Method and apparatus for policy-based network access control with arbitrary network access control frameworks
    1.
    发明授权
    Method and apparatus for policy-based network access control with arbitrary network access control frameworks 有权
    用于具有任意网络访问控制框架的基于策略的网络访问控制的方法和装置

    公开(公告)号:US08245281B2

    公开(公告)日:2012-08-14

    申请号:US11966837

    申请日:2007-12-28

    IPC分类号: G06F21/00

    CPC分类号: H04L63/20 H04L63/102

    摘要: A method and apparatus for integrating various network access control frameworks under the control of a single policy decision point (PDP). The apparatus supports pluggable protocol terminators to interface to any number of access protocols or backend support services. The apparatus contains Trust and Identity Mediators to mediate between the protocol terminators and a canonical policy subsystem, translating attributes between framework representations, and a canonical representation using extensible data-driven dictionaries.

    摘要翻译: 一种用于在单个策略决策点(PDP)的控制下集成各种网络访问控制框架的方法和装置。 该设备支持可插拔协议终结器,以连接任何数量的访问协议或后端支持服务。 该设备包含信任和身份调解员,以协调协议终结者和规范性策略子系统之间的转换,在框架表示之间翻译属性,以及使用可扩展数据驱动的字典进行规范化表示。

    Method and apparatus for policy-based network access control with arbitrary network access control frameworks
    2.
    发明授权
    Method and apparatus for policy-based network access control with arbitrary network access control frameworks 有权
    用于具有任意网络访问控制框架的基于策略的网络访问控制的方法和装置

    公开(公告)号:US08713639B2

    公开(公告)日:2014-04-29

    申请号:US13549244

    申请日:2012-07-13

    IPC分类号: H04L29/06

    CPC分类号: H04L63/20 H04L63/102

    摘要: A method and apparatus for integrating various network access control frameworks under the control of a single policy decision point (PDP). The apparatus supports pluggable protocol terminators to interface to any number of access protocols or backend support services. The apparatus contains Trust and Identity Mediators to mediate between the protocol terminators and a canonical policy subsystem, translating attributes between framework representations, and a canonical representation using extensible data-driven dictionaries.

    摘要翻译: 一种用于在单个策略决策点(PDP)的控制下集成各种网络访问控制框架的方法和装置。 该设备支持可插拔协议终结器,以连接任何数量的访问协议或后端支持服务。 该设备包含信任和身份调解员,以协调协议终结者和规范性策略子系统之间的转换,在框架表示之间翻译属性,以及使用可扩展数据驱动的字典进行规范化表示。

    METHOD AND APPARATUS FOR POLICY-BASED NETWORK ACCESS CONTROL WITH ARBITRARY NETWORK ACCESS CONTROL FRAMEWORKS
    3.
    发明申请
    METHOD AND APPARATUS FOR POLICY-BASED NETWORK ACCESS CONTROL WITH ARBITRARY NETWORK ACCESS CONTROL FRAMEWORKS 有权
    基于政策网络访问控制的方法和装置,具有仲裁网络访问控制框架

    公开(公告)号:US20130042002A1

    公开(公告)日:2013-02-14

    申请号:US13549244

    申请日:2012-07-13

    IPC分类号: G06F15/173

    CPC分类号: H04L63/20 H04L63/102

    摘要: A method and apparatus for integrating various network access control frameworks under the control of a single policy decision point (PDP). The apparatus supports pluggable protocol terminators to interface to any number of access protocols or backend support services. The apparatus contains Trust and Identity Mediators to mediate between the protocol terminators and a canonical policy subsystem, translating attributes between framework representations, and a canonical representation using extensible data-driven dictionaries.

    摘要翻译: 一种用于在单个策略决策点(PDP)的控制下集成各种网络访问控制框架的方法和装置。 该设备支持可插拔协议终结器,以连接任何数量的访问协议或后端支持服务。 该设备包含信任和身份调解员,以协调协议终结者和规范性策略子系统之间的转换,在框架表示之间翻译属性,以及使用可扩展数据驱动的字典进行规范化表示。

    METHOD AND APPARATUS FOR POLICY-BASED NETWORK ACCESS CONTROL WITH ARBITRARY NETWORK ACCESS CONTROL FRAMEWORKS
    4.
    发明申请
    METHOD AND APPARATUS FOR POLICY-BASED NETWORK ACCESS CONTROL WITH ARBITRARY NETWORK ACCESS CONTROL FRAMEWORKS 有权
    基于政策网络访问控制的方法和装置,具有仲裁网络访问控制框架

    公开(公告)号:US20080163340A1

    公开(公告)日:2008-07-03

    申请号:US11966837

    申请日:2007-12-28

    IPC分类号: H04L9/32

    CPC分类号: H04L63/20 H04L63/102

    摘要: A method and apparatus for integrating various network access control frameworks under the control of a single policy decision point (PDP). The apparatus supports pluggable protocol terminators to interface to any number of access protocols or backend support services. The apparatus contains Trust and Identity Mediators to mediate between the protocol terminators and a canonical policy subsystem, translating attributes between framework representations, and a canonical representation using extensible data-driven dictionaries.

    摘要翻译: 一种用于在单个策略决策点(PDP)的控制下集成各种网络访问控制框架的方法和装置。 该设备支持可插拔协议终结器,以连接任何数量的访问协议或后端支持服务。 该设备包含信任和身份调解员,以协调协议终结者和规范性策略子系统之间的转换,在框架表示之间翻译属性,以及使用可扩展数据驱动的字典进行规范化表示。

    METHOD FOR PROVISIONING POLICY ON USER DEVICES IN WIRED AND WIRELESS NETWORKS
    5.
    发明申请
    METHOD FOR PROVISIONING POLICY ON USER DEVICES IN WIRED AND WIRELESS NETWORKS 有权
    在有线和无线网络中为用户设备提供政策的方法

    公开(公告)号:US20080168547A1

    公开(公告)日:2008-07-10

    申请号:US11959863

    申请日:2007-12-19

    IPC分类号: G06F21/00

    摘要: A method for provisioning client devices securely and automatically by means of a network provisioning system is disclosed. Provisioning occurs before the client is granted access to the network. The provisioning is determined dynamically at the time a client connects to the network and may depend on a multitude of factors specified by data dictionaries of the provisioning system.

    摘要翻译: 公开了一种通过网络供应系统安全自动地提供客户端设备的方法。 在客户机被授予对网络的访问权限之前发生配置。 在客户端连接到网络时动态地确定供应,并且可以依赖于由供应系统的数据字典指定的多种因素。

    Method for provisioning policy on user devices in wired and wireless networks
    6.
    发明授权
    Method for provisioning policy on user devices in wired and wireless networks 有权
    在有线和无线网络中的用户设备上配置策略的方法

    公开(公告)号:US08051464B2

    公开(公告)日:2011-11-01

    申请号:US11959863

    申请日:2007-12-19

    IPC分类号: G06F7/04

    摘要: A method for provisioning client devices securely and automatically by means of a network provisioning system is disclosed. Provisioning occurs before the client is granted access to the network. The provisioning is determined dynamically at the time a client connects to the network and may depend on a multitude of factors specified by data dictionaries of the provisioning system.

    摘要翻译: 公开了一种通过网络供应系统安全自动地提供客户端设备的方法。 在客户机被授予对网络的访问权限之前发生配置。 在客户端连接到网络时动态地确定供应,并且可以依赖于由供应系统的数据字典指定的多种因素。