Packet header compression system and method based upon a dynamic template creation
    2.
    发明申请
    Packet header compression system and method based upon a dynamic template creation 失效
    基于动态模板创建的数据包头压缩系统和方法

    公开(公告)号:US20050041660A1

    公开(公告)日:2005-02-24

    申请号:US10886956

    申请日:2004-07-08

    IPC分类号: H03M7/30 H04L29/06 H04L12/28

    摘要: Header compression system for compressing the header of the data packets of a flow transmitted from an ingress node to an egress node through a data transmission network comprising template creating means, in both ingress node and egress node, adapted for creating the same compression template from a predetermined number of uncompressed data packets at the beginning of the flow respectively transmitted by the ingress node and received by the egress node, and header compression means, in the ingress node, adapted for compressing the header of each packet following the predetermined number of uncompressed data packets before transmitting it through the data transmission network, the compression being achieved by using the compression template.

    摘要翻译: 标题压缩系统,用于压缩通过数据传输网络从入口节点传送到出口节点的流的数据分组的报头,包括模板创建装置,在入口节点和出口节点中适于从一个 在入口节点分别由入口节点发送并由出口节点接收的流的开始处的预定数量的未压缩数据分组和头部压缩装置,适用于压缩预定数量的未压缩数据之后的每个分组的报头 数据包在通过数据传输网络传输之前,通过使用压缩模板来实现压缩。

    Method and system for securely scanning network traffic
    5.
    发明授权
    Method and system for securely scanning network traffic 有权
    安全扫描网络流量的方法和系统

    公开(公告)号:US07543332B2

    公开(公告)日:2009-06-02

    申请号:US11703020

    申请日:2007-02-06

    IPC分类号: G06F15/00

    摘要: A method and system for implementing secure network communications between a first device and a second device, at least one of the devices communicating with the other device via a firewall device, are provided. The method and system may include obtaining an encryption parameter that is shared by the first device, second device and firewall device. A data packet sent by the first device may then be copied within the firewall device, so that decryption of the copy of the data packet within a portion of the firewall device may take place. In particular, the portion of the firewall device in which decryption takes place is defined such that contents of the portion are inaccessible to an operator of the firewall device. Thus, scanning of the decrypted copy of the data packet for compliance with a predetermined criterion may take place within the firewall device, without an operator of the firewall device having access to the contents of the data packet to be transmitted. Thereafter, the original data packet can be forwarded to its originally intended recipient.

    摘要翻译: 提供了一种用于在第一设备和第二设备之间实现安全网络通信的方法和系统,至少一个设备经由防火墙设备与另一设备通信。 该方法和系统可以包括获得由第一设备,第二设备和防火墙设备共享的加密参数。 然后可以在防火墙设备内复制由第一设备发送的数据分组,从而可以在防火墙设备的一部分内对数据分组的副本进行解密。 特别地,定义防火墙设备中发生解密的部分,使得该部分的内容对于防火墙设备的操作者是不可访问的。 因此,在防火墙设备内可以进行符合预定标准的数据分组的解密副本的扫描,而防火墙设备的操作者可以访问要发送的数据分组的内容。 此后,可以将原始数据分组转发到其原始的接收者。

    Method and system for securely scanning network traffic
    6.
    发明申请
    Method and system for securely scanning network traffic 有权
    安全扫描网络流量的方法和系统

    公开(公告)号:US20070169187A1

    公开(公告)日:2007-07-19

    申请号:US11703020

    申请日:2007-02-06

    IPC分类号: G06F15/16

    摘要: A method and system for implementing secure network communications between a first device and a second device, at least one of the devices communicating with the other device via a firewall device, are provided. The method and system may include obtaining an encryption parameter that is shared by the first device, second device and firewall device. A data packet sent by the first device may then be copied within the firewall device, so that decryption of the copy of the data packet within a portion of the firewall device may take place. In particular, the portion of the firewall device in which decryption takes place is defined such that contents of the portion are inaccessible to an operator of the firewall device. Thus, scanning of the decrypted copy of the data packet for compliance with a predetermined criterion may take place within the firewall device, without an operator of the firewall device having access to the contents of the data packet to be transmitted. Thereafter, the original data packet can be forwarded to its originally intended recipient.

    摘要翻译: 提供了一种用于在第一设备和第二设备之间实现安全网络通信的方法和系统,至少一个设备经由防火墙设备与另一设备通信。 该方法和系统可以包括获得由第一设备,第二设备和防火墙设备共享的加密参数。 然后可以在防火墙设备内复制由第一设备发送的数据分组,从而可以在防火墙设备的一部分内对数据分组的副本进行解密。 特别地,定义防火墙设备中发生解密的部分,使得该部分的内容对于防火墙设备的操作者是不可访问的。 因此,在防火墙设备内可以进行符合预定标准的数据分组的解密副本的扫描,而防火墙设备的操作者可以访问要发送的数据分组的内容。 此后,可以将原始数据分组转发到其原始的接收者。

    Method and system for assembling segmented frames of data transmitted over a backbone network
    7.
    发明授权
    Method and system for assembling segmented frames of data transmitted over a backbone network 失效
    用于组合通过骨干网传输的数据分段帧的方法和系统

    公开(公告)号:US06870850B1

    公开(公告)日:2005-03-22

    申请号:US09512562

    申请日:2000-02-24

    摘要: A method and system of transmitting data frames from a sending unit (10) to a receiving unit (12) in a data transmission network comprising at least a backbone (14) wherein the data are transmitted over high speed links enabling long Maximum Transmission Units (MTU) between an ingress node (18) connected to the sending unit by a first access link (16) and an egress node (22) connected to the receiving node by a second access link (20), with at least one of the first and second access links being a low speed access link requiring the data frames to be segmented into short MTUs between the sending unit and the ingress node and between the egress node and the receiving unit. A plurality of consecutive segmented data frames (28) belonging to the same flow of data transmitted from the sending unit to the ingress node are assembled by the ingress node into an assembled data frame (30) corresponding to the long MTU, the assembled data frame is transmitted over the backbone from the ingress node to the egress node at a high speed authorized by the backbone links, and the assembled data frame is de-assembled into consecutive segmented data frames (32) corresponding to the short MTUs by the egress node before being transmitted to the receiving unit.

    摘要翻译: 一种将数据帧从发送单元(10)发送到至少包括主干(14)的数据传输网络中的接收单元(12)的方法和系统,其中所述数据通过高速链路传输,从而能够实现长的最大传输单元 在由第一接入链路(16)连接到发送单元的入口节点(18)和通过第二接入链路(20)连接到接收节点的出口节点(22)之间的MTU中,至少一个第一接入链路 并且第二接入链路是低速接入链路,需要将数据帧分段成发送单元和入节点之间以及出口节点与接收单元之间的短MTU。 属于从发送单元向入口节点发送的相同数据流的多个连续分段数据帧(28)由入口节点组装成对应于长MTU的组合数据帧(30),组合数据帧 以骨干链路授权的高速通过骨干网从入口节点传送到出口节点,组装好的数据帧在出口节点之前被去组装成与出口节点对应的短MTU的连续分段数据帧(32) 被发送到接收单元。

    Method and system in a packet switching network for dynamically adjusting the bandwidth of a continuous bit rate virtual path connection according to the network load
    8.
    发明授权
    Method and system in a packet switching network for dynamically adjusting the bandwidth of a continuous bit rate virtual path connection according to the network load 失效
    分组交换网络中的方法和系统,用于根据网络负载动态调整连续比特率虚拟路径连接的带宽

    公开(公告)号:US06690678B1

    公开(公告)日:2004-02-10

    申请号:US09437820

    申请日:1999-11-10

    IPC分类号: H04J1500

    摘要: The present invention relates to a system and method for dynamically adjusting the bandwidth of a continuous bit rate virtual path connection established between a source node and a destination node within a packet or cell switching network comprising a plurality of nodes interconnected with transmission links. In the network, a bandwidth management server having access to information concerning network nodes and transmission links is defined. This server is informed each time a virtual path connection or a virtual channel connection is established on the network with an indication concerning the initial bandwidth reserved for said connection. The server detects and shares, on a continuous or periodical mode, the bandwidth which is available on transmission links among the bandwidth adjustable continuous bit rate virtual path connections and determines for each connection a new bandwidth. The source node is informed each time a new bandwidth is computed. It adjusts the bandwidth of the corresponding bandwidth adjustable continuous bit rate virtual path connection accordingly.

    摘要翻译: 本发明涉及一种系统和方法,用于动态地调整在包括与传输链路互连的多个节点的分组或小区交换网络内的源节点和目的地节点之间建立的连续比特率虚拟路径连接的带宽。 在网络中,定义了具有访问有关网络节点和传输链路的信息的带宽管理服务器。 每当在网络上建立虚拟路径连接或虚拟通道连接时,通知该服务器,并显示关于为所述连接保留的初始带宽。 服务器以连续或周期模式检测和共享带宽可调连续比特率虚拟路径连接之间的传输链路上可用的带宽,并为每个连接确定新的带宽。 每次计算新的带宽时通知源节点。 它相应地调整相应带宽可调连续比特率虚拟路径连接的带宽。

    Adaptive bandwidth allocation method for non-reserved traffic in a
high-speed data transmission network, and system for implementing said
method
    10.
    发明授权
    Adaptive bandwidth allocation method for non-reserved traffic in a high-speed data transmission network, and system for implementing said method 失效
    用于高速数据传输网络中非保留流量的自适应带宽分配方法,以及用于实现所述方法的系统

    公开(公告)号:US6118791A

    公开(公告)日:2000-09-12

    申请号:US760202

    申请日:1996-12-04

    摘要: Adaptive bandwidth allocation for Non-Reserved traffic over high speed transmission links of a digital network is operated through regulation of data packet transfers over network nodes/ports including input/output adapters connected through a switching device. A network node is assigned with a Control Point computing devise (CP) storing a Topology Data Base containing an image of the network. This Data Base is periodically and at call set up updated by Topology Data Base Update messages (TDUs) including an Explicit Rate parameter for link l indicating the current available bandwidth on link l, and a parameter NNRl indicating the number of Non-Reserved connections on link l. This information are used within each Adapter to periodically regulate the transmission bandwidth assigned to each Non-Reserved traffic connection within the network. To that end, each adapter is provided with an Access Control Function device for each attached connection (data source) and a Connection Agent (CA) getting, on request, required current link informations from the attached Topology Data Base.

    摘要翻译: 通过在包括通过交换设备连接的输入/输出适配器的网络节点/端口上的数据分组传输的调节来操作数字网络的高速传输链路上的非保留流量的自适应带宽分配。 网络节点被分配有存储包含网络图像的拓扑数据库的控制点计算设备(CP)。 该数据库是周期性的并且在由拓扑数据库更新消息(TDU)更新的呼叫建立中,包括用于指示链路l上的当前可用带宽的链路l的显式速率参数,以及指示非保留连接数目的参数NNR1 链接l。 该信息在每个适配器内使用以周期性地调节分配给网络内的每个非保留业务连接的传输带宽。 为此,每个适配器都具有每个连接的连接(数据源)的访问控制功能设备,连接代理(CA)根据请求从所附的拓扑数据库中获取所需的当前链接信息。