Virtual private network crossovers based on certificates
    1.
    发明授权
    Virtual private network crossovers based on certificates 有权
    基于证书的虚拟专用网络交换机

    公开(公告)号:US07574738B2

    公开(公告)日:2009-08-11

    申请号:US10288574

    申请日:2002-11-06

    IPC分类号: G06F15/16

    摘要: A method and system for enabling interconnection of VPNs is disclosed. An interconnection device manages an interconnection process at one or more facilities including, for example, a gateway device. The gateway device has information relating to a plurality of VPNs, and may facilitate interconnection between devices on at least two of the VPNs by determining that one device is in fact a member of a first one of the VPNs, and by forwarding connection parameters of the first VPN to the second VPN on an as-needed basis. In this way, the gateway allows interconnection without the need for a completely centralized decision-making process, and does so independently of the type of device and/or VPN(s) being used. Moreover, the gateway may implement only those VPN parameters needed by both VPNs to communicate with one another with a desired level of security, thereby simplifying the routing and forwarding processes associated with the actual communication occurring via the interconnection. The information related to the plurality of VPNs and their respective member devices may be stored in a mapping table at the gateway, and identification parameters of a device seeking interconnection and/or associated VPN parameters may be verified by the use of digital certificates.

    摘要翻译: 公开了一种实现VPN互连的方法和系统。 互连设备管理包括例如网关设备在内的一个或多个设施的互连处理。 网关设备具有与多个VPN相关的信息,并且可以通过确定一个设备实际上是VPN中的第一个的成员,并且通过转发所述VPN中的第一个VPN的连接参数来促进至少两个VPN中的设备之间的互连 第一个VPN到第二个VPN根据需要。 以这种方式,网关允许互连,而不需要完全集中的决策过程,并且独立于正在使用的设备和/或VPN的类型。 此外,网关可以仅实现两个VPN所需的VPN参数,以便以期望的安全级别彼此通信,从而简化与通过互连发生的实际通信相关联的路由和转发过程。 与多个VPN及其各自的成员设备相关的信息可以存储在网关的映射表中,并且可以通过使用数字证书来验证寻求互连和/或相关VPN参数的设备的识别参数。

    System and method for reserving a virtual connection in an IP network
    2.
    发明授权
    System and method for reserving a virtual connection in an IP network 有权
    在IP网络中预留虚拟连接的系统和方法

    公开(公告)号:US07320034B2

    公开(公告)日:2008-01-15

    申请号:US09811038

    申请日:2001-03-16

    IPC分类号: G06F15/16

    摘要: A method and system for reserving a virtual connection from a source workstation to a destination workstation. Packets of data are transmitted over a network between an ingress node of the source workstation and an egress node of the destination workstation. In accordance with the method of the present invention, a reservation request is delivered from the source workstation to a reservation server. The reservation server includes a user database for storing the identification of each user allowed to access to the reservation server and also stores the rights of each user. The reservation server further includes a network database for storing the information describing a network capacity required to set up the virtual connection. A verification is then performed to determine whether or not the reservation request may be validated in view of user information within said source workstation. A second verification is performed to determine whether or not the capacity of said network is sufficient to meet the requirements of the reservation request. In response to the capacity of the network being sufficient to meet the requirements of the reservation request, a virtual connection is established from the ingress node to the egress node.

    摘要翻译: 一种用于将虚拟连接从源工作站预留到目标工作站的方法和系统。 数据包通过源工作站的入口节点和目标工作站的出口节点之间的网络传输。 根据本发明的方法,将预留请求从源工作站传送到预约服务器。 预约服务器包括用于存储允许访问预约服务器的每个用户的标识的用户数据库,并且还存储每个用户的权限。 预约服务器还包括网络数据库,用于存储描述建立虚拟连接所需的网络容量的信息。 然后执行验证以确定预留请求是否可以根据所述源工作站内的用户信息而被验证。 执行第二验证以确定所述网络的容量是否足以满足预留请求的要求。 响应于网络的容量足以满足预留请求的要求,建立从入口节点到出口节点的虚拟连接。

    Data transmission system for reserving a virtual connection over multiple IP networks by means of a reservation
    3.
    发明授权
    Data transmission system for reserving a virtual connection over multiple IP networks by means of a reservation 失效
    数据传输系统,用于通过预留保留在多个IP网络上的虚拟连接

    公开(公告)号:US06961318B2

    公开(公告)日:2005-11-01

    申请号:US09850862

    申请日:2001-05-08

    摘要: Data transmission system for transmitting packets of data from a source workstation (10) to a destination workstation (40) wherein the packets of data are transmitted over at least a first IP network (14) and a second IP network (30) between an ingress node (20) connected to the source workstation in the first network and an egress node (38) connected to the destination workstation in the second network. The system comprises a local reservation server (26) in the first network accessible by the source workstation and a remote reservation server (42) in the second network accessible by the local reservation server. The local reservation server includes connection setup means for setting up a virtual connection meeting a predefined requirement of Quality of Service from the ingress node to the egress node in response to a request from the source workstation and bandwidth request means for requesting additional bandwidth in the second network to the remote reservation server.

    摘要翻译: 用于从源工作站(10)向目的地工作站(40)发送数据分组的数据传输系统,其中通过至少第一IP网络(14)和第二IP网络(30)在入口之间传输数据分组 连接到第一网络中的源工作站的节点(20)和连接到第二网络中的目的地工作站的出口节点(38)。 该系统包括可由源工作站访问的第一网络中的本地预约服务器(26)和由本地预约服务器可访问的第二网络中的远程预订服务器(42)。 本地预约服务器包括连接建立装置,用于响应来自源工作站的请求和带宽请求装置在第二个请求中请求附加带宽,建立满足来自入口节点到出口节点的预定服务质量要求的虚拟连接 网络到远程预留服务器。

    Priority queue management system for the transmission of data frames from a node in a network node
    4.
    发明授权
    Priority queue management system for the transmission of data frames from a node in a network node 失效
    用于从网络节点中的节点传输数据帧的优先级队列管理系统

    公开(公告)号:US06771653B1

    公开(公告)日:2004-08-03

    申请号:US09664696

    申请日:2000-09-19

    IPC分类号: H04L1254

    摘要: A system for providing prioritized queue management within a data transmission network node that supports different types of data frame traffic is disclosed herein. The system includes a frame buffer for storing an incoming frame that has an identifiable frame type. A queue is pre-associated with the frame type of the incoming frame such that upon arrival of the frame at the network node, the queue stores a location address at which the frame is stored within the frame buffer such that the frame is maintained within the queue. The queue that contains the frame is stored within a frame table. Processing means are provided for determining a time at which the queue forwards the frame from the frame buffer in accordance with a pre-determined sub-queue priority list. The system further includes time metering means associated with the frame for temporally assigning the frame to a virtual sub-queue among multiple virtual sub-queues that are associated with the queue. The sub-queues are sequentially ordered according to the predetermined sub-queue priority list such that the processing means selects a highest priority frame for forwarding from the frame buffer.

    摘要翻译: 本文公开了一种用于在支持不同类型的数据帧业务的数据传输网络节点内提供优先级队列管理的系统。 该系统包括用于存储具有可识别帧类型的传入帧的帧缓冲器。 队列与进入帧的帧类型预先关联,使得在帧到达网络节点时,队列存储帧在帧缓冲器内被存储的位置地址,使得帧保持在 队列。 包含帧的队列存储在一个帧表中。 提供处理装置,用于根据预定的子队列优先级列表确定队列从帧缓冲器转发帧的时间。 该系统还包括与帧相关联的时间计量装置,用于在与队列相关联的多个虚拟子队列之间临时地将帧分配给虚拟子队列。 子队列根据预定的子队列优先级顺序顺序排列,使得处理装置从帧缓冲器中选择用于转发的最高优先级帧。

    Method of reinitializing dictionaries in a data transmission system
using data compression
    5.
    发明授权
    Method of reinitializing dictionaries in a data transmission system using data compression 失效
    使用数据压缩在数据传输系统中重新初始化字典的方法

    公开(公告)号:US6067381A

    公开(公告)日:2000-05-23

    申请号:US67457

    申请日:1998-04-28

    IPC分类号: H03M7/30 G06K9/36 H03M7/34

    CPC分类号: H03M7/3088

    摘要: Method of reinitializing dictionaries in a data transmission system using data compression having a transmit device and a receive device, and in which strings of characters have to be transmitted in a compressed form, the transmit device having a transmit dictionary storing codewords associated with the strings of characters which are transmitted instead of the strings of characters, the receive device having a receive dictionary storing codewords associated with the strings of characters, and both dictionaries being updated each time a new string of characters has to be transmitted so that the contents of the dictionaries remain identical. This method saves at least the addresses of the parts of the transmit or receive dictionary which have to be modified by a dictionary updating operation, builds a check message based upon the contents of the transmit dictionary updated by the dictionary updating operation, transmits the check message from the transmit device to the receive device, and then deletes in both dictionaries the parts which are determined by the saved addresses in the event that the check message does not correspond to the contents of the updated receive dictionary. This enables both dictionaries to be reinitialized in an intermediate state without being reset.

    摘要翻译: 在使用具有发送设备和接收设备的数据压缩的数据传输系统中重新初始化字典的方法,并且其中字符串必须以压缩形式发送,所述发送设备具有存储与字符串相关联的码字的发送字典 发送而不是字符串的字符,接收装置具有存储与字符串相关联的码字的接收字典,并且每当必须发送新的字符串字符时,两个字典都被更新,使得字典的内容 保持相同 该方法至少存储必须通过字典更新操作修改的发送或接收字典的部分的地址,基于由字典更新操作更新的发送字典的内容构建检查消息,发送检查消息 从发送设备到接收设备,然后在两个字典中删除在检查消息不对应于更新的接收字典的内容的情况下由保存的地址确定的部分。 这使得两个字典都不会被重新初始化在中间状态。

    Time division multiplex frame slot assignment system and method for
interconnecting telephone stations on a token ring network
    6.
    发明授权
    Time division multiplex frame slot assignment system and method for interconnecting telephone stations on a token ring network 失效
    时分复用帧时隙分配系统和方法,用于在令牌环网上互连电话台

    公开(公告)号:US5751714A

    公开(公告)日:1998-05-12

    申请号:US727333

    申请日:1996-10-08

    IPC分类号: H04L12/43 H04L12/433 H04J3/12

    CPC分类号: H04L12/433 H04L12/43

    摘要: In a token ring network a periodic recirculating frame having a plurality of information carrying slots and a header section is used for enabling a plurality of telephone stations to exchange information carrying signals. The header is provided with a token which can assume one of three states. In the first state FF, a telephone station wanting to make a call, changes the token to the second state 00 and inserts call establishment information in the header. A server station also connected in the ring detects the second state as a request to establish a connection from and to a station specified in the header. The server changes the token to the third state AA and inserts a slot assignment in the header. All stations receiving a frame with a token in the third state examine the header. The calling station implies confirmation of the requested connection and the called station is made aware of the call and the identity of the caller. When this frame returns to the server the token state is set to FF and another station on the ring can request a slot for communication with another station.

    摘要翻译: 在令牌环网络中,使用具有多个信息携带时隙的周期性再循环帧和报头部分,以使多个电话台能够交换信息携带信号。 标题提供有一个可以承担三种状态之一的令牌。 在第一状态FF中,要进行呼叫的电话台将令牌改变为第二状态00,并将呼叫建立信息插入到头部中。 还连接在环中的服务器站检测到第二状态,作为与头中指定的站建立连接的请求。 服务器将令牌更改为第三个状态AA,并在标题中插入一个插槽分配。 接收具有第三状态的令牌的帧的所有站检查标题。 呼叫站意味着确认所请求的连接,并且使被叫站知道呼叫和呼叫者的身份。 当该帧返回到服务器时,令牌状态被设置为FF,并且环上的另一个站可以请求与另一站通信的时隙。

    Time-based graphic network reporting navigator
    7.
    发明授权
    Time-based graphic network reporting navigator 有权
    基于时间的图形网络报告导航器

    公开(公告)号:US08732297B2

    公开(公告)日:2014-05-20

    申请号:US12613707

    申请日:2009-11-06

    IPC分类号: G06F15/173 H04L12/24

    摘要: The presently disclosed embodiments are directed to representing network performance information using a network map by partitioning a graphical affordance representing a network element in the network map into segmented sections in accordance with a temporal encoding scheme to encode temporal information in the network map. The segmented sections are encoded using a performance encoding scheme to identify a level of performance associated with the segmented sections so that the network map depicts a performance of the network element over time.

    摘要翻译: 目前公开的实施例涉及通过使用网络地图来表示网络性能信息,所述网络地图通过根据时间编码方案将网络图中的网络元素的图形能力划分为分段部分,以对网络图中的时间信息进行编码。 分段部分使用性能编码方案进行编码,以识别与分段部分相关联的性能级别,使得网络映射描绘网络元素随时间的性能。

    Compression and encryption protocol for controlling data flow in a network
    8.
    发明授权
    Compression and encryption protocol for controlling data flow in a network 有权
    用于控制网络中的数据流的压缩和加密协议

    公开(公告)号:US06704866B1

    公开(公告)日:2004-03-09

    申请号:US09187097

    申请日:1998-11-05

    IPC分类号: H04L900

    CPC分类号: H04L63/0428

    摘要: Process for controlling frames transporting data from a transmitting Terminal (DTE 1) to at least a receiving Terminal (DTE 2) through a plurality of consecutive nodes including a start access node (NODE 1) connected to said transmitting Terminal and at least an end access node (NODE 6) connected to said receiving Terminal and intermediary nodes (NODE 2 to NODE 5), with each data frame comprising one or several protocol layers respectively associated with one or several communication protocols of controlling the frame flow at each node; such a process consisting in adding to each data frame a Data Manipulation Layer (DML) defining the parameters necessary for managing the manipulation (compression and/or encryption) of each field of the data frame located after the DML, and adding to each data frame a Control message for transporting a control protocol defining new parameters to be used by some ones nodes for managing the communication flow through the consecutive nodes.

    摘要翻译: 用于控制通过包括连接到所述发射终端的起始接入节点(NODE 1)的多个连续节点将数据从发射终端(DTE 1)传输到至少接收终端(DTE 2)的帧的过程,以及至少一个终端接入 连接到所述接收终端的节点(节点6)和中间节点(NODE 2到节点5),每个数据帧包括分别与控制每个节点处的帧流的一个或多个通信协议相关联的一个或多个协议层; 这种过程包括在每个数据帧中添加一个数据操作层(DML),该数据操作层定义了管理位于DML之后的数据帧的每个字段的操纵(压缩和/或加密)所需的参数,并且添加到每个数据帧 控制消息,用于传送定义要由某些节点使用的新参数的控制协议,用于管理通过连续节点的通信流。

    TIME-BASED GRAPHIC NETWORK REPORTING NAVIGATOR
    9.
    发明申请
    TIME-BASED GRAPHIC NETWORK REPORTING NAVIGATOR 有权
    基于时间的图形网络报告导航仪

    公开(公告)号:US20110072353A1

    公开(公告)日:2011-03-24

    申请号:US12613707

    申请日:2009-11-06

    IPC分类号: G06F15/177

    摘要: The presently disclosed embodiments are directed to representing network performance information using a network map by partitioning a graphical affordance representing a network element in the network map into segmented sections in accordance with a temporal encoding scheme to encode temporal information in the network map. The segmented sections are encoded using a performance encoding scheme to identify a level of performance associated with the segmented sections so that the network map depicts a performance of the network element over time.

    摘要翻译: 目前公开的实施例涉及通过使用网络映射来表示网络性能信息,所述网络映射通过根据时间编码方案将网络图中的网络元素的图形能力划分为分段部分,以对网络图中的时间信息进行编码。 分段部分使用性能编码方案进行编码,以识别与分段部分相关联的性能级别,使得网络图描绘网络元素随时间的性能。

    Method for validating an electronic payment by a credit/debit card
    10.
    发明授权
    Method for validating an electronic payment by a credit/debit card 有权
    通过信用卡/借记卡验证电子支付的方法

    公开(公告)号:US07769697B2

    公开(公告)日:2010-08-03

    申请号:US11530736

    申请日:2006-09-11

    IPC分类号: G06Q99/00

    摘要: A method for validating an electronic payment by a credit/debit card in a transaction system. The method includes registering a purchase of an article by a buyer using a credit/debit card associated with at least one PIN code, checking that the at least one PIN code is associated with the number of said credit/debit card provided by said buyer to said seller terminal, checking, by said electronic payment center, whether or not said at least one PIN code is valid, and one of: after the at least one PIN code is found to be valid, checking, by said electronic payment center, whether the electronic payment center has received a pre-validation from a third party; after the at least one PIN code is found to be valid, contacting a third party via a communication network and requesting that the third party validate the purchase; and after the at least one PIN code is found to be valid, contacting a third party via a communication network and requesting said at least one PIN code from the third party. The third party is a prime owner of the credit/debit card.

    摘要翻译: 一种在交易系统中通过信用卡/借记卡验证电子支付的方法。 该方法包括使用与至少一个PIN码相关联的信用卡/借记卡来注册购买商品的商品,检查所述至少一个PIN码是否与所述买方提供的所述信用卡/借记卡的数量相关联 所述卖方终端,通过所述电子支付中心检查所述至少一个PIN码是否有效,并且在所述至少一个PIN码被发现有效之后,由所述电子支付中心检查是否 电子支付中心已收到第三方的预验证; 在发现至少一个PIN码有效之后,通过通信网络与第三方联系并请求第三方验证购买; 并且在发现所述至少一个PIN码有效之后,经由通信网络与第三方联系并从所述第三方请求所述至少一个PIN码。 第三方是信用卡/借记卡的主要所有者。