Method and apparatus for improving file system proxy performance and security by distributing information to clients via file handles
    1.
    发明申请
    Method and apparatus for improving file system proxy performance and security by distributing information to clients via file handles 有权
    通过文件句柄向客户分发信息来提高文件系统代理性能和安全性的方法和装置

    公开(公告)号:US20050210072A1

    公开(公告)日:2005-09-22

    申请号:US10803788

    申请日:2004-03-17

    IPC分类号: G06F7/00 G06F17/30 G06F21/00

    CPC分类号: G06F17/30067 G06F21/64

    摘要: The preferred embodiment of the invention distributes, and effectively caches, information by inserting it into file handles that the proxy sends to clients. This information can be used to improve performance by eliminating the need for the proxy to generate additional requests to the server to establish file identity. The distributed information can also be intended to improve security, for example, by allowing the proxy to encode into the file handle a session key that expires after some amount of time.

    摘要翻译: 本发明的优选实施例通过将信息插入到代理发送给客户端的文件句柄中来分发和有效地缓存信息。 该信息可用于通过消除对代理产生对服务器建立文件标识的附加请求的需要来提高性能。 分布式信息还可以旨在提高安全性,例如,通过允许代理对文件进行编码处理在一段时间后到期的会话密钥。

    Data storage and/or retrieval
    2.
    发明授权
    Data storage and/or retrieval 有权
    数据存储和/或检索

    公开(公告)号:US08352726B2

    公开(公告)日:2013-01-08

    申请号:US10704115

    申请日:2003-11-07

    IPC分类号: G06F21/00

    摘要: A system and method comprises receiving a write request from a client to store data at first and second non-sequential locations of a storage medium. The data of the write request is recognized as not being a predefined data pattern, and a first encryption method is applied to the data of the write request before it is stored at the first and second non-sequential locations of the storage medium. Further, a second different encryption method is applied to content of an area between the first and second non-sequential locations, where the content of the area is recognized as being the predefined pattern.

    摘要翻译: 系统和方法包括从客户端接收写入请求以在存储介质的第一和第二非连续位置处存储数据。 写请求的数据被识别为不是预定义的数据模式,并且第一加密方法在存储在存储介质的第一和第二非连续位置之前被应用于写请求的数据。 此外,第二不同的加密方法被应用于第一和第二非连续位置之间的区域的内容,其中该区域的内容被识别为预定义模式。

    Method and/or system to authorize access to stored data
    4.
    发明授权
    Method and/or system to authorize access to stored data 有权
    授权访问存储数据的方法和/或系统

    公开(公告)号:US07900265B1

    公开(公告)日:2011-03-01

    申请号:US12568333

    申请日:2009-09-28

    IPC分类号: H04L9/00

    摘要: Embodiments of methods and/or systems to authorize access to stored data are disclosed herein. When a data access request is detected by an agent executing on a first device, the agent determines whether the data access request is authorized based on at least one rule associated with a security policy on the first device. If the agent determines that the data access request is authorized, then the data access request is transmitted to a second device. Subsequently, an application executing on the second device, then determines whether the presence of an agent on the first device is required to forward the data access request to a data storage system. This determination is based on statistical information associated with data access of the data storage system. If it is determined that the presence of the agent is required, the second device then determines whether the agent is present and forwards the data to the agent if the agent is present.

    摘要翻译: 本文公开了授权访问存储的数据的方法和/或系统的实施例。 当在第一设备上执行的代理检测到数据访问请求时,代理基于与第一设备上的安全策略相关联的至少一个规则来确定数据访问请求是否被授权。 如果代理确定数据访问请求被授权,则数据访问请求被发送到第二设备。 随后,在第二设备上执行的应用程序然后确定是否需要在第一设备上存在代理将数据访问请求转发到数据存储系统。 该确定基于与数据存储系统的数据访问相关联的统计信息。 如果确定需要代理的存在,则第二设备然后确定代理是否存在,并且如果代理存在则将数据转发给代理。

    System and/or method for encrypting data
    5.
    发明授权
    System and/or method for encrypting data 有权
    用于加密数据的系统和/或方法

    公开(公告)号:US07646867B2

    公开(公告)日:2010-01-12

    申请号:US11223444

    申请日:2005-09-09

    IPC分类号: G09C5/00 G06F11/30

    摘要: A method, system and article for encrypting data by applying an encryption process, wherein the encryption process includes storing progress data relating to the progress of the encryption process so that the encryption process may be resumed after an interruption. Even more specifically, after the interruption, progress data relating to the progress of the encryption process is accessed. Portions of the progress data are compared to determine the last encrypted data segment. After the last encrypted data segment, the encryption process at the data segment is resumed.

    摘要翻译: 一种用于通过应用加密处理来加密数据的方法,系统和物品,其中所述加密处理包括存储与所述加密处理的进度有关的进度数据,使得可以在中断之后恢复所述加密处理。 更具体地,在中断之后,访问与加密处理的进度相关的进度数据。 比较进度数据的部分以确定最后加密的数据段。 在最后一个加密数据段之后,恢复数据段的加密过程。

    Protocol translation
    6.
    发明授权
    Protocol translation 有权
    协议翻译

    公开(公告)号:US08898452B2

    公开(公告)日:2014-11-25

    申请号:US11222684

    申请日:2005-09-08

    IPC分类号: H04L9/00 H04L29/06 G06F21/62

    摘要: A system and method for securing data by receiving encrypted data at a security appliance transmitted from a client, wherein at least a portion of the encrypted data is encrypted according to a first encryption protocol, and wherein the encrypted data is transmitted to the security appliance according to a first data transfer protocol. The encrypted data is then decrypted at the security appliance, wherein at least a portion of the decrypted data is re-encrypted according to a second encryption protocol at the security appliance. The re-encrypted data is transmitted from the security appliance to a storage device, wherein the re-encrypted data is transmitted according to a second data transfer protocol that is different than the first data transfer protocol.

    摘要翻译: 一种通过在从客户端发送的安全装置处接收加密数据来保护数据的系统和方法,其中根据第一加密协议对所述加密数据的至少一部分进行加密,并且其中所述加密数据按照 到第一个数据传输协议。 然后,所述加密数据在所述安全设备处被解密,其中所述解密数据的至少一部分根据所述安全设备处的第二加密协议重新加密。 重新加密的数据从安全设备发送到存储设备,其中根据不同于第一数据传输协议的第二数据传输协议传输重新加密的数据。

    System and/or method relating to managing a network
    9.
    发明授权
    System and/or method relating to managing a network 有权
    与管理网络有关的系统和/或方法

    公开(公告)号:US07739605B2

    公开(公告)日:2010-06-15

    申请号:US11223443

    申请日:2005-09-09

    摘要: The present invention displays a graphical representation of a multi-layer network having a front end layer and a back end layer. A plurality of front end units of the front end layer and a plurality of back end units of the back end layer are represented as a plurality of front end graphical objects and a plurality of back end graphical objects. A user selects a front end graphical object representing a selected front end unit and a back end graphical object representing a selected back end unit to form a logical connection between the front end unit and the back end unit. The logical connection grants the selected front end unit access to the selected back end unit.

    摘要翻译: 本发明显示具有前端层和后端层的多层网络的图示。 前端层的多个前端单元和后端层的多个后端单元被表示为多个前端图形对象和多个后端图形对象。 用户选择表示所选择的前端单元的前端图形对象和表示所选择的后端单元的后端图形对象,以形成前端单元和后端单元之间的逻辑连接。 逻辑连接允许所选的前端单元访问所选的后端单元。