logon information for a secured network and the management engine connects to the secure network through a secured connection using the logon information. If the operating system is operating the operating system provides the logon information to the management engine. Certificate verification may be performed by a remote server on behalf of the management engine. Other embodiments are disclosed and claimed.

    摘要翻译: 在包括与主机操作系统分离的主机操作系统和管理引擎的计算设备中,如果主操作系统不工作,则管理引擎可以经由用于安全网络的第一网络连接登录信息从证书服务器获得 并且管理引擎通过使用登录信息的安全连接连接到安全网络。 如果操作系统正在操作,操作系统会向管理引擎提供登录信息。 证书验证可以由远程服务器代表管理引擎执行。 公开和要求保护其他实施例。