Securely Pushing Connection Settings to a Terminal Server Using Tickets
    1.
    发明申请
    Securely Pushing Connection Settings to a Terminal Server Using Tickets 审中-公开
    使用门票将连接设置安全地推送到终端服务器

    公开(公告)号:US20090259757A1

    公开(公告)日:2009-10-15

    申请号:US12103542

    申请日:2008-04-15

    IPC分类号: G06F15/16

    CPC分类号: H04L63/0807 G06F21/335

    摘要: Systems and techniques for securely pushing connection settings to a terminal server using tickets are described. In one embodiment, a request is received at a first network component from a client for access to a second network component. A ticket associated with one or more connection settings is created and provided to the client. The ticket is provided by the client to the second network component. The ticket is provided from the second network component to the first network component, and the one or more connection settings associated with the ticket are received from the first network component back to the second network component. The one or more connection settings are enforced at the second network component.

    摘要翻译: 描述使用票据将连接设置安全地推送到终端服务器的系统和技术。 在一个实施例中,在来自客户端的用于访问第二网络组件的第一网络组件处接收到请求。 创建与一个或多个连接设置相关联的故障单并提供给客户端。 该客票由客户端提供给第二网络组件。 从第二网络组件提供票据到第一网络组件,并且将与票据相关联的一个或多个连接设置从第一网络组件接收回第二网络组件。 一个或多个连接设置在第二个网络组件实施。

    Strategies for securely applying connection policies via a gateway
    3.
    发明授权
    Strategies for securely applying connection policies via a gateway 有权
    通过网关安全地应用连接策略的策略

    公开(公告)号:US08201218B2

    公开(公告)日:2012-06-12

    申请号:US11680518

    申请日:2007-02-28

    IPC分类号: H04L29/06

    摘要: A strategy is described for securely applying connection policies in a system that includes a first entity (e.g., a TS client) connected to a second entity (e.g., a TS server) via a gateway using a remote-operating protocol (e.g., RDP). The strategy involves establishing a first secure channel between the gateway and the TS server and transmitting policy information from the gateway to the TS server. The strategy then involves deactivating the first secure channel and setting up a second secure channel between the TS client and the TS server. The strategy uses the second secure channel to transmit RDP data from the TS client to the TS server. The TS server uses the previously-transmitted policy information to determine whether to enable or disable a feature that affects the TS client, such as device redirection.

    摘要翻译: 描述了用于在包括通过使用远程操作协议(例如RDP)的网关连接到第二实体(例如,TS服务器)的第一实体(例如,TS服务器))的系统中安全地应用连接策略的策略, 。 该策略涉及在网关和TS服务器之间建立第一安全通道,并将策略信息从网关发送到TS服务器。 然后,该策略涉及停用第一安全通道并在TS客户端与TS服务器之间建立第二安全通道。 该策略使用第二个安全通道将RDP数据从TS客户端传输到TS服务器。 TS服务器使用先前发送的策略信息来确定是否启用或禁用影响TS客户端的功能,例如设备重定向。

    Providing consistent application aware firewall traversal
    5.
    发明授权
    Providing consistent application aware firewall traversal 有权
    提供一致的应用感知防火墙穿越

    公开(公告)号:US07685633B2

    公开(公告)日:2010-03-23

    申请号:US11326992

    申请日:2006-01-05

    IPC分类号: G06F15/16

    摘要: Implementations of the present invention relate to a communication framework that is readily adaptable to a wide variety of resources intended to be accessible through a firewall. In general, a communication framework at a gateway server can provide a specific connection to a requested resource in accordance with a wide range of resource and/or network access policies. In one instance, a client requests a connection to a specific resource behind a firewall. The communication framework authenticates the connection, and quarantines the connection until determining, for example, that the client is using an appropriate resource features. If appropriately authenticated, the communication framework can pass control of the connection to an appropriately identified protocol plug-in processor, which facilitates a direct connection to the requested resource at an application layer of a communication stack.

    摘要翻译: 本发明的实现涉及一种易于适应旨在通过防火墙访问的各种资源的通信框架。 通常,网关服务器处的通信框架可以根据广泛的资源和/或网络访问策略提供与请求的资源的特定连接。 在一种情况下,客户端请求与防火墙后面的特定资源的连接。 通信框架认证连接,并隔离连接,直到确定客户端正在使用适当的资源特征。 如果适当地认证,则通信框架可以将连接的控制传递到适当识别的协议插件处理器,这有助于在通信栈的应用层处直接连接到所请求的资源。

    Strategies for Securely Applying Connection Policies via a Gateway
    6.
    发明申请
    Strategies for Securely Applying Connection Policies via a Gateway 有权
    通过网关安全地应用连接策略的策略

    公开(公告)号:US20080209538A1

    公开(公告)日:2008-08-28

    申请号:US11680518

    申请日:2007-02-28

    IPC分类号: G06F15/16

    摘要: A strategy is described for securely applying connection policies in a system that includes a first entity (e.g., a TS client) connected to a second entity (e.g., a TS server) via a gateway using a remote-operating protocol (e.g., RDP). The strategy involves establishing a first secure channel between the gateway and the TS server and transmitting policy information from the gateway to the TS server. The strategy then involves deactivating the first secure channel and setting up a second secure channel between the TS client and the TS server. The strategy uses the second secure channel to transmit RDP data from the TS client to the TS server. The TS server uses the previously-transmitted policy information to determine whether to enable or disable a feature that affects the TS client, such as device redirection.

    摘要翻译: 描述了用于在包括通过使用远程操作协议(例如RDP)的网关连接到第二实体(例如,TS服务器)的第一实体(例如,TS服务器))的系统中安全地应用连接策略的策略, 。 该策略涉及在网关和TS服务器之间建立第一安全通道,并将策略信息从网关发送到TS服务器。 然后,该策略涉及停用第一安全通道并在TS客户端与TS服务器之间建立第二安全通道。 该策略使用第二个安全通道将RDP数据从TS客户端传输到TS服务器。 TS服务器使用先前发送的策略信息来确定是否启用或禁用影响TS客户端的功能,例如设备重定向。

    PLUGGABLE MODULES FOR TERMINAL SERVICES
    7.
    发明申请
    PLUGGABLE MODULES FOR TERMINAL SERVICES 审中-公开
    终端服务的可扩展模块

    公开(公告)号:US20090183225A1

    公开(公告)日:2009-07-16

    申请号:US11972443

    申请日:2008-01-10

    IPC分类号: G06F21/00

    摘要: Embodiments that facilitate the use of pluggable policy modules and authentication modules for access to a Terminal Services (TS) server are disclosed. In accordance with various embodiments, a method includes accessing one or more pluggable modules at a Terminal Services Gateway (TSG) server or a Terminal Services (TS) server. The method further includes processing a TS server access request from a TS client at the TSG server or the TS server. The TS server access request is processed in part based on the one or more pluggable modules. In one particular embodiment, the one or more pluggable modules include at least one of a connection authorization policy (CAP) module, a resource authorization policy (RAP) module, and an authentication module.

    摘要翻译: 公开了有助于使用可插拔策略模块和认证模块来访问终端服务(TS)服务器的实施例。 根据各种实施例,一种方法包括访问终端服务网关(TSG)服务器或终端服务(TS)服务器处的一个或多个可插拔模块。 该方法还包括从TSG服务器或TS服务器处的TS客户机处理TS服务器访问请求。 TS服务器访问请求部分基于一个或多个可插拔模块进行处理。 在一个特定实施例中,一个或多个可插拔模块包括连接授权策略(CAP)模块,资源授权策略(RAP)模块和认证模块中的至少一个。

    Techniques for enabling remote management of servers configured with graphics processors
    8.
    发明授权
    Techniques for enabling remote management of servers configured with graphics processors 有权
    实现对配置有图形处理器的服务器进行远程管理的技术

    公开(公告)号:US08830228B2

    公开(公告)日:2014-09-09

    申请号:US12973622

    申请日:2010-12-20

    摘要: A technique for enabling the use of a baseboard management controller in a computer system configured to stream 3D graphical user interfaces to remote clients is described. In an exemplary configuration, a cap driver that is written to conform to a driver model that can interface with a 3D graphics application program interface can be loaded for use with the baseboard management controller instead of a legacy driver that was written to conform to a legacy driver model. This allows a control program to load a graphics driver that can interoperate with the 3D graphics application program interface. In addition to the foregoing, other aspects are described in the text of the summary and detailed description, the claims, and drawings.

    摘要翻译: 描述了一种用于在被配置成将3D图形用户界面流向远程客户端的计算机系统中使用基板管理控制器的技术。 在示例性配置中,可以加载写入以符合可与3D图形应用程序接口连接的驱动程序模型的盖帽驱动程序,以便与基板管理控制器不同地使用已编写以符合遗留的传统驱动程序 司机模式。 这允许控制程序加载可与3D图形应用程序接口互操作的图形驱动程序。 除了上述之外,其他方面在摘要和详细描述,权利要求和附图的文本中描述。

    Techniques For Enabling Remote Management Of Servers Configured With Graphics Processors
    9.
    发明申请
    Techniques For Enabling Remote Management Of Servers Configured With Graphics Processors 有权
    使用图形处理器配置的服务器的远程管理技术

    公开(公告)号:US20120154375A1

    公开(公告)日:2012-06-21

    申请号:US12973622

    申请日:2010-12-20

    IPC分类号: G06T15/00

    摘要: A technique for enabling the use of a baseboard management controller in a computer system configured to stream 3D graphical user interfaces to remote clients is described. In an exemplary configuration, a cap driver that is written to conform to a driver model that can interface with a 3D graphics application program interface can be loaded for use with the baseboard management controller instead of a legacy driver that was written to conform to a legacy driver model. This allows a control program to load a graphics driver that can interoperate with the 3D graphics application program interface. In addition to the foregoing, other aspects are described in the text of the summary and detailed description, the claims, and drawings.

    摘要翻译: 描述了一种用于在被配置成将3D图形用户界面流向远程客户端的计算机系统中使用基板管理控制器的技术。 在示例性配置中,可以加载写入以符合可与3D图形应用程序接口连接的驱动程序模型的盖帽驱动程序,以便与基板管理控制器不同地使用已编写以符合遗留的传统驱动程序 司机模式。 这允许控制程序加载可与3D图形应用程序接口互操作的图形驱动程序。 除了上述之外,其他方面在摘要和详细描述,权利要求和附图的文本中描述。