Method And System For Restricting Access To User Resources
    1.
    发明申请
    Method And System For Restricting Access To User Resources 有权
    限制用户资源访问的方法和系统

    公开(公告)号:US20120297460A1

    公开(公告)日:2012-11-22

    申请号:US13480439

    申请日:2012-05-24

    IPC分类号: G06F21/00

    摘要: A user's set top box (STB), or other client, executes a shell and has an application program interface (API) by which certain features of the client can be controlled. The client is in communication with a walled garden proxy server (WGPS). The client sends a request to the WGPS to access a service provided by a site in the garden. The site sends the client a message containing code calling a function in the API. The WGPS traps the message from the site and looks up the site in a table to determine the access control list (ACL) for the site. The WGPS includes the ACL in the header of the hypertext transport protocol (HTTP) message to the client. The shell receives the message and extracts the ACL. If the code lacks permission, the shell stops execution.

    摘要翻译: 用户的机顶盒(STB)或其他客户端执行外壳,并具有可以控制客户端的某些功能的应用程序接口(API)。 客户端与墙壁花园代理服务器(WGPS)进行通信。 客户向WGPS发送请求,以访问由花园中的站点提供的服务。 该站点向客户端发送一个包含在API中调用函数的代码的消息。 WGPS从站点中捕获消息,并在表中查找站点,以确定站点的访问控制列表(ACL)。 WGPS在客户端的超文本传输​​协议(HTTP)消息头中包含ACL。 shell接收消息并提取ACL。 如果代码缺少权限,shell将停止执行。

    Delivering Multimedia Services
    2.
    发明申请
    Delivering Multimedia Services 有权
    提供多媒体服务

    公开(公告)号:US20110029642A1

    公开(公告)日:2011-02-03

    申请号:US12901194

    申请日:2010-10-08

    申请人: Milo S. Medin

    发明人: Milo S. Medin

    IPC分类号: G06F15/16

    摘要: Disclosed is a scalable, hierarchical, distributed network architecture and processes for the delivery of high-performance, end-to-end online multimedia services, including Internet services such as World Wide Web access. The network architecture connects a high-speed private backbone to multiple network access points of the Internet, to a network operation center, to a back office system, and to multiple regional servers in regional data centers. Each of the regional servers connects to several caching servers in modified head-ends, which in turn connect via fiber optics to many neighborhood nodes. Finally, each node connects via coaxial cable to multiple end-user systems. The processes include those for replicating and caching frequently-accessed content, and multicasting content customized per region or locality.

    摘要翻译: 公开了一种可扩展的分层式分布式网络架构,并提供高性能端到端在线多媒体服务(包括万维网访问等互联网服务)的流程。 网络架构将高速专用骨干网连接到互联网的多个网络接入点,网络操作中心,后台系统以及区域数据中心的多个区域服务器。 每个区域服务器都连接到几个具有修改头端的缓存服务器,后者又通过光纤连接到许多邻居节点。 最后,每个节点通过同轴电缆连接到多个终端用户系统。 这些过程包括用于复制和缓存经常访问的内容的过程,以及针对每个区域或地区定制的多播内容。

    Method and System for Restricting Access to User Resources
    3.
    发明申请
    Method and System for Restricting Access to User Resources 有权
    限制用户资源访问的方法和系统

    公开(公告)号:US20110023117A1

    公开(公告)日:2011-01-27

    申请号:US12901081

    申请日:2010-10-08

    IPC分类号: G06F15/173 G06F21/00

    摘要: A user's set top box (STB), or other client, executes a shell and has an application program interface (API) by which certain features of the client can be controlled. The client is in communication with a walled garden proxy server (WGPS), which controls access to a walled garden. The walled garden contains links to one or more servers providing network-based services. The client sends a request to the WGPS to access a service provided by a site in the garden. To provide the service, the site sends the client a message containing code calling a function in the API. The WGPS traps the message from the site and looks up the site in a table to determine the access control list (ACL) for the site. The ACL is a bit-map that specifies which functions of the client's API can be invoked by code from the site. The WGPS includes the ACL in the header of the hypertext transport protocol (HTTP) message to the client. The shell receives the message and extracts the ACL. The shell uses the ACL to determine whether the code has permission to execute any called functions in the API. If the code lacks permission, the shell stops execution and sends a message to the site indicating that the site lacks permission. Otherwise, the shell allows the code to call the function.

    摘要翻译: 用户的机顶盒(STB)或其他客户端执行外壳,并具有可以控制客户端的某些功能的应用程序接口(API)。 客户端与墙壁花园代理服务器(WGPS)进行通信,该服务器控制访问有围墙的花园。 围墙花园包含提供基于网络的服务的一个或多个服务器的链接。 客户向WGPS发送请求,以访问由花园中的站点提供的服务。 为了提供服务,站点向客户端发送一个包含在API中调用函数的代码的消息。 WGPS从站点中捕获消息,并在表中查找站点以确定站点的访问控制列表(ACL)。 ACL是一个位图,用于指定可以通过站点的代码调用客户机API的哪些功能。 WGPS在客户端的超文本传输​​协议(HTTP)消息头中包含ACL。 shell接收到消息并提取ACL。 shell使用ACL来确定代码是否具有在API中执行任何被调用函数的权限。 如果代码缺少权限,shell将停止执行,并向站点发送一条消息,指示该站点缺少权限。 否则,shell允许代码调用该函数。

    Method and system for restricting access to user resources
    4.
    发明授权
    Method and system for restricting access to user resources 有权
    限制用户资源访问的方法和系统

    公开(公告)号:US07873737B2

    公开(公告)日:2011-01-18

    申请号:US12166088

    申请日:2008-07-01

    摘要: A user's set top box (STB), or other client, executes a shell and has an application program interface (API) by which certain features of the client can be controlled. The client is in communication with a walled garden proxy server (WGPS), which controls access to a walled garden. The walled garden contains links to one or more servers providing network-based services. The client sends a request to the WGPS to access a service provided by a site in the garden. To provide the service, the site sends the client a message containing code calling a function in the API. The WGPS traps the message from the site and looks up the site in a table to determine the access control list (ACL) for the site. The ACL is a bit-map that specifies which functions of the client's API can be invoked by code from the site. The WGPS includes the ACL in the header of the hypertext transport protocol (HTTP) message to the client. The shell receives the message and extracts the ACL. The shell uses the ACL to determine whether the code has permission to execute any called functions in the API. If the code lacks permission, the shell stops execution and sends a message to the site indicating that the site lacks permission. Otherwise, the shell allows the code to call the function.

    摘要翻译: 用户的机顶盒(STB)或其他客户端执行外壳,并具有可以控制客户端的某些功能的应用程序接口(API)。 客户端与墙壁花园代理服务器(WGPS)进行通信,该服务器控制访问有围墙的花园。 围墙花园包含提供基于网络的服务的一个或多个服务器的链接。 客户向WGPS发送请求,以访问花园中的站点提供的服务。 为了提供服务,站点向客户端发送一个包含在API中调用函数的代码的消息。 WGPS从站点中捕获消息,并在表中查找站点以确定站点的访问控制列表(ACL)。 ACL是一个位图,用于指定可以通过站点的代码调用客户机API的哪些功能。 WGPS在客户端的超文本传输​​协议(HTTP)消息头中包含ACL。 shell接收消息并提取ACL。 shell使用ACL来确定代码是否具有在API中执行任何被调用函数的权限。 如果代码缺少权限,shell将停止执行,并向站点发送一条消息,指示该站点缺少权限。 否则,shell允许代码调用该函数。

    Sharing IP network resources
    5.
    发明授权
    Sharing IP network resources 有权
    共享IP网络资源

    公开(公告)号:US08463920B2

    公开(公告)日:2013-06-11

    申请号:US11261809

    申请日:2005-10-28

    IPC分类号: G06F15/177

    摘要: A system and method for sharing access to an internet protocol (IP) network among multiple internet service providers (ISPs) uses multiprotocol label switching (MPLS). End-users are coupled to a broadband customer access network. Each end-user is also associated with at least one of the ISPs. An aggregation router interfaces the customer access network with a network backbone. The network backbone includes a border router for interfacing between the network backbone and the network of an ISP. When the border router is activated, it creates a forwarding equivalency class (FEC) corresponding to the ISP. The border router stores a label for the FEC and the interface for reaching the ISP in an FEC table. The border router advertises the label binding for the FEC to all upstream nodes. An intermediate node receiving the label binding creates its own FEC table, associates a new label with the FEC, and advertises the new label binding to its upstream nodes. The aggregation router receives and builds a FEC table containing the label bindings for all ISPs reachable over the network backbone. When the aggregation router receives a data packet from an end-user, the aggregation router determines the ISP associated with the end-user, labels the data packet with the label corresponding to the FEC for that ISP, and routes the packet on the network backbone. The packet eventually reaches the border router, which pops off the label and passes the packet to the ISP.

    摘要翻译: 用于在多个互联网服务提供商(ISP)之间共享对互联网协议(IP)网络的访问的系统和方法使用多协议标签交换(MPLS)。 最终用户耦合到宽带用户接入网络。 每个终端用户还与至少一个ISP相关联。 聚合路由器将客户接入网络与网络骨干网接口。 网络骨干网包括用于在网络骨干网和ISP网络之间进行接口的边界路由器。 当边界路由器被激活时,它创建与ISP对应的转发等价类(FEC)。 边界路由器存储FEC的标签和到达FEC表中的ISP的接口。 边界路由器将FEC的标签绑定通告给所有上游节点。 接收标签绑定的中间节点创建自己的FEC表,将新标签与FEC相关联,并将新标签绑定到其上游节点。 聚合路由器接收并构建一个包含通过网络骨干网到达的所有ISP的标签绑定的FEC表。 当聚合路由器收到最终用户的数据报文时,聚合路由器确定与终端用户相关联的ISP,标识与该ISP对应的FEC标签的数据报文,并将报文路由到网络骨干网 。 该分组最终到达边界路由器,该路由器弹出标签并将该分组传递给ISP。

    System and method for delivering high-performance online multimedia services
    6.
    发明授权
    System and method for delivering high-performance online multimedia services 有权
    提供高性能在线多媒体服务的系统和方法

    公开(公告)号:US07225275B2

    公开(公告)日:2007-05-29

    申请号:US10777912

    申请日:2004-02-11

    申请人: Milo S. Medin

    发明人: Milo S. Medin

    摘要: Disclosed is a scalable, hierarchical, distributed network architecture and processes for the delivery of high-performance, end-to-end online multimedia services, including Internet services such as World Wide Web access. The network architecture connects a high-speed private backbone to multiple network access points of the Internet, to a network operation center, to a back office system, and to multiple regional servers in regional data centers. Each of the regional servers connects to several caching servers in modified head-ends, which in turn connect via fiber optics to many neighborhood nodes. Finally, each node connects via coaxial cable to multiple end-user systems. The processes include those for replicating and caching frequently-accessed content, and multicasting content customized per region or locality.

    摘要翻译: 公开了一种可扩展的分层式分布式网络架构,并提供高性能端到端在线多媒体服务(包括万维网访问等互联网服务)的流程。 网络架构将高速专用骨干网连接到互联网的多个网络接入点,网络操作中心,后台系统以及区域数据中心的多个区域服务器。 每个区域服务器都连接到几个具有修改头端的缓存服务器,后者又通过光纤连接到许多邻居节点。 最后,每个节点通过同轴电缆连接到多个终端用户系统。 这些过程包括用于复制和缓存经常访问的内容的过程,以及针对每个区域或地区定制的多播内容。

    Sharing IP network resources
    7.
    发明授权

    公开(公告)号:US06985963B1

    公开(公告)日:2006-01-10

    申请号:US09645011

    申请日:2000-08-23

    IPC分类号: G06F13/00

    摘要: A system and method for sharing access to an internet protocol (IP) network among multiple internet service providers (ISPs) uses multiprotocol label switching (MPLS). End-users are coupled to a broadband customer access network. Each end-user is also associated with at least one of the ISPs. An aggregation router interfaces the customer access network with a network backbone. The network backbone includes a border router for interfacing between the network backbone and the network of an ISP. When the border router is activated, it creates a forwarding equivalency class (FEC) corresponding to the ISP. The border router stores a label for the FEC and the interface for reaching the ISP in an FEC table. The border router advertises the label binding for the FEC to all upstream nodes. An intermediate node receiving the label binding creates its own FEC table, associates a new label with the FEC, and advertises the new label binding to its upstream nodes. The aggregation router receives and builds a FEC table containing the label bindings for all ISPs reachable over the network backbone. When the aggregation router receives a data packet from an end-user, the aggregation router determines the ISP associated with the end-user, labels the data packet with the label corresponding to the FEC for that ISP, and routes the packet on the network backbone. The packet eventually reaches the border router, which pops off the label and passes the packet to the ISP.

    Delivering Multimedia Services
    8.
    发明申请
    Delivering Multimedia Services 有权
    提供多媒体服务

    公开(公告)号:US20120096118A1

    公开(公告)日:2012-04-19

    申请号:US13333958

    申请日:2011-12-21

    申请人: Milo S. Medin

    发明人: Milo S. Medin

    IPC分类号: G06F15/16

    摘要: Disclosed is a scalable, hierarchical, distributed network architecture and processes for the delivery of high-performance, end-to-end online multimedia services, including Internet services such as World Wide Web access. The network architecture connects a high-speed private backbone to multiple network access points of the Internet, to a network operation center, to a back office system, and to multiple regional servers in regional data centers. Each of the regional servers connects to several caching servers in modified head-ends, which in turn connect via fiber optics to many neighborhood nodes. Finally, each node connects via coaxial cable to multiple end-user systems. The processes include those for replicating and caching frequently-accessed content, and multicasting content customized per region or locality.

    摘要翻译: 公开了一种可扩展的分层式分布式网络架构,并提供高性能端到端在线多媒体服务(包括万维网访问等互联网服务)的流程。 网络架构将高速专用骨干网连接到互联网的多个网络接入点,网络操作中心,后台系统以及区域数据中心的多个区域服务器。 每个区域服务器都连接到几个具有修改头端的缓存服务器,后者又通过光纤连接到许多邻居节点。 最后,每个节点通过同轴电缆连接到多个终端用户系统。 这些过程包括用于复制和缓存经常访问的内容的过程,以及针对每个区域或地区定制的多播内容。

    Method and system for restricting access to user resources
    9.
    发明授权
    Method and system for restricting access to user resources 有权
    限制用户资源访问的方法和系统

    公开(公告)号:US06732179B1

    公开(公告)日:2004-05-04

    申请号:US09427778

    申请日:1999-10-26

    IPC分类号: G06F1516

    摘要: A user's set top box (STB), or other client, executes a shell and has an application programming interface (API) by which certain features of the client can be controlled. The client is in communication with a walled garden proxy server (WGPS), which controls access to a walled garden. The walled garden contains links to one or more servers providing network-based services. The client sends a request to the WGPS to access a service provided by a site in the garden. To provide the service, the site sends the client a message containing code calling a function in the API. The WGPS traps the message from the site and looks up the site in a table to determine the access control list (ACL) for the site. The ACL is a bit-map that specifies which functions of the client's API can be invoked by code from the site. The WGPS includes the ACL in the header of the hypertext transport protocol (HTTP) message to the client. The shell receives the message and extracts the ACL. The shell uses the ACL to determine whether the code has permission to execute any called functions in the API. If the code lacks permission, the shell stops execution and sends a message to the site indicating that the site lacks permission. Otherwise, the shell allows the code to call the function.

    摘要翻译: 用户的机顶盒(STB)或其他客户端执行外壳,并具有应用程序编程接口(API),通过该应用程序编程接口可以控制客户机的某些功能。 客户端与墙壁花园代理服务器(WGPS)进行通信,该服务器控制访问有围墙的花园。 围墙花园包含提供基于网络的服务的一个或多个服务器的链接。 客户向WGPS发送请求,以访问由花园中的站点提供的服务。 为了提供服务,站点向客户端发送一个包含在API中调用函数的代码的消息。 WGPS从站点中捕获消息,并在表中查找站点以确定站点的访问控制列表(ACL)。 ACL是一个位图,用于指定可以通过站点的代码调用客户机API的哪些功能。 WGPS在客户端的超文本传输​​协议(HTTP)消息头中包含ACL。 shell接收消息并提取ACL。 shell使用ACL来确定代码是否具有在API中执行任何被调用函数的权限。 如果代码缺少权限,shell将停止执行,并向站点发送一条消息,指示该站点缺少权限。 否则,shell允许代码调用该函数。

    Delivering multimedia services
    10.
    发明授权
    Delivering multimedia services 有权
    提供多媒体服务

    公开(公告)号:US07529856B2

    公开(公告)日:2009-05-05

    申请号:US11735925

    申请日:2007-04-16

    申请人: Milo S. Medin

    发明人: Milo S. Medin

    摘要: Disclosed is a scalable, hierarchical, distributed network architecture and processes for the delivery of high-performance, end-to-end online multimedia services, including Internet services such as World Wide Web access. The network architecture connects a high-speed private backbone to multiple network access points of the Internet, to a network operation center, to a back office system, and to multiple regional servers in regional data centers. Each of the regional servers connects to several caching servers in modified head-ends, which in turn connect via fiber optics to many neighborhood nodes. Finally, each node connects via coaxial cable to multiple end-user systems. The processes include those for replicating and caching frequently-accessed content, and multicasting content customized per region or locality.

    摘要翻译: 公开了一种可扩展的分层式分布式网络架构,并提供高性能端到端在线多媒体服务(包括万维网访问等互联网服务)的流程。 网络架构将高速专用骨干网连接到互联网的多个网络接入点,网络操作中心,后台系统以及区域数据中心的多个区域服务器。 每个区域服务器都连接到几个具有修改头端的缓存服务器,后者又通过光纤连接到许多邻居节点。 最后,每个节点通过同轴电缆连接到多个终端用户系统。 这些过程包括用于复制和缓存经常访问的内容的过程,以及针对每个区域或地区定制的多播内容。