Method and apparatus for performing configuration over a network
    1.
    发明授权
    Method and apparatus for performing configuration over a network 有权
    用于通过网络执行配置的方法和装置

    公开(公告)号:US07366898B2

    公开(公告)日:2008-04-29

    申请号:US10679869

    申请日:2003-10-06

    IPC分类号: H04L9/00 H04L9/32

    摘要: A method and apparatus are provided for passing configuration information over a network. In one embodiment, the configuration information is passed between a DHCP server and a DHCP client and includes parameters not formally defined within DHCP. The parameters are therefore encoded into a vendor-specific portion of a DHCP message using at least one triplet comprising a code field, a length field, and a value field. The value field comprises a set of one or more name-value pairs. The code field includes an indication of encryption of the value field. In another embodiment, a fixed-function appliance device is attached to a network, and is booted using boot code and a configuration stored locally to the device. The device then downloads a network configuration, which is compared to the locally stored configuration. If the network configuration is different from the locally stored configuration, the network configuration is stored locally to the device. The device is then rebooted using the stored network configuration.

    摘要翻译: 提供了一种通过网络传递配置信息的方法和装置。 在一个实施例中,配置信息在DHCP服务器和DHCP客户端之间传递,并且包括在DHCP中没有正式定义的参数。 因此,使用至少一个包括代码字段,长度字段和值字段的三元组将参数编码到DHCP消息的供应商特定部分。 值字段包括一组一个或多个名称 - 值对。 代码字段包括值字段的加密指示。 在另一个实施例中,固定功能设备设备附接到网络,并且使用引导代码和本地存储在该设备上的配置来引导。 该设备然后下载一个网络配置,与本地存储的配置进行比较。 如果网络配置与本地存储的配置不同,则网络配置本地存储在设备上。 然后使用存储的网络配置重新启动设备。

    Method and apparatus for performing configuration over a network
    2.
    发明申请
    Method and apparatus for performing configuration over a network 有权
    用于通过网络执行配置的方法和装置

    公开(公告)号:US20050055575A1

    公开(公告)日:2005-03-10

    申请号:US10679869

    申请日:2003-10-06

    IPC分类号: G06F9/445 H04L9/00 H04L12/24

    摘要: A method and apparatus are provided for passing configuration information over a network. In one embodiment, the configuration information is passed between a DHCP server and a DHCP client and includes parameters not formally defined within DHCP. The parameters are therefore encoded into a vendor-specific portion of a DHCP message using at least one triplet comprising a code field, a length field, and a value field. The value field comprises a set of one or more name-value pairs. The code field includes an indication of encryption of the value field. In another embodiment, a fixed-function appliance device is attached to a network, and is booted using boot code and a configuration stored locally to the device. The device then downloads a network configuration, which is compared to the locally stored configuration. If the network configuration is different from the locally stored configuration, the network configuration is stored locally to the device. The device is then rebooted using the stored network configuration.

    摘要翻译: 提供了一种通过网络传递配置信息的方法和装置。 在一个实施例中,配置信息在DHCP服务器和DHCP客户端之间传递,并且包括在DHCP中没有正式定义的参数。 因此,使用至少一个包括代码字段,长度字段和值字段的三元组将参数编码到DHCP消息的供应商特定部分。 值字段包括一组一个或多个名称 - 值对。 代码字段包括值字段的加密指示。 在另一个实施例中,固定功能设备设备附接到网络,并且使用引导代码和本地存储在该设备上的配置来引导。 该设备然后下载一个网络配置,与本地存储的配置进行比较。 如果网络配置与本地存储的配置不同,则网络配置本地存储在设备上。 然后使用存储的网络配置重新启动设备。

    SECURE NETWORK IDENTITY ALLOCATION
    3.
    发明申请
    SECURE NETWORK IDENTITY ALLOCATION 审中-公开
    安全网络标识分配

    公开(公告)号:US20080025292A1

    公开(公告)日:2008-01-31

    申请号:US11834441

    申请日:2007-08-06

    IPC分类号: H04L12/66

    摘要: A computer system is connectable to a network. The computer system includes a plurality of processing units, each of the processing units being provided with a respective network identity for communication with the network. At least one service processor is operable to allocate network identities to the processing units. A switch is provided for interconnecting the processing units to the network. The switch is operable to maintain a record of the network identities allocated to the processing units by the service processor and filters network access by each processing unit such that network access is blocked where a processing unit identity does not correspond to that held by the switch. By maintaining a record of the network identities allocated to the processing units by the service processor in the switch and filtering network access, access by a processing unit that has been changed or where its network identity has otherwise changed, can be prevented, maintaining the integrity of the network.

    摘要翻译: 计算机系统可连接到网络。 计算机系统包括多个处理单元,每个处理单元被提供有用于与网络通信的相应网络身份。 至少一个服务处理器可操作以将处理单元分配网络身份。 提供用于将处理单元与网络互连的开关。 交换机可操作以维护由服务处理器分配给处理单元的网络标识的记录,并且过滤每个处理单元的网络访问,使得在处理单元标识与交换机所保持的标识不对应的情况下阻止网络访问。 通过维护由交换机中的服务处理器分配给处理单元的网络标识和过滤网络访问的记录,可以防止已被改变的处理单元或其网络身份否则改变的访问,保持完整性 的网络。

    Secure transfer of host identities
    5.
    发明申请
    Secure transfer of host identities 有权
    主机身份的安全传输

    公开(公告)号:US20050050356A1

    公开(公告)日:2005-03-03

    申请号:US10653025

    申请日:2003-08-29

    IPC分类号: H04L9/00 H04L29/06

    CPC分类号: H04L63/126

    摘要: A first host system can be configured initially with a first host identity and a second host system can be configured initially with a second host identity. A host identity can belong to only one host system at a time. An administrator system can hold an additional host identity. The administrator system can securely connect to the first host system and can pass the additional host identity to the first host system. The first host system can reconfiguring itself to use the additional host identity and can pass the first host identity to the administrator system. The administrator system can securely connect to the second host system and can pass the first host identity to the second host system. The second host system can then reconfigure itself to use the first host identity and pass the second host identity to the administrator system. In this manner the first host identity can be passed securely from the first to the host system without a risk of duplication.

    摘要翻译: 可以初始地配置第一主机系统,其具有第一主机标识,并且可以最初以第二主机标识配置第二主机系统。 主机身份一次只能属于一个主机系统。 管理员系统可以容纳另外的主机身份。 管理员系统可以安全地连接到第一主机系统并且可以将附加主机标识传递给第一主机系统。 第一个主机系统可以重新配置自己以使用额外的主机标识,并可以将第一个主机标识传递给管理员系统。 管理员系统可以安全地连接到第二主机系统,并且可以将第一主机身份传递给第二主机系统。 然后,第二主机系统可以重新配置自己以使用第一主机标识并将第二主机标识传递给管理员系统。 以这种方式,可以将第一主机身份从第一主机系统安全地传递到主机系统,而不会有重复的风险。

    Transferring system identities
    6.
    发明申请
    Transferring system identities 有权
    传输系统标识

    公开(公告)号:US20050050185A1

    公开(公告)日:2005-03-03

    申请号:US10653033

    申请日:2003-08-29

    摘要: First and second host systems can each include a respective repository of host identities. The first host system can encode a host identity to be transferred to the second host system using a parameter, for example a property of the second host system. The first host system can divulge the result of the encoding and remove the host identity from its repository. The second host system can decode the host identity to be transferred using the parameter, and can then add the host identity to be transferred to its repository.

    摘要翻译: 第一和第二主机系统可以各自包括主机身份的相应存储库。 第一主机系统可以使用参数(例如第二主机系统的属性)对要传送到第二主机系统的主机标识进行编码。 第一个主机系统可以泄露编码的结果,并从其存储库中删除主机标识。 第二个主机系统可以使用该参数对要传输的主机标识进行解码,然后可以将要传送到其存储库的主机标识相加。

    System health monitoring
    7.
    发明申请
    System health monitoring 有权
    系统健康监测

    公开(公告)号:US20050049825A1

    公开(公告)日:2005-03-03

    申请号:US10653034

    申请日:2003-08-29

    IPC分类号: G06F15/00

    CPC分类号: H04L43/0817 G06F11/0757

    摘要: Monitoring the health of a system module can be carried out during state transitioning, for example when starting or stopping a system module. A monitor module can be operationally connected to the system module. The system module can output a status signal for predetermined system status points during state transitioning. The monitor module can start a timer on detecting a first status signal and can reset the timer on detecting a subsequent status signal. The timer can indicate a failed transitioning of the system module in the event that the timer is not reset within a determined period of being reset.

    摘要翻译: 监视系统模块的运行状况可以在状态转换期间执行,例如在启动或停止系统模块时。 监视器模块可以可操作地连接到系统模块。 系统模块可以在状态转换期间输出预定系统状态点的状态信号。 监视器模块可以在检测到第一状态信号时启动定时器,并且可以在检测到后续状态信号时复位定时器。 在定时器在复位的确定时间段内不复位的情况下,定时器可以指示系统模块的故障转换。

    File server system tolerant to software and hardware failures
    8.
    发明授权
    File server system tolerant to software and hardware failures 有权
    文件服务器系统容忍软件和硬件故障

    公开(公告)号:US06367029B1

    公开(公告)日:2002-04-02

    申请号:US09185414

    申请日:1998-11-03

    IPC分类号: G06F1136

    摘要: A file server system tolerant to hardware and software failures is located over a plurality of hardware nodes. The nodes of the system act as hosts for software components of the system. Several of the software components can be replicated. The replicable software components include the system file store, a checker and a logger. The replicated components have one primary copy and one or more back-up copies. Replica copies of a given replicated component are each located at different nodes. Location and handling of replica copies of a given replicable component is under the control of a replication manager which is a (non-replicable) software component of the system. The replication manager is distributed meaning it can have one of its instances running on each node of the system. These instances inter-communicate to maintain coherence. The failure detector is also distributed, its instances running on each of the nodes, and contributing to an early detection of hardware and software failures. The file store is configured to hold stored objects and includes a signature generator for computing an object-specific signature from an object. The checker comprises a signature store for holding a previously computed signature for each of the stored objects and a comparator operable to compare a signature retrieved from the signature store with a corresponding signature computed by the signature generator from an object retrieved from the file store, thus to enhance system reliability.

    摘要翻译: 容忍硬件和软件故障的文件服务器系统位于多个硬件节点上。 系统的节点充当系统软件组件的主机。 可以复制几个软件组件。 可复制的软件组件包括系统文件存储,检查器和记录器。 复制的组件具有一个主要副本和一个或多个备份副本。 给定复制组件的副本副本各自位于不同的节点。 给定可复制组件的副本副本的位置和处理由复制管理器控制,复制管理器是系统的(不可复制的)软件组件。 复制管理器是分布式的,意味着它可以使其一个实例在系统的每个节点上运行。 这些实例相互通信以保持一致性。 故障检测器也被分布,其实例在每个节点上运行,并有助于早期检测硬件和软件故障。 文件存储被配置为保存存储的对象,并且包括用于从对象计算对象特定签名的签名生成器。 检查器包括用于保存用于每个存储对象的先前计算的签名的签名存储器,以及比较器,用于将从签名存储检索到的签名与从文件存储器检索到的对象由签名生成器计算的对应签名进行比较,从而 以提高系统的可靠性。

    Distributed switch
    9.
    发明申请
    Distributed switch 有权
    分布式交换机

    公开(公告)号:US20050063354A1

    公开(公告)日:2005-03-24

    申请号:US10653030

    申请日:2003-08-29

    CPC分类号: G11B33/126 G11B33/128

    摘要: A computer system comprises a plurality of shelves. Each shelf has a carrier for removably receiving a plurality of information processing modules and a switching module. Each shelf also has an interconnection member for providing connections between the information processing modules and the switching module. The switching modules of the respective shelves are interconnected in a logical stacking configuration to form a logical stacking arrangement.

    摘要翻译: 计算机系统包括多个货架。 每个搁架具有用于可拆卸地接收多个信息处理模块和切换模块的载体。 每个搁架还具有用于提供信息处理模块和切换模块之间的连接的互连构件。 各个搁板的交换模块以逻辑堆叠配置互连以形成逻辑堆叠布置。

    Aggregation switch
    10.
    发明申请
    Aggregation switch 有权
    聚合开关

    公开(公告)号:US20050047098A1

    公开(公告)日:2005-03-03

    申请号:US10653029

    申请日:2003-08-29

    CPC分类号: G11B33/126 G11B33/128

    摘要: A computer system comprises a plurality of shelves. Each shelf has a carrier for removably receiving a plurality of information processing modules and a switching module. Each shelf also has an interconnection member for providing connections between the information processing modules and the switching module. The shelves are logically connected into a plurality of stacks, the switching modules of the respective shelves in each stack being interconnected in a logical stacking configuration. The computer system further comprises a shelf having a carrier for removably receiving a master switching module, wherein the master switching module is connected into each stack as a common master switch for all of the stacks

    摘要翻译: 计算机系统包括多个货架。 每个搁架具有用于可拆卸地接收多个信息处理模块和切换模块的载体。 每个搁架还具有用于提供信息处理模块和切换模块之间的连接的互连构件。 搁板逻辑上连接到多个堆叠中,每个堆叠中的相应搁板的交换模块以逻辑堆叠配置互连。 计算机系统还包括具有用于可拆卸地接收主交换模块的载体的机架,其中主交换模块连接到每个堆叠中作为用于所有堆栈的公共主交换机