Securely Pushing Connection Settings to a Terminal Server Using Tickets
    1.
    发明申请
    Securely Pushing Connection Settings to a Terminal Server Using Tickets 审中-公开
    使用门票将连接设置安全地推送到终端服务器

    公开(公告)号:US20090259757A1

    公开(公告)日:2009-10-15

    申请号:US12103542

    申请日:2008-04-15

    IPC分类号: G06F15/16

    CPC分类号: H04L63/0807 G06F21/335

    摘要: Systems and techniques for securely pushing connection settings to a terminal server using tickets are described. In one embodiment, a request is received at a first network component from a client for access to a second network component. A ticket associated with one or more connection settings is created and provided to the client. The ticket is provided by the client to the second network component. The ticket is provided from the second network component to the first network component, and the one or more connection settings associated with the ticket are received from the first network component back to the second network component. The one or more connection settings are enforced at the second network component.

    摘要翻译: 描述使用票据将连接设置安全地推送到终端服务器的系统和技术。 在一个实施例中,在来自客户端的用于访问第二网络组件的第一网络组件处接收到请求。 创建与一个或多个连接设置相关联的故障单并提供给客户端。 该客票由客户端提供给第二网络组件。 从第二网络组件提供票据到第一网络组件,并且将与票据相关联的一个或多个连接设置从第一网络组件接收回第二网络组件。 一个或多个连接设置在第二个网络组件实施。

    Strategies for securely applying connection policies via a gateway
    3.
    发明授权
    Strategies for securely applying connection policies via a gateway 有权
    通过网关安全地应用连接策略的策略

    公开(公告)号:US08201218B2

    公开(公告)日:2012-06-12

    申请号:US11680518

    申请日:2007-02-28

    IPC分类号: H04L29/06

    摘要: A strategy is described for securely applying connection policies in a system that includes a first entity (e.g., a TS client) connected to a second entity (e.g., a TS server) via a gateway using a remote-operating protocol (e.g., RDP). The strategy involves establishing a first secure channel between the gateway and the TS server and transmitting policy information from the gateway to the TS server. The strategy then involves deactivating the first secure channel and setting up a second secure channel between the TS client and the TS server. The strategy uses the second secure channel to transmit RDP data from the TS client to the TS server. The TS server uses the previously-transmitted policy information to determine whether to enable or disable a feature that affects the TS client, such as device redirection.

    摘要翻译: 描述了用于在包括通过使用远程操作协议(例如RDP)的网关连接到第二实体(例如,TS服务器)的第一实体(例如,TS服务器))的系统中安全地应用连接策略的策略, 。 该策略涉及在网关和TS服务器之间建立第一安全通道,并将策略信息从网关发送到TS服务器。 然后,该策略涉及停用第一安全通道并在TS客户端与TS服务器之间建立第二安全通道。 该策略使用第二个安全通道将RDP数据从TS客户端传输到TS服务器。 TS服务器使用先前发送的策略信息来确定是否启用或禁用影响TS客户端的功能,例如设备重定向。

    Providing consistent application aware firewall traversal
    5.
    发明授权
    Providing consistent application aware firewall traversal 有权
    提供一致的应用感知防火墙穿越

    公开(公告)号:US07685633B2

    公开(公告)日:2010-03-23

    申请号:US11326992

    申请日:2006-01-05

    IPC分类号: G06F15/16

    摘要: Implementations of the present invention relate to a communication framework that is readily adaptable to a wide variety of resources intended to be accessible through a firewall. In general, a communication framework at a gateway server can provide a specific connection to a requested resource in accordance with a wide range of resource and/or network access policies. In one instance, a client requests a connection to a specific resource behind a firewall. The communication framework authenticates the connection, and quarantines the connection until determining, for example, that the client is using an appropriate resource features. If appropriately authenticated, the communication framework can pass control of the connection to an appropriately identified protocol plug-in processor, which facilitates a direct connection to the requested resource at an application layer of a communication stack.

    摘要翻译: 本发明的实现涉及一种易于适应旨在通过防火墙访问的各种资源的通信框架。 通常,网关服务器处的通信框架可以根据广泛的资源和/或网络访问策略提供与请求的资源的特定连接。 在一种情况下,客户端请求与防火墙后面的特定资源的连接。 通信框架认证连接,并隔离连接,直到确定客户端正在使用适当的资源特征。 如果适当地认证,则通信框架可以将连接的控制传递到适当识别的协议插件处理器,这有助于在通信栈的应用层处直接连接到所请求的资源。

    Strategies for Securely Applying Connection Policies via a Gateway
    6.
    发明申请
    Strategies for Securely Applying Connection Policies via a Gateway 有权
    通过网关安全地应用连接策略的策略

    公开(公告)号:US20080209538A1

    公开(公告)日:2008-08-28

    申请号:US11680518

    申请日:2007-02-28

    IPC分类号: G06F15/16

    摘要: A strategy is described for securely applying connection policies in a system that includes a first entity (e.g., a TS client) connected to a second entity (e.g., a TS server) via a gateway using a remote-operating protocol (e.g., RDP). The strategy involves establishing a first secure channel between the gateway and the TS server and transmitting policy information from the gateway to the TS server. The strategy then involves deactivating the first secure channel and setting up a second secure channel between the TS client and the TS server. The strategy uses the second secure channel to transmit RDP data from the TS client to the TS server. The TS server uses the previously-transmitted policy information to determine whether to enable or disable a feature that affects the TS client, such as device redirection.

    摘要翻译: 描述了用于在包括通过使用远程操作协议(例如RDP)的网关连接到第二实体(例如,TS服务器)的第一实体(例如,TS服务器))的系统中安全地应用连接策略的策略, 。 该策略涉及在网关和TS服务器之间建立第一安全通道,并将策略信息从网关发送到TS服务器。 然后,该策略涉及停用第一安全通道并在TS客户端与TS服务器之间建立第二安全通道。 该策略使用第二个安全通道将RDP数据从TS客户端传输到TS服务器。 TS服务器使用先前发送的策略信息来确定是否启用或禁用影响TS客户端的功能,例如设备重定向。

    Enabling terminal services through a firewall
    7.
    发明授权
    Enabling terminal services through a firewall 有权
    通过防火墙启用终端服务

    公开(公告)号:US07810148B2

    公开(公告)日:2010-10-05

    申请号:US11067125

    申请日:2005-02-25

    IPC分类号: G06F9/00

    CPC分类号: H04L63/029

    摘要: Systems and methods are described that provide terminal services through a firewall. In one implementation, data is wrapped with an RPC-based protocol, wherein the data to be wrapped is configured according to a stream-based protocol consistent with establishing a server/client relationship. The RPC-based protocol is then layered over HTTPS. The wrapped data is then passed through the firewall.

    摘要翻译: 描述了通过防火墙提供终端服务的系统和方法。 在一个实现中,数据被包装有基于RPC的协议,其中待包装的数据根据​​与建立服务器/客户端关系一致的基于流的协议被配置。 然后基于RPC的协议通过HTTPS分层。 然后将包裹的数据通过防火墙。