Secure transport of multicast traffic
    1.
    发明授权
    Secure transport of multicast traffic 有权
    安全传输组播流量

    公开(公告)号:US08433900B2

    公开(公告)日:2013-04-30

    申请号:US13308254

    申请日:2011-11-30

    IPC分类号: H04L29/06

    摘要: A request to receive multicast data, associated with a multicast group, may be transmitted. The request may be transmitted via a tunnel. Group keys may be received in response to the request. The group keys may be based on the multicast group. An encapsulated packet may be received via another tunnel. The encapsulated packet may be processed, using the group keys, to obtain a multicast packet associated with the multicast data. The multicast packet may be forwarded to at least one multicast recipient.

    摘要翻译: 可以发送与多播组相关联的接收组播数据的请求。 请求可以通过隧道传输。 可以响应于该请求而接收组密钥。 组密钥可以基于组播组。 封装的分组可以经由另一个隧道接收。 可以使用组密钥来处理封装的分组以获得与多播数据相关联的多播分组。 多播分组可以被转发到至少一个多播接收者。

    SECURE TRANSPORT OF MULTICAST TRAFFIC
    2.
    发明申请
    SECURE TRANSPORT OF MULTICAST TRAFFIC 有权
    多媒体交通安全运输

    公开(公告)号:US20090292917A1

    公开(公告)日:2009-11-26

    申请号:US12512098

    申请日:2009-07-30

    IPC分类号: H04L9/00 H04L12/56

    摘要: Secure tunneled multicast transmission and reception through a network is provided. A join request may be received from a second tunnel endpoint, the join request indicating a multicast group to be joined. Group keys may be transmitted to the second tunnel endpoint, where the group keys are based at least on the multicast group. A packet received at the first tunnel endpoint may be cryptographically processed to generate an encapsulated payload. A header may be appended to the encapsulated payload to form an encapsulated packet, wherein the header includes information associated with the second tunnel endpoint. A tunnel may be established between the first tunnel endpoint and the second tunnel endpoint based on the appended header. The encapsulated packet may be transmitted through the tunnel to the second tunnel endpoint. The second tunnel endpoint may receive the encapsulated packet. Cryptographic processing of the encapsulated packet may reveal the packet having a second header. The packet may then be forwarded on an interface toward at least one multicast recipient identified in the second header.

    摘要翻译: 提供通过网络进行安全隧道传输和接收。 可以从第二隧道端点接收加入请求,该连接请求指示要加入的多播组。 组密钥可以被发送到第二隧道端点,其中组密钥至少基于多播组。 可以对在第一隧道端点处接收的分组进行密码处理以产生封装的有效载荷。 报头可以附加到封装的有效载荷以形成封装的分组,其中报头包括与第二隧道端点相关联的信息。 可以基于附加的报头在第一隧道端点和第二隧道端点之间建立隧道。 封装的分组可以通过隧道传输到第二隧道端点。 第二隧道端点可以接收封装的分组。 封装分组的加密处理可以揭示具有第二报头的分组。 然后,分组可以在接口上朝向在第二报头中标识的至少一个多播接收机转发。

    Secure transport of multicast traffic
    3.
    发明授权
    Secure transport of multicast traffic 有权
    安全传输组播流量

    公开(公告)号:US08132000B2

    公开(公告)日:2012-03-06

    申请号:US12512098

    申请日:2009-07-30

    IPC分类号: H04L29/06

    摘要: Secure tunneled multicast transmission and reception through a network is provided. A join request may be received from a second tunnel endpoint, the join request indicating a multicast group to be joined. Group keys may be transmitted to the second tunnel endpoint, where the group keys are based at least on the multicast group. A packet received at the first tunnel endpoint may be cryptographically processed to generate an encapsulated payload. A header may be appended to the encapsulated payload to form an encapsulated packet, wherein the header includes information associated with the second tunnel endpoint. A tunnel may be established between the first tunnel endpoint and the second tunnel endpoint based on the appended header. The encapsulated packet may be transmitted through the tunnel to the second tunnel endpoint. The second tunnel endpoint may receive the encapsulated packet. Cryptographic processing of the encapsulated packet may reveal the packet having a second header. The packet may then be forwarded on an interface toward at least one multicast recipient identified in the second header.

    摘要翻译: 提供通过网络进行安全隧道传输和接收。 可以从第二隧道端点接收加入请求,该连接请求指示要加入的多播组。 组密钥可以被发送到第二隧道端点,其中组密钥至少基于多播组。 可以对在第一隧道端点处接收的分组进行密码处理以产生封装的有效载荷。 报头可以附加到封装的有效载荷以形成封装的分组,其中报头包括与第二隧道端点相关联的信息。 可以基于附加的报头在第一隧道端点和第二隧道端点之间建立隧道。 封装的分组可以通过隧道传输到第二隧道端点。 第二隧道端点可以接收封装的分组。 封装分组的加密处理可以揭示具有第二报头的分组。 然后,分组可以在接口上朝向在第二报头中标识的至少一个多播接收机转发。

    SECURE TRANSPORT OF MULTICAST TRAFFIC
    4.
    发明申请
    SECURE TRANSPORT OF MULTICAST TRAFFIC 有权
    多媒体交通安全运输

    公开(公告)号:US20120144191A1

    公开(公告)日:2012-06-07

    申请号:US13308254

    申请日:2011-11-30

    IPC分类号: H04L29/06 H04L12/56

    摘要: A request to receive multicast data, associated with a multicast group, may be transmitted. The request may be transmitted via a tunnel. Group keys may be received in response to the request. The group keys may be based on the multicast group. An encapsulated packet may be received via another tunnel. The encapsulated packet may be processed, using the group keys, to obtain a multicast packet associated with the multicast data. The multicast packet may be forwarded to at least one multicast recipient.

    摘要翻译: 可以发送与多播组相关联的接收组播数据的请求。 请求可以通过隧道传输。 可以响应于该请求而接收组密钥。 组密钥可以基于组播组。 封装的分组可以经由另一个隧道接收。 可以使用组密钥来处理封装的分组以获得与多播数据相关联的多播分组。 多播分组可以被转发到至少一个多播接收者。

    Secure transport of multicast traffic
    5.
    发明授权
    Secure transport of multicast traffic 有权
    安全传输组播流量

    公开(公告)号:US07587591B2

    公开(公告)日:2009-09-08

    申请号:US10976026

    申请日:2004-10-29

    IPC分类号: H04L29/06

    摘要: Secure tunneled multicast transmission and reception through a network is provided. A join request may be received from a second tunnel endpoint, the join request indicating a multicast group to be joined. Group keys may be transmitted to the second tunnel endpoint, where the group keys are based at least on the multicast group. A packet received at the first tunnel endpoint may be cryptographically processed to generate an encapsulated payload. A header may be appended to the encapsulated payload to form an encapsulated packet, wherein the header includes information associated with the second tunnel endpoint. A tunnel may be established between the first tunnel endpoint and the second tunnel endpoint based on the appended header. The encapsulated packet may be transmitted through the tunnel to the second tunnel endpoint. The second tunnel endpoint may receive the encapsulated packet. Cryptographic processing of the encapsulated packet may reveal the packet having a second header. The packet may then be forwarded on an interface toward at least one multicast recipient identified in the second header.

    摘要翻译: 提供通过网络进行安全隧道传输和接收。 可以从第二隧道端点接收加入请求,该连接请求指示要加入的多播组。 组密钥可以被发送到第二隧道端点,其中组密钥至少基于多播组。 可以对在第一隧道端点处接收的分组进行密码处理以产生封装的有效载荷。 报头可以附加到封装的有效载荷以形成封装的分组,其中报头包括与第二隧道端点相关联的信息。 可以基于附加的报头在第一隧道端点和第二隧道端点之间建立隧道。 封装的分组可以通过隧道传输到第二隧道端点。 第二隧道端点可以接收封装的分组。 封装分组的加密处理可以揭示具有第二报头的分组。 然后,分组可以在接口上朝向在第二报头中标识的至少一个多播接收机转发。

    Point-to-multi-point/non-broadcasting multi-access VPN tunnels
    6.
    发明授权
    Point-to-multi-point/non-broadcasting multi-access VPN tunnels 有权
    点到多点/非广播多路访问VPN隧道

    公开(公告)号:US08127349B2

    公开(公告)日:2012-02-28

    申请号:US12834726

    申请日:2010-07-12

    IPC分类号: G06F9/00 G06F15/16 G06F17/00

    摘要: A system establishes a virtual private network (VPN) tunnel to a destination and determines a next hop for the VPN tunnel. The system inserts the next hop, and an address associated with the destination, into an entry of a first table. The system inserts the next hop, and a tunnel identifier corresponding to the established VPN tunnel, into an entry of a second table. The system associates one or more security parameters, used to encrypt traffic sent via the VPN tunnel, with the tunnel identifier.

    摘要翻译: 系统建立到目的地的虚拟专用网(VPN)隧道,并确定VPN隧道的下一跳。 系统将下一跳和与目的地相关联的地址插入到第一个表的条目中。 系统将下一跳和对应于已建立的VPN隧道的隧道标识符插入第二个表的条目。 该系统将用于加密经由VPN隧道发送的流量的一个或多个安全参数与隧道标识符相关联。

    POINT-TO-MULTI-POINT/NON-BROADCASTING MUTLI-ACCESS VPN TUNNELS
    7.
    发明申请
    POINT-TO-MULTI-POINT/NON-BROADCASTING MUTLI-ACCESS VPN TUNNELS 有权
    点对多点/非广播MUTLI访问VPN隧道

    公开(公告)号:US20100278181A1

    公开(公告)日:2010-11-04

    申请号:US12834726

    申请日:2010-07-12

    IPC分类号: H04L12/56

    摘要: A system establishes a virtual private network (VPN) tunnel to a destination and determines a next hop for the VPN tunnel. The system inserts the next hop, and an address associated with the destination, into an entry of a first table. The system inserts the next hop, and a tunnel identifier corresponding to the established VPN tunnel, into an entry of a second table. The system associates one or more security parameters, used to encrypt traffic sent via the VPN tunnel, with the tunnel identifier.

    摘要翻译: 系统建立到目的地的虚拟专用网(VPN)隧道,并确定VPN隧道的下一跳。 系统将下一跳和与目的地相关联的地址插入到第一个表的条目中。 系统将下一跳和对应于已建立的VPN隧道的隧道标识符插入第二个表的条目。 该系统将用于加密经由VPN隧道发送的流量的一个或多个安全参数与隧道标识符相关联。

    Point-to-multi-point/non-broadcasting multi-access VPN tunnels
    8.
    发明授权
    Point-to-multi-point/non-broadcasting multi-access VPN tunnels 有权
    点到多点/非广播多路访问VPN隧道

    公开(公告)号:US07779461B1

    公开(公告)日:2010-08-17

    申请号:US10988835

    申请日:2004-11-16

    IPC分类号: G06F9/00 G06F15/16 G06F17/00

    摘要: A system establishes a virtual private network (VPN) tunnel to a destination and determines a next hop for the VPN tunnel. The system inserts the next hop, and an address associated with the destination, into an entry of a first table. The system inserts the next hop, and a tunnel identifier corresponding to the established VPN tunnel, into an entry of a second table. The system associates one or more security parameters, used to encrypt traffic sent via the VPN tunnel, with the tunnel identifier.

    摘要翻译: 系统建立到目的地的虚拟专用网(VPN)隧道,并确定VPN隧道的下一跳。 系统将下一跳和与目的地相关联的地址插入到第一个表的条目中。 系统将下一跳和对应于已建立的VPN隧道的隧道标识符插入第二个表的条目。 该系统将用于加密经由VPN隧道发送的流量的一个或多个安全参数与隧道标识符相关联。

    Secure transport of multicast traffic
    9.
    发明申请
    Secure transport of multicast traffic 有权
    安全传输组播流量

    公开(公告)号:US20050138369A1

    公开(公告)日:2005-06-23

    申请号:US10976026

    申请日:2004-10-29

    摘要: Secure tunneled multicast transmission and reception through a network is provided. A join request may be received from a second tunnel endpoint, the join request indicating a multicast group to be joined. Group keys may be transmitted to the second tunnel endpoint, where the group keys are based at least on the multicast group. A packet received at the first tunnel endpoint may be cryptographically processed to generate an encapsulated payload. A header may be appended to the encapsulated payload to form an encapsulated packet, wherein the header includes information associated with the second tunnel endpoint. A tunnel may be established between the first tunnel endpoint and the second tunnel endpoint based on the appended header. The encapsulated packet may be transmitted through the tunnel to the second tunnel endpoint. The second tunnel endpoint may receive the encapsulated packet. Cryptographic processing of the encapsulated packet may reveal the packet having a second header. The packet may then be forwarded on an interface toward at least one multicast recipient identified in the second header.

    摘要翻译: 提供通过网络进行安全隧道传输和接收。 可以从第二隧道端点接收加入请求,该连接请求指示要加入的多播组。 组密钥可以被发送到第二隧道端点,其中组密钥至少基于多播组。 可以对在第一隧道端点处接收的分组进行密码处理以产生封装的有效载荷。 报头可以附加到封装的有效载荷以形成封装的分组,其中报头包括与第二隧道端点相关联的信息。 可以基于附加的报头在第一隧道端点和第二隧道端点之间建立隧道。 封装的分组可以通过隧道传输到第二隧道端点。 第二隧道端点可以接收封装的分组。 封装分组的加密处理可以揭示具有第二报头的分组。 然后,分组可以在接口上朝向在第二报头中标识的至少一个多播接收机转发。

    CONGESTION MANAGEMENT OF SESSION NEGOTIATIONS IN NETWORK DEVICES
    10.
    发明申请
    CONGESTION MANAGEMENT OF SESSION NEGOTIATIONS IN NETWORK DEVICES 有权
    网络设备会话讨论的约束管理

    公开(公告)号:US20090320122A1

    公开(公告)日:2009-12-24

    申请号:US12550806

    申请日:2009-08-31

    IPC分类号: G06F21/20 G06F15/16

    CPC分类号: H04L69/40 H04L63/0272

    摘要: A network device implements congestion management of sessions of a network protocol. In one implementation, an incoming request component receives session requests for a negotiation session between the network device and a second network device. A capacity pool stores a value relating to capacity of the network device to continue to efficiently process the session requests. New sessions are initiated when the value stored in the capacity pool is less than an estimate of the capacity of the network device at which the network device maximizes processor usage while minimizing session timeouts.

    摘要翻译: 网络设备实现网络协议会话的拥塞管理。 在一个实现中,传入请求组件接收在网络设备和第二网络设备之间的协商会话的会话请求。 容量池存储与网络设备的容量相关的值,以继续有效地处理会话请求。 当存储在容量池中的值小于网络设备在网络设备最大化处理器使用量并最小化会话超时的容量的估计时,将启动新会话。