Apparatus and method for configuring data plane behavior on network forwarding elements
    1.
    发明授权
    Apparatus and method for configuring data plane behavior on network forwarding elements 失效
    在网络转发元素上配置数据平面行为的装置和方法

    公开(公告)号:US07646759B2

    公开(公告)日:2010-01-12

    申请号:US10338291

    申请日:2003-01-07

    IPC分类号: H04L12/28

    摘要: A method and apparatus for configuring data plane behavior on network forwarding elements are described. In one embodiment, the method includes receiving, within a network element control plane, protocol configuration information extracted from a protocol application utilizing a network protocol application programming interface (API). Once the protocol configuration information is received, the protocol configuration information is processed using a control interface corresponding to the network protocol implemented by the protocol application. Once the protocol configuration information is processed, the control interface programs one or more data plane forwarding elements of the network element according to protocol configuration information. Accordingly, by providing similar control interfaces for multiple, network protocols, inter-operability between components from multiple vendors is enabled.

    摘要翻译: 描述了一种用于在网络转发元件上配置数据平面行为的方法和装置。 在一个实施例中,该方法包括在网络元件控制平面内接收使用网络协议应用编程接口(API)从协议应用中提取的协议配置信息。 一旦接收到协议配置信息,使用与由协​​议应用实现的网络协议相对应的控制接口处理协议配置信息。 一旦处理了协议配置信息,控制接口根据协议配置信息对网元的一个或多个数据平面转发元素进行编程。 因此,通过为多个网络协议提供类似的控制接口,可以实现来自多个供应商的组件之间的互操作性。

    Method and apparatus for secured embedded device communication
    2.
    发明授权
    Method and apparatus for secured embedded device communication 有权
    用于安全嵌入式设备通信的方法和装置

    公开(公告)号:US08949598B2

    公开(公告)日:2015-02-03

    申请号:US13334643

    申请日:2011-12-22

    IPC分类号: H04L29/04 H04L9/32 H04L29/06

    摘要: In a computing device that includes a host operating system and a management engine separate from the host operating system, if the primary operating system is not operating, a management engine may obtain from a credential server via a first network connection logon information for a secured network and the management engine connects to the secure network through a secured connection using the logon information. If the operating system is operating the operating system provides the logon information to the management engine. Certificate verification may be performed by a remote server on behalf of the management engine. Other embodiments are disclosed and claimed.

    摘要翻译: 在包括与主机操作系统分离的主机操作系统和管理引擎的计算设备中,如果主操作系统不工作,则管理引擎可以经由用于安全网络的第一网络连接登录信息从证书服务器获得 并且管理引擎通过使用登录信息的安全连接连接到安全网络。 如果操作系统正在操作,操作系统会向管理引擎提供登录信息。 证书验证可以由远程服务器代表管理引擎执行。 公开和要求保护其他实施例。

    SANDBOXING FOR MULTI-TENANCY
    3.
    发明申请
    SANDBOXING FOR MULTI-TENANCY 审中-公开
    多伦多沙发

    公开(公告)号:US20130160115A1

    公开(公告)日:2013-06-20

    申请号:US13330682

    申请日:2011-12-20

    IPC分类号: G06F11/00

    摘要: Systems and methods according to various embodiments disclose a worker process manager adapted to spawn one or more worker processes on a server and to load an application on each of the worker processes. The worker process manager is adapted to isolate the one or more worker processes from each other and to control resource usage by the worker processes. A resource manager is adapted to detect applications that overuse system resources. The worker process manager is adapted to isolate worker processes and to control resource usage using one or more of the following techniques: least-privilege execution, messaging isolation, credentials isolation, data isolation, network isolation, fair share resource usage, and managed runtime security. Heuristic algorithms are used to detect applications that frequently overuse system resources that are unchargeable and that cause system unresponsiveness.

    摘要翻译: 根据各种实施例的系统和方法公开了适于在服务器上产生一个或多个工作进程并且在每个工作进程上加载应用程序的工作进程管理器。 工作进程管理器适于将一个或多个工作进程彼此隔离并且控制工作进程的资源使用。 资源管理器适用于检测过度使用系统资源的应用程序。 工作进程管理器适用于使用以下一种或多种技术来隔离工作进程并控制资源使用:最小权限执行,消息传递隔离,凭据隔离,数据隔离,网络隔离,公平共享资源使用以及受管理的运行时安全性 。 启发式算法用于检测经常过度使用不可充电的系统资源并导致系统无响应的应用程序。

    Method and apparatus for secured embedded device communication
    4.
    发明授权
    Method and apparatus for secured embedded device communication 有权
    用于安全嵌入式设备通信的方法和装置

    公开(公告)号:US08091123B2

    公开(公告)日:2012-01-03

    申请号:US12059354

    申请日:2008-03-31

    IPC分类号: G06F17/00 G06F17/30

    摘要: In a computing device that includes a host operating system and a management engine separate from the host operating system, if the primary operating system is not operating, a management engine may obtain from a credential server via a first network connection logon information for a secured network and the management engine connects to the secure network through a secured connection using the logon information. If the operating system is operating the operating system provides the logon information to the management engine. Certificate verification may be performed by a remote server on behalf of the management engine. Other embodiments are disclosed and claimed.

    摘要翻译: 在包括与主机操作系统分离的主机操作系统和管理引擎的计算设备中,如果主操作系统不工作,则管理引擎可以经由用于安全网络的第一网络连接登录信息从证书服务器获得 并且管理引擎通过使用登录信息的安全连接连接到安全网络。 如果操作系统正在操作,操作系统会向管理引擎提供登录信息。 证书验证可以由远程服务器代表管理引擎执行。 公开和要求保护其他实施例。

    Method for secure device discovery and introduction
    5.
    发明授权
    Method for secure device discovery and introduction 有权
    安全设备发现和介绍的方法

    公开(公告)号:US08001584B2

    公开(公告)日:2011-08-16

    申请号:US11241589

    申请日:2005-09-30

    IPC分类号: H04L9/32

    摘要: A first message is transmitted over a communication channel to initiate a transaction. The first message contains a random number and a public key of a device. Continuing the transaction, a second message is received. The second message also contains a random number and a public key of a second device. At least one message is received that contains a proof-of-possession of the device's password, along with a credential that is encrypted with a credential key.

    摘要翻译: 通过通信信道发送第一消息以发起交易。 第一个消息包含一个设备的随机数和公钥。 继续交易,收到第二条消息。 第二个消息还包含第二个设备的随机数和公钥。 接收到至少一个包含设备密码证明的消息,以及使用证书密钥加密的证书。

    Multi-tenant, high-density container service for hosting stateful and stateless middleware components
    7.
    发明授权
    Multi-tenant, high-density container service for hosting stateful and stateless middleware components 有权
    多租户,高密度容器服务,用于托管状态和无状态的中间件组件

    公开(公告)号:US08468548B2

    公开(公告)日:2013-06-18

    申请号:US12972411

    申请日:2010-12-17

    IPC分类号: G06F13/00

    CPC分类号: G06F9/5061

    摘要: A container service is capable of hosting large numbers of middleware components for multiple tenants. A central container manager controls a plurality of compute nodes. The central container manager receives middleware components from external devices or services and assigns the components to containers on one or more designated compute nodes. Each compute node has a container management agent and one or more containers. The container management agents activate and manage the appropriate number of containers to run the assigned middleware components. The container management agent assigns each container on its compute node a limited set of privileges to control access to shared resources. The central container manager and each node's container management agent monitor container load levels and dynamically adjust the placement of the middleware components to maintain balanced operation. The compute nodes are grouped into clusters based upon the type of middleware components hosted on each compute node.

    摘要翻译: 容器服务能够为多个租户托管大量的中间件组件。 中央容器管理器控制多个计算节点。 中央容器管理器从外部设备或服务器接收中间件组件,并将组件分配给一个或多个指定的计算节点上的容器。 每个计算节点都有一个容器管理代理和一个或多个容器。 容器管理代理激活并管理适当数量的容器以运行分配的中间件组件。 容器管理代理在其计算节点上分配有限的一组权限以控制对共享资源的访问。 中央集装箱管理员和每个节点的集装箱管理代理监控集装箱装载水平,动态调整中间件组件的位置,保持平衡运行。 基于每个计算节点上托管的中间件组件的类型,将计算节点分组为集群。

    Apparatus and methods useful for monitoring intraocular pressure
    9.
    发明申请
    Apparatus and methods useful for monitoring intraocular pressure 审中-公开
    用于监测眼内压的装置和方法

    公开(公告)号:US20060281986A1

    公开(公告)日:2006-12-14

    申请号:US11149581

    申请日:2005-06-09

    IPC分类号: A61B3/16

    CPC分类号: A61B3/16

    摘要: Apparatus useful in sensing intraocular pressure are provided. The apparatus generally include a rigid tube defining a hollow through space sized and adapted to allow a flexible catheter of a pressure sensor or transducer used to sense IOP to pass in or in fluid communication with the hollow through space. The apparatus includes stabilizing structure for facilitating fixing of the tube in a desired position or angular orientation within the eye. The present apparatus more effectively maintains the position or angle of the flexible catheter or distal end portion of the pressure sensor or in the eye relative to a similar pressure sensor transducer including a flexible catheter without the rigid tube and/or without the stabilizing structure.

    摘要翻译: 提供了用于感测眼内压的装置。 该装置通常包括限定中空通过空间的刚性管,其大小适于允许用于感测IOP的压力传感器或换能器的柔性导管进入或与中空通过空间流体连通。 该装置包括稳定结构,以便于将管固定在眼睛内的期望位置或角度取向。 本装置相对于包括没有刚性管的柔性导管和/或不具有稳定结构的类似的压力传感器换能器,更有效地维持柔性导管或压力传感器的远端部分或眼睛中的位置或角度。