MANAGEMENT NETWORK SECURITY FRAMEWORK AND ITS INFORMATION PROCESSING METHOD
    1.
    发明申请
    MANAGEMENT NETWORK SECURITY FRAMEWORK AND ITS INFORMATION PROCESSING METHOD 审中-公开
    管理网络安全框架及其信息处理方法

    公开(公告)号:US20090100259A1

    公开(公告)日:2009-04-16

    申请号:US12337835

    申请日:2008-12-18

    申请人: Yuzhi Ma Fuyou Miao

    发明人: Yuzhi Ma Fuyou Miao

    IPC分类号: H04L9/32 G06F21/20

    摘要: A management network security framework and its information processing method are disclosed. The management network security framework under the present disclosure includes a management station and a managed device. The method under the present disclosure includes: a secure transfer channel is established between the management station and the managed device; the managed device authenticates the management station; and information is exchanged between the management station and the managed device through the secure transfer channel. The embodiment of the present disclosure combines the AAA system, the upper-layer management protocol and the lower-layer security protocol organically.

    摘要翻译: 公开了一种管理网络安全框架及其信息处理方法。 本公开的管理网络安全框架包括管理站和被管理设备。 本公开的方法包括:在管理站和被管理设备之间建立安全传输通道; 被管理设备认证管理站; 并且通过安全传送通道在管理站和被管理设备之间交换信息。 本公开的实施例有机地组合了AAA系统,上层管理协议和下层安全协议。

    Method for Transferring Network Event Protocol Messages
    2.
    发明申请
    Method for Transferring Network Event Protocol Messages 有权
    传输网络事件协议消息的方法

    公开(公告)号:US20070211760A1

    公开(公告)日:2007-09-13

    申请号:US11616949

    申请日:2006-12-28

    申请人: Fuyou Miao Yuzhi Ma

    发明人: Fuyou Miao Yuzhi Ma

    IPC分类号: H04J3/24

    摘要: A method for transferring network event protocol messages includes: attaching message length information to SYSLOG (network event protocol) messages; the receiver of the SYSLOG messages parses the SYSLOG messages from the received transport payload according to the message length information. By means of the method in this invention, SYSLOG messages can be rapidly parsed from the received transport payload by the receiver of the SYSLOG messages.

    摘要翻译: 一种用于传送网络事件协议消息的方法包括:将消息长度信息附加到SYSLOG(网络事件协议)消息; SYSLOG消息的接收者根据消息长度信息从接收的传输有效载荷中解析SYSLOG消息。 通过本发明的方法,可以通过SYSLOG消息的接收者从接收到的传输有效载荷中快速解析SYSLOG消息。

    METHODS AND SYSTEMS FOR USER AUTHENTICATION
    3.
    发明申请
    METHODS AND SYSTEMS FOR USER AUTHENTICATION 有权
    用户认证的方法和系统

    公开(公告)号:US20090300743A1

    公开(公告)日:2009-12-03

    申请号:US12511807

    申请日:2009-07-29

    申请人: Yuzhi Ma Fuyou Miao

    发明人: Yuzhi Ma Fuyou Miao

    IPC分类号: H04L9/32

    摘要: Method and systems for user authentication are provided according to the embodiments of the invention. The method mainly includes: sending, by a management station, an authentication request message of an authentication protocol to a managed device via a management protocol, and sending user authentication information to the managed device; and authenticating the user by the managed device via the authentication protocol or a authentication server based on the received user authentication information, and returning an authentication acknowledgement message of the authentication protocol carrying the authentication result to the management station via the management protocol. The system mainly includes a management station and a managed device; or, a management station, a managed device and a backend authentication server. With the present invention, methods and systems for user authentication with a good extensibility and a widened application are provided.

    摘要翻译: 根据本发明的实施例提供了用于用户认证的方法和系统。 该方法主要包括:由管理站通过管理协议向被管理设备发送认证协议的认证请求消息,并向被管理设备发送用户认证信息; 以及基于所接收的用户认证信息,通过所述认证协议或认证服务器,通过所述被管理设备认证所述用户,并且经由所述管理协议,将携带有认证结果的认证协议的认证确认消息返回给所述管理站。 该系统主要包括管理站和受管设备; 或管理站,被管理设备和后端认证服务器。 利用本发明,提供了具有良好可扩展性和扩展应用的用户认证的方法和系统。

    Method for transferring network event protocol messages
    4.
    发明授权
    Method for transferring network event protocol messages 有权
    传送网络事件协议消息的方法

    公开(公告)号:US08792519B2

    公开(公告)日:2014-07-29

    申请号:US11616949

    申请日:2006-12-28

    申请人: Fuyou Miao Yuzhi Ma

    发明人: Fuyou Miao Yuzhi Ma

    IPC分类号: H04J3/24

    摘要: A method for transferring network event protocol messages includes: attaching message length information to SYSLOG (network event protocol) messages; the receiver of the SYSLOG messages parses the SYSLOG messages from the received transport payload according to the message length information. By means of the method in this invention, SYSLOG messages can be rapidly parsed from the received transport payload by the receiver of the SYSLOG messages.

    摘要翻译: 一种用于传送网络事件协议消息的方法包括:将消息长度信息附加到SYSLOG(网络事件协议)消息; SYSLOG消息的接收者根据消息长度信息从接收的传输有效载荷中解析SYSLOG消息。 通过本发明的方法,SYSLOG消息可以由SYSLOG消息的接收者从接收到的传输有效负载快速解析。

    Methods and systems for user authentication
    5.
    发明授权
    Methods and systems for user authentication 有权
    用户认证的方法和系统

    公开(公告)号:US08276194B2

    公开(公告)日:2012-09-25

    申请号:US12511807

    申请日:2009-07-29

    申请人: Yuzhi Ma Fuyou Miao

    发明人: Yuzhi Ma Fuyou Miao

    摘要: Method and systems for user authentication are provided according to the embodiments of the invention. The method mainly includes: sending, by a management station, an authentication request message of an authentication protocol to a managed device via a management protocol, and sending user authentication information to the managed device; and authenticating the user by the managed device via the authentication protocol or a authentication server based on the received user authentication information, and returning an authentication acknowledgement message of the authentication protocol carrying the authentication result to the management station via the management protocol. The system mainly includes a management station and a managed device; or, a management station, a managed device and a backend authentication server. With the present invention, methods and systems for user authentication with a good extensibility and a widened application are provided.

    摘要翻译: 根据本发明的实施例提供了用于用户认证的方法和系统。 该方法主要包括:由管理站通过管理协议向被管理设备发送认证协议的认证请求消息,并向被管理设备发送用户认证信息; 以及基于所接收的用户认证信息,通过所述认证协议或认证服务器,通过所述被管理设备认证所述用户,并且经由所述管理协议,将携带有认证结果的认证协议的认证确认消息返回给所述管理站。 该系统主要包括管理站和受管设备; 或管理站,被管理设备和后端认证服务器。 利用本发明,提供了具有良好可扩展性和扩展应用的用户认证的方法和系统。

    METHOD AND APPARATUS FOR PROCESSING ALARM/EVENT INFORMATION
    6.
    发明申请
    METHOD AND APPARATUS FOR PROCESSING ALARM/EVENT INFORMATION 有权
    用于处理报警/事件信息的方法和装置

    公开(公告)号:US20100057892A1

    公开(公告)日:2010-03-04

    申请号:US12618046

    申请日:2009-11-13

    IPC分类号: G06F15/177 G06F15/16

    CPC分类号: H04L41/0631 H04L41/0686

    摘要: A method and apparatus for processing alarm/event information are disclosed. The method includes: parsing received notification information that includes uniformly sorted alarm/event information; and obtaining the uniformly sorted alarm/event information. The apparatus includes: a parsing module, configured to parse received notification information that includes uniformly sorted alarm/event information; and a processing module, configured to obtain the uniformly sorted alarm/event information. The method and apparatus implement data interworking, reduce XML tags, and improve the efficiency of transmitting data on the network.

    摘要翻译: 公开了一种用于处理报警/事件信息的方法和装置。 该方法包括:解析收到的通知信息,包括统一排列的报警/事件信息; 并获得统一排序的报警/事件信息。 该装置包括:解析模块,被配置为解析包括统一排序的报警/事件信息的接收到的通知信息; 以及处理模块,用于获得统一排序的报警/事件信息。 该方法和设备实现数据互通,减少XML标签,提高网络上传输数据的效率。

    Method and system for obtaining home agent information of a mobile node
    7.
    发明授权
    Method and system for obtaining home agent information of a mobile node 有权
    用于获取移动节点的归属代理信息的方法和系统

    公开(公告)号:US08213369B2

    公开(公告)日:2012-07-03

    申请号:US12044358

    申请日:2008-03-07

    申请人: Yuzhi Ma

    发明人: Yuzhi Ma

    IPC分类号: H04W4/00

    摘要: Embodiments of the invention provide a method and a system for obtaining home agent information of a mobile node. The method includes: when a DHCPv6 server receives a request message from a mobile node, it obtains the home agent information of the mobile node; the DHCPv6 server includes the home agent information into the response message, and sends the response to the mobile node. With embodiments of the present invention, a mobile node may obtain its home agent information (such as its home agent address information) simultaneously when it requests related information. When the request message is a home address request message or a care-of address request message, the invention provides a clearly defined process for a mobile node to obtain home agent information when it is started up on a home link or foreign link. The invention avoids a special message interaction procedure to obtain home agent information. It increases the efficiency in obtaining home agent information, refines the RFC and improves the handover speed of the mobile node.

    摘要翻译: 本发明的实施例提供一种用于获得移动节点的归属代理信息的方法和系统。 该方法包括:当DHCPv6服务器从移动节点接收到请求消息时,获取移动节点的归属代理信息; DHCPv6服务器将归属代理信息包含在响应消息中,并将响应发送给移动节点。 利用本发明的实施例,当移动节点请求相关信息时,移动节点可以同时获得其归属代理信息(例如其归属代理地址信息)。 当请求消息是家庭地址请求消息或转交地址请求消息时,本发明为移动节点在家庭链路或外部链路上启动时获得本地代理信息提供了明确定义的过程。 本发明避免了特殊的消息交互过程来获得归属代理信息。 提高了获取归属代理信息的效率,优化了RFC,提高了移动节点的切换速度。

    Method and apparatus for processing alarm/event information
    8.
    发明授权
    Method and apparatus for processing alarm/event information 有权
    报警/事件信息处理方法及装置

    公开(公告)号:US08005914B2

    公开(公告)日:2011-08-23

    申请号:US12618046

    申请日:2009-11-13

    IPC分类号: G06F15/16 G06F15/173

    CPC分类号: H04L41/0631 H04L41/0686

    摘要: A method and apparatus for processing alarm/event information are disclosed. The method includes: parsing received notification information that includes uniformly sorted alarm/event information; and obtaining the uniformly sorted alarm/event information. The apparatus includes: a parsing module, configured to parse received notification information that includes uniformly sorted alarm/event information; and a processing module, configured to obtain the uniformly sorted alarm/event information. The method and apparatus implement data interworking, reduce XML tags, and improve the efficiency of transmitting data on the network.

    摘要翻译: 公开了一种用于处理报警/事件信息的方法和装置。 该方法包括:解析收到的通知信息,包括统一排列的报警/事件信息; 并获得统一排序的报警/事件信息。 该装置包括:解析模块,被配置为解析包括统一排序的报警/事件信息的接收到的通知信息; 以及处理模块,用于获得统一排序的报警/事件信息。 该方法和设备实现数据互通,减少XML标签,提高网络上传输数据的效率。

    Method and system for initialization configuration of managed device
    9.
    发明授权
    Method and system for initialization configuration of managed device 有权
    被管理设备的初始化配置方法和系统

    公开(公告)号:US07916748B2

    公开(公告)日:2011-03-29

    申请号:US12013051

    申请日:2008-01-11

    申请人: Yuzhi Ma

    发明人: Yuzhi Ma

    IPC分类号: H04L12/42 H04L12/56

    摘要: A method for initialization configuration of a managed device, includes: predefining and storing initial configuration information of the managed device; detecting a message requesting for IP address assignment broadcasted from the managed device; searching in the initial configuration information for the message requesting for IP address assignment, to obtain an IP address of a Device Management (DM) interface of the managed device; sending the IP address to the managed device; upon determining that the managed device has configured its IP address as the IP address, sending an initial configuration command to the managed device; and performing automatically the initialization configuration of the managed device in accordance with the initial configuration information. A system for initialization configuration of a managed device is also provided.

    摘要翻译: 一种被管理设备的初始化配置的方法,包括:预先定义和存储被管理设备的初始配置信息; 检测从被管理设备广播的请求IP地址分配的消息; 在请求IP地址分配的消息的初始配置信息中搜索以获得被管理设备的设备管理(DM)接口的IP地址; 将IP地址发送到被管理设备; 在确定被管理设备已经配置其IP地址作为IP地址后,向被管理设备发送初始配置命令; 并根据初始配置信息自动执行被管理设备的初始化配置。 还提供了用于被管理设备的初始化配置的系统。

    Configuration and management system and implementation method of multi-protocol label switching VPN
    10.
    发明授权
    Configuration and management system and implementation method of multi-protocol label switching VPN 有权
    多协议标签交换VPN的配置管理系统及实现方法

    公开(公告)号:US07801974B2

    公开(公告)日:2010-09-21

    申请号:US10739986

    申请日:2003-12-18

    IPC分类号: G06F15/177

    CPC分类号: H04L12/4641

    摘要: The invention relates to a configuration and management development system for MPLS VPN in the network management field of a data communication. The development system is a three-dimensional structure, which includes first dimension of view layer, second dimension of management layer and third dimension of TCP/IP layer, and each layer is divided into several sub-layers. MPLS VPN can be implemented in various different ways with the development system; software having better adaptability can be developed. With the development system, configuration and management software for MPLS VPN can be rapidly designed and implemented. The configuration and management software, developed with the development system, has a modularized structure with clear specification and a better expandability.

    摘要翻译: 本发明涉及数据通信网络管理领域的MPLS VPN的配置和管理开发系统。 开发系统是三维结构,包括视图层的第一维度,管理层的第二维度和TCP / IP层的第三维度,每层分为几个子层。 MPLS VPN可以通过开发系统以各种不同的方式实现; 可以开发具有更好适应性的软件。 通过开发系统,可以快速设计和实现MPLS VPN的配置和管理软件。 与开发系统开发的配置和管理软件具有模块化结构,具有明确的规格和更好的可扩展性。