Virtual Machine Management Using a Downloadable Subscriber Identity Module
    1.
    发明申请
    Virtual Machine Management Using a Downloadable Subscriber Identity Module 有权
    使用可下载的用户身份模块进行虚拟机管理

    公开(公告)号:US20140373012A1

    公开(公告)日:2014-12-18

    申请号:US14369455

    申请日:2011-12-29

    IPC分类号: G06F9/455 H04W4/00

    摘要: A method is presented of establishing communications with a Virtual Machine, VM, in a virtualised computing environment using a 3GPPcommunications network. The method includes establishing a Machine-to-Machine Equipment Platform, M2MEP, which comprises a Communications Module, CM, providing an end-point of a communication channel between the 3GPP network and the VM. A virtual Machine-to-Machine Equipment is established that comprises a VM running on the M2MEP and a downloadable Subscriber Identity Module, associated with the CM. The Subscriber Identity Module includes security data and functions for enabling access via the 3GPP network. The CM utilises data in the Subscriber Identity Module for controlling communication over the communication channel between the VM and the 3GPP network.

    摘要翻译: 提出了一种使用3GPP通信网络在虚拟化计算环境中与虚拟机VM建立通信的方法。 该方法包括建立一个机器到机器设备平台,M2MEP,其包括通信模块CM,其提供3GPP网络和VM之间的通信信道的端点。 建立了虚拟机对机器设备,其包括在M2MEP上运行的VM和与CM相关联的可下载的订户身份模块。 订户身份​​模块包括用于通过3GPP网络访问的安全数据和功能。 CM利用订户身份模块中的数据来控制在VM与3GPP网络之间的通信信道上的通信。

    Virtual machine management using a downloadable subscriber identity module
    2.
    发明授权
    Virtual machine management using a downloadable subscriber identity module 有权
    使用可下载的用户识别模块进行虚拟机管理

    公开(公告)号:US09569237B2

    公开(公告)日:2017-02-14

    申请号:US14369455

    申请日:2011-12-29

    摘要: A method is presented of establishing communications with a Virtual Machine, VM, in a virtualized computing environment using a 3GPPcommunications network. The method includes establishing a Machine-to-Machine Equipment Platform, M2MEP, which comprises a Communications Module, CM, providing an end-point of a communication channel between the 3GPP network and the VM. A virtual Machine-to-Machine Equipment is established that comprises a VM running on the M2MEP and a downloadable Subscriber Identity Module, associated with the CM. The Subscriber Identity Module includes security data and functions for enabling access via the 3GPP network. The CM utilizes data in the Subscriber Identity Module for controlling communication over the communication channel between the VM and the 3GPP network.

    摘要翻译: 提出了一种使用3GPP通信网络在虚拟化计算环境中与虚拟机VM建立通信的方法。 该方法包括建立一个机器到机器设备平台,M2MEP,其包括通信模块CM,其提供3GPP网络和VM之间的通信信道的端点。 建立了虚拟机对机器设备,其包括在M2MEP上运行的VM和与CM相关联的可下载的订户身份模块。 订户身份​​模块包括用于通过3GPP网络访问的安全数据和功能。 CM利用订户身份模块中的数据来控制在VM与3GPP网络之间的通信信道上的通信。

    Virtual machine migration using 3GPP MCIM
    3.
    发明授权
    Virtual machine migration using 3GPP MCIM 有权
    使用3GPP MCIM进行虚拟机迁移

    公开(公告)号:US09286100B2

    公开(公告)日:2016-03-15

    申请号:US14368360

    申请日:2011-12-29

    IPC分类号: G06F9/455 G06F9/48

    CPC分类号: G06F9/45533 G06F9/4856

    摘要: A method of migrating a virtual machine comprises a first manager, managing a first computing environment (such as a computing cloud), initiates migration of a virtual machine currently executing on a first vM2ME (virtual machine-to-machine equipment) in the first computing environment to a second computing environment (such as another computing cloud). Once the VM has migrated, the first manager disables execution of the first vM2ME.

    摘要翻译: 迁移虚拟机的方法包括:管理第一计算环境(例如计算云)的第一管理器,在第一计算中启动当前在第一vM2ME(虚拟机对机器设备)上执行的虚拟机的迁移 环境到第二计算环境(例如另一计算云)。 VM迁移之后,第一个管理员将禁用第一个vM2ME的执行。

    Remote Provisioning of 3GPP Downloadable Subscriber Identity Module for Virtual Machine Applications
    4.
    发明申请
    Remote Provisioning of 3GPP Downloadable Subscriber Identity Module for Virtual Machine Applications 有权
    用于虚拟机应用的3GPP可下载用户身份模块的远程配置

    公开(公告)号:US20140337940A1

    公开(公告)日:2014-11-13

    申请号:US14369538

    申请日:2011-12-29

    摘要: A method is presented of providing a subscriber identity for the provision of services on behalf of the subscriber in a virtual computing environment. The method includes receiving a request to establish an execution environment for a virtual machine-to-machine equipment, vM2 M E. The vM2ME is provided, comprising software for execution in the virtual computing environment and a downloadable Subscriber Identity Module. A Communications Module, CM, is set up for execution in a domain of a virtualisation platform. The CM provides an end-point for communications between the vM2ME and a 3GPP network. The Subscriber Identity Module is installed for execution together with the CM, the Subscriber Identity Module including a 3GPP identity of the subscriber, security data and functions for enabling access to the vM2ME via the 3GPP network.

    摘要翻译: 提出了一种提供用于在虚拟计算环境中代表用户提供服务的订户身份的方法。 该方法包括接收建立用于虚拟机对机器设备vM2M E的执行环境的请求。提供vM2ME,其包括用于在虚拟计算环境中执行的软件和可下载的订户身份模块。 通信模块CM设置为在虚拟化平台的域中执行。 CM为vM2ME和3GPP网络之间的通信提供了一个端点。 用户身份模块被安装为与CM一起执行,订户身份模块包括用户的3GPP身份,安全数据和用于通过3GPP网络访问vM2ME的功能。

    VIRTUAL MACHINE MIGRATION USING 3GPP MCIM
    5.
    发明申请
    VIRTUAL MACHINE MIGRATION USING 3GPP MCIM 有权
    使用3GPP MCIM进行虚拟机移动

    公开(公告)号:US20140325515A1

    公开(公告)日:2014-10-30

    申请号:US14368360

    申请日:2011-12-29

    IPC分类号: G06F9/455

    CPC分类号: G06F9/45533 G06F9/4856

    摘要: A method of migrating a virtual machine comprises a first manager, managing a first computing environment (such as a computing cloud), initiates migration of a virtual machine currently executing on a first vM2ME (virtual machine-to-machine equipment) in the first computing environment to a second computing environment (such as another computing cloud). Once the VM has migrated, the first manager disables execution of the first vM2ME.

    摘要翻译: 迁移虚拟机的方法包括:管理第一计算环境(例如计算云)的第一管理器,在第一计算中启动当前在第一vM2ME(虚拟机对机器设备)上执行的虚拟机的迁移 环境到第二计算环境(例如另一计算云)。 VM迁移之后,第一个管理员将禁用第一个vM2ME的执行。

    Remote provisioning of 3GPP downloadable subscriber identity module for virtual machine applications
    6.
    发明授权
    Remote provisioning of 3GPP downloadable subscriber identity module for virtual machine applications 有权
    用于虚拟机应用的3GPP可下载的用户识别模块的远程配置

    公开(公告)号:US09549321B2

    公开(公告)日:2017-01-17

    申请号:US14369538

    申请日:2011-12-29

    摘要: A method is presented of providing a subscriber identity for the provision of services on behalf of the subscriber in a virtual computing environment. The method includes receiving a request to establish an execution environment for a virtual machine-to-machine equipment, vM2 M E. The vM2ME is provided, comprising software for execution in the virtual computing environment and a downloadable Subscriber Identity Module. A Communications Module, CM, is set up for execution in a domain of a virtualization platform. The CM provides an end-point for communications between the vM2ME and a 3GPP network. The Subscriber Identity Module is installed for execution together with the CM, the Subscriber Identity Module including a 3GPP identity of the subscriber, security data and functions for enabling access to the vM2ME via the 3GPP network.

    摘要翻译: 提出了一种提供用于在虚拟计算环境中代表用户提供服务的订户身份的方法。 该方法包括接收建立用于虚拟机对机器设备vM2M E的执行环境的请求。提供vM2ME,其包括用于在虚拟计算环境中执行的软件和可下载的订户身份模块。 通信模块CM设置为在虚拟化平台的域中执行。 CM为vM2ME和3GPP网络之间的通信提供了一个端点。 用户身份模块被安装为与CM一起执行,订户身份模块包括用户的3GPP身份,安全数据和用于通过3GPP网络访问vM2ME的功能。

    Method for Detection of Persistent Malware on a Network Node
    7.
    发明申请
    Method for Detection of Persistent Malware on a Network Node 有权
    网络节点上持久性恶意软件检测方法

    公开(公告)号:US20150180898A1

    公开(公告)日:2015-06-25

    申请号:US14363484

    申请日:2012-04-02

    IPC分类号: H04L29/06 H04L12/26

    摘要: The present invention relates to methods and devices for detecting persistency of a first network node (12). In a first aspect of the invention, a method is provided comprising the steps of monitoring (S101), during a specified observation period, whether the first network node has established a connection to a second network node (13), and determining (S102) a total number of sessions of connectivity occurring during said specified observation period in which the first network node connects to the second network node. Further, the method comprises the steps of determining (S103), from the total number of sessions, a number of sessions comprising at least one communication flow between the first network node and the second network node, and determining (S104) inter-session persistence of the first network node on the basis of the total number of sessions and the number of sessions comprising at least one communication flow.

    摘要翻译: 本发明涉及用于检测第一网络节点(12)的持续性的方法和设备。 在本发明的第一方面中,提供了一种方法,包括以下步骤:在指定的观察期间,监视(S101)第一网络节点是否建立了与第二网络节点(13)的连接,并确定(S102) 在第一网络节点连接到第二网络节点的所述指定观察期期间发生的连接会话的总数。 此外,该方法包括以下步骤:从总会话数量确定(S103)包括第一网络节点和第二网络节点之间的至少一个通信流的会话数量,并且确定(S104)会话间持续性 基于会话的总数和包括至少一个通信流的会话的数量的第一网络节点。

    Method for detection of persistent malware on a network node
    8.
    发明授权
    Method for detection of persistent malware on a network node 有权
    在网络节点上检测持久性恶意软件的方法

    公开(公告)号:US09380071B2

    公开(公告)日:2016-06-28

    申请号:US14363484

    申请日:2012-04-02

    摘要: The present invention relates to methods and devices for detecting persistency of a first network node (12). In a first aspect of the invention, a method is provided comprising the steps of monitoring (S101), during a specified observation period, whether the first network node has established a connection to a second network node (13), and determining (S102) a total number of sessions of connectivity occurring during said specified observation period in which the first network node connects to the second network node. Further, the method comprises the steps of determining (S103), from the total number of sessions, a number of sessions comprising at least one communication flow between the first network node and the second network node, and determining (S104) inter-session persistence of the first network node on the basis of the total number of sessions and the number of sessions comprising at least one communication flow.

    摘要翻译: 本发明涉及用于检测第一网络节点(12)的持续性的方法和设备。 在本发明的第一方面中,提供了一种方法,包括以下步骤:在指定的观察期间,监视(S101)第一网络节点是否建立了与第二网络节点(13)的连接,并且确定(S102) 在第一网络节点连接到第二网络节点的所述指定观察期期间发生的连接会话的总数。 此外,该方法包括以下步骤:从总会话数量确定(S103)包括第一网络节点和第二网络节点之间的至少一个通信流的会话数,并且确定(S104)会话间持续性 基于会话的总数和包括至少一个通信流的会话的数量的第一网络节点。

    Network Based Local Mobility Management
    9.
    发明申请
    Network Based Local Mobility Management 审中-公开
    基于网络的本地移动管理

    公开(公告)号:US20100177698A1

    公开(公告)日:2010-07-15

    申请号:US12664608

    申请日:2007-06-14

    IPC分类号: H04W8/02

    CPC分类号: H04W80/04 H04W88/182

    摘要: A network comprises a NetLMM domain having at least one Host Identity Protocol proxy coupled to one or more Access Points for communicating with a Mobile Node and acting, in use, as an Access Router for the NetLMM domain. Use of an HIP proxy as an Access Router allows the Access Router itself to be mobile. Furthermore, the Access Router can reside in IPv4 networks, and can even be behind NAT boxes located between the Access Router and a Local Mobility Anchor to which the Access Router is registered. The invention may be applied using a hierarchical architecture in which each domain comprises a respective Local Mobility Anchor coupled to each HIP proxy acting as an Access Router in the domain. The Local Mobility Anchor of a domain may itself be an HIP Local Mobility Anchor. Alternatively, the HIP proxies in a domain may be arranged in a distributed manner.

    摘要翻译: 网络包括具有耦合到一个或多个接入点的至少一个主机身份协议代理的NetLMM域,用于与移动节点进行通信,并在使用中作为NetLMM域的接入路由器。 使用HIP代理作为访问路由器允许访问路由器本身是移动的。 此外,接入路由器可以驻留在IPv4网络中,甚至可以位于接入路由器和接入路由器注册的本地移动锚点之间的NAT框之后。 可以使用分层架构来应用本发明,其中每个域包括耦合到在域中用作接入路由器的每个HIP代理的相应的本地移动性锚点。 域的本地移动锚本身可能是HIP本地移动锚点。 或者,域中的HIP代理可以以分布式方式排列。

    Verifying a message in a communication network
    10.
    发明授权
    Verifying a message in a communication network 有权
    验证通信网络中的消息

    公开(公告)号:US08601604B2

    公开(公告)日:2013-12-03

    申请号:US12991542

    申请日:2008-05-13

    IPC分类号: H04N7/16

    摘要: A method and apparatus for verifying a request for service in a communication network. An authentication node generates a secret and transmits the secret to a node providing a service. The authentication node then receives a request for authentication from a requesting node, and once the requesting node is authenticated, the authorization node sends an identifier for the requesting node and a first token, which is derived using the secret and the identifier. A service providing node subsequently receives a request for service from the requesting node, the request including the identifier for the requesting node and the first token. The service providing node derives a second token using the identifier and the secret. If the first token and the second token match, then the service providing node allows the request, and if the first token and the second token do not match, then the request is refused.

    摘要翻译: 一种用于在通信网络中验证服务请求的方法和装置。 认证节点生成秘密,并将秘密发送给提供服务的节点。 认证节点然后从请求节点接收认证请求,并且一旦请求节点被认证,授权节点就发送用于请求节点的标识符和使用秘密和标识符导出的第一令牌。 服务提供节点随后从请求节点接收服务请求,该请求包括请求节点和第一令牌的标识符。 服务提供节点使用标识符和秘密导出第二个令牌。 如果第一令牌和第二令牌匹配,则服务提供节点允许请求,并且如果第一令牌和第二令牌不匹配,则该请求被拒绝。