Method and apparatus for high-speed processing of structured application messages in a network device
    3.
    发明授权
    Method and apparatus for high-speed processing of structured application messages in a network device 有权
    用于在网络设备中高速处理结构化应用消息的方法和装置

    公开(公告)号:US08549171B2

    公开(公告)日:2013-10-01

    申请号:US11089794

    申请日:2005-03-24

    IPC分类号: G06F15/173

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for high-speed processing of structured application messages in a network device. According to one aspect, a network device receives a set of message classification rules that have been prepared beforehand by a system administrator or customer. The system analyzes the message classification rules to determine what part(s) of the message are necessary to classify a message according to the message classification rules. This allows the system to consider only the relevant parts of the message and ignore the rest of the message. The system extracts the portion of the message necessary for classifying the message and classifies the message using the values of the extracted information and the message classification rules. A unique sequence of operations is implied by the message classification and those operations must then be applied to the message.

    摘要翻译: 公开了一种用于在网络设备中高速处理结构化应用消息的方法。 根据一个方面,网络设备接收由系统管理员或客户预先准备的一组消息分类规则。 系统分析消息分类规则,以根据消息分类规则确定消息的哪些部分是必要的,以对消息进行分类。 这允许系统仅考虑消息的相关部分,并忽略消息的其余部分。 系统提取消息分类所需的部分,并使用提取的信息和消息分类规则的值对消息进行分类。 消息分类暗示了唯一的操作序列,然后必须将这些操作应用于消息。

    Performing Message Payload Processing Functions In A Network Element On Behalf Of An Application
    5.
    发明申请
    Performing Message Payload Processing Functions In A Network Element On Behalf Of An Application 有权
    在应用程序的网络元素中执行消息有效负载处理功能

    公开(公告)号:US20110208867A1

    公开(公告)日:2011-08-25

    申请号:US13100144

    申请日:2011-05-03

    IPC分类号: G06F15/16

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element intercepts data packets comprising network layer or transport layer headers having an address of a destination which destination differs from the network element. The network element determines whether information contained in layer 2-4 headers of the data packet satisfies specified criteria. If the information satisfies the specified criteria, the network element directs the data packets to a blade of the network element that performs processing based on an application layer message at least partially contained in the data packets. If the information does not satisfy the specified criteria, the network element forwards the data packets towards the destination without sending them to the blade.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件拦截包括网络层或传输层报头的数据分组,其具有目的地与网络元素不同的目的地地址。 网元确定包含在数据包的第2-4层头中的信息是否满足指定的标准。 如果信息满足指定的标准,则网络元件将数据分组引导到基于至少部分地包含在数据分组中的应用层消息执行处理的网元的叶片。 如果信息不符合规定的标准,则网络单元将数据包转发到目的地,而不将其发送到刀片。

    Performing message payload processing functions in a network element on behalf of an application
    6.
    发明授权
    Performing message payload processing functions in a network element on behalf of an application 有权
    代表应用程序在网络元素中执行消息有效负载处理功能

    公开(公告)号:US08312148B2

    公开(公告)日:2012-11-13

    申请号:US13100144

    申请日:2011-05-03

    IPC分类号: G06F15/16

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element intercepts data packets comprising network layer or transport layer headers having an address of a destination which destination differs from the network element. The network element determines whether information contained in layer 2-4 headers of the data packet satisfies specified criteria. If the information satisfies the specified criteria, the network element directs the data packets to a blade of the network element that performs processing based on an application layer message at least partially contained in the data packets. If the information does not satisfy the specified criteria, the network element forwards the data packets towards the destination without sending them to the blade.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件拦截包括网络层或传输层报头的数据分组,其具有目的地与网络元素不同的目的地地址。 网元确定包含在数据包的第2-4层头中的信息是否满足指定的标准。 如果信息满足指定的标准,则网络元件将数据分组引导到基于至少部分地包含在数据分组中的应用层消息执行处理的网元的叶片。 如果信息不符合规定的标准,则网络单元将数据包转发到目的地,而不将其发送到刀片。

    Performing message payload processing functions in a network element on behalf of an application
    7.
    发明申请
    Performing message payload processing functions in a network element on behalf of an application 有权
    代表应用程序在网络元素中执行消息有效负载处理功能

    公开(公告)号:US20060123467A1

    公开(公告)日:2006-06-08

    申请号:US11005978

    申请日:2004-12-06

    IPC分类号: H04L9/32

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element receives user-specified input that indicates a particular message classification. The network element also receives one or more data packets. Based on the data packets, the network element determines that an application layer message, which is collectively contained in payload portions of the data packets, matches the particular message classification. The network element processes at least a portion of the message by performing, on behalf of the application to which the message is directed, and relative to at least the portion of the message, one or more actions that are (a) specified in the user-specified input and (b) associated with the particular message classification.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件接收指示特定消息分类的用户指定的输入。 网元还接收一个或多个数据包。 基于数据分组,网元确定在数据分组的有效载荷部分中共同包含的应用层消息与特定消息分类相匹配。 网络元件通过代表消息所针对的应用程序并相对于消息的至少一部分执行一个或多个动作(a)在用户中指定的处理消息的至少一部分 指定的输入和(b)与特定消息分类相关联。

    Performing message payload processing functions in a network element on behalf of an application
    8.
    发明授权
    Performing message payload processing functions in a network element on behalf of an application 有权
    代表应用程序在网络元素中执行消息有效负载处理功能

    公开(公告)号:US07987272B2

    公开(公告)日:2011-07-26

    申请号:US11005978

    申请日:2004-12-06

    IPC分类号: G06F15/16

    CPC分类号: H04L51/00 G06F9/546 H04L69/08

    摘要: A method is disclosed for performing message payload processing functions in a network element on behalf of an application. According to one aspect, a network element receives user-specified input that indicates a particular message classification. The network element also receives one or more data packets. Based on the data packets, the network element determines that an application layer message, which is collectively contained in payload portions of the data packets, matches the particular message classification. The network element processes at least a portion of the message by performing, on behalf of the application to which the message is directed, and relative to at least the portion of the message, one or more actions that are (a) specified in the user-specified input and (b) associated with the particular message classification.

    摘要翻译: 公开了一种代表应用程序在网络元件中执行消息有效载荷处理功能的方法。 根据一个方面,网络元件接收指示特定消息分类的用户指定的输入。 网元还接收一个或多个数据包。 基于数据分组,网元确定在数据分组的有效载荷部分中共同包含的应用层消息与特定消息分类相匹配。 网络元件通过代表消息所针对的应用程序并相对于消息的至少一部分执行一个或多个动作(a)在用户中指定的处理消息的至少一部分 指定的输入和(b)与特定消息分类相关联。

    Performing security functions on a message payload in a network element
    9.
    发明授权
    Performing security functions on a message payload in a network element 有权
    在网络元素中的消息有效载荷上执行安全功能

    公开(公告)号:US07496750B2

    公开(公告)日:2009-02-24

    申请号:US11007421

    申请日:2004-12-07

    IPC分类号: H04L29/00

    摘要: Techniques are provided for performing security functions on a message payload in a network element. According to one aspect, a network element receives one or more data packets. The network element performs a security function on at least a portion of an application layer message that is contained in one or more payload portions of the one or more data packets. According to another aspect, a network element receives a first request that is destined for a first application. The network element sends, to a second application that sent the first request, a second request for authentication information. The network element receives the authentication information and determines whether the authentication information is valid. If the authentication information is not valid, then the network element prevents the first request from being sent to the first application.

    摘要翻译: 提供了用于在网络元件中的消息有效载荷上执行安全功能的技术。 根据一个方面,网络元件接收一个或多个数据分组。 网络元件对包含在一个或多个数据分组的一个或多个有效载荷部分中的应用层消息的至少一部分执行安全功能。 根据另一方面,网络元件接收注定用于第一应用的第一请求。 网元向发送第一请求的第二应用发送认证信息的第二请求。 网元接收认证信息,判断认证信息是否有效。 如果认证信息无效,则网络元件防止将第一请求发送到第一应用。

    Performing security functions on a message payload in a network element
    10.
    发明申请
    Performing security functions on a message payload in a network element 有权
    在网络元素中的消息有效载荷上执行安全功能

    公开(公告)号:US20060123226A1

    公开(公告)日:2006-06-08

    申请号:US11007421

    申请日:2004-12-07

    IPC分类号: H04L9/00

    摘要: A method is disclosed for performing security functions on a message payload in a network element. According to one aspect, a network element receives one or more data packets. The network element performs a security function on at least a portion of an application layer message that is contained in one or more payload portions of the one or more data packets. According to another aspect, a network element receives a first request that is destined for a first application. The network element sends, to a second application that sent the first request, a second request for authentication information. The network element receives the authentication information and determines whether the authentication information is valid. If the authentication information is not valid, then the network element prevents the first request from being sent to the first application.

    摘要翻译: 公开了一种用于在网络元件中的消息有效载荷上执行安全功能的方法。 根据一个方面,网络元件接收一个或多个数据分组。 网络元件对包含在一个或多个数据分组的一个或多个有效载荷部分中的应用层消息的至少一部分执行安全功能。 根据另一方面,网络元件接收注定用于第一应用的第一请求。 网元向发送第一请求的第二应用发送认证信息的第二请求。 网元接收认证信息,判断认证信息是否有效。 如果认证信息无效,则网络元件防止将第一请求发送到第一应用。