SYSTEM AND METHOD FOR FORMING VIRTUAL PRIVATE NETWORK
    1.
    发明申请
    SYSTEM AND METHOD FOR FORMING VIRTUAL PRIVATE NETWORK 审中-公开
    用于形成虚拟私有网络的系统和方法

    公开(公告)号:US20110085552A1

    公开(公告)日:2011-04-14

    申请号:US12904774

    申请日:2010-10-14

    IPC分类号: H04W40/00

    摘要: Technology for forming a virtual private network (VPN) is provided. A VPN gateway that supports mobility with a connection node having a virtual home address (HoA) and a care of address (CoA) includes a mobility support unit, a data security unit, and a virtual address converter. When a packet is transferred from the connection node, the mobility support unit sustains a binding relationship between a home address (HoA) of the connection node and the changed CoA, and processes a mobility tunnel for the packet, thereby generating a first conversion packet. The data security unit performs a security test of the first conversion packet. The virtual address converter converts the HoA of the connection node, which is a source address of the first conversion packet in which the security test is complete, to a private network internal address that can be used in the VPN, thereby generating a second conversion packet.

    摘要翻译: 提供了形成虚拟专用网(VPN)技术。 支持具有虚拟归属地址(HoA)和托管地址(CoA)的连接节点的移动性的VPN网关包括移动性支持单元,数据安全单元和虚拟地址转换器。 当从连接节点传送分组时,移动性支持单元维持连接节点的归属地址(HoA)与改变的CoA之间的绑定关系,并处理分组的移动性隧道,从而生成第一转换分组。 数据安全单元执行第一个转换数据包的安全测试。 虚拟地址转换器将作为安全测试完成的第一转换分组的源地址的连接节点的HoA转换为可在VPN中使用的专用网络内部地址,从而生成第二转换分组 。

    METHOD OF PROVIDING DIRECT COMMUNICATION IN INTERNET PROTOCOL NETWORK
    2.
    发明申请
    METHOD OF PROVIDING DIRECT COMMUNICATION IN INTERNET PROTOCOL NETWORK 审中-公开
    在互联网协议网络中提供直接通信的方法

    公开(公告)号:US20110082941A1

    公开(公告)日:2011-04-07

    申请号:US12898929

    申请日:2010-10-06

    IPC分类号: G06F15/16

    摘要: In order for a peer node to perform direct communication with a correspondent peer node in an Internet protocol network, the peer node receives a virtual address of the correspondent peer node from a server, and then when the peer node can directly set a tunnel with the correspondent peer node, the peer node sets a tunnel with the correspondent peer node, and when the peer node cannot directly set a tunnel with the correspondent peer node, the peer node sets a tunnel with a tunnel repeater. Thereafter, the peer node connects a virtual address of the correspondent peer node as route information to the tunnel. Thereby, a packet using a virtual address of the correspondent peer node as a destination is transmitted to the correspondent peer node through a predetermined tunnel.

    摘要翻译: 为了使对等节点与互联网协议网络中的通信对等节点进行直接通信,对等节点从服务器接收对端节点的虚拟地址,然后当对等节点可以直接设置与 通信对端节点,对端节点与通信对端节点建立隧道,当对等节点不能直接设置通信对端节点的隧道时,对端节点设置隧道中继器。 此后,对等节点将通信对端节点的虚拟地址作为路由信息连接到隧道。 由此,使用通信对端节点的虚拟地址作为目的地的分组通过预定的隧道被发送到对端节点。

    NETWORK CONTROL METHOD FOR CONTROLLING CLIENT-AND-SERVER BASED HIGH RELIABILITY SESSION FOR SECURE PAYMENT USING MULTI INTERFACE USER TERMINAL IN WIRED OF WIRELESS INTERNET
    7.
    发明申请
    NETWORK CONTROL METHOD FOR CONTROLLING CLIENT-AND-SERVER BASED HIGH RELIABILITY SESSION FOR SECURE PAYMENT USING MULTI INTERFACE USER TERMINAL IN WIRED OF WIRELESS INTERNET 审中-公开
    网络控制方法,用于控制基于客户端和服务器的高可靠性会话,使用多个接口用户终端在无线互联网中进行安全支付

    公开(公告)号:US20120054837A1

    公开(公告)日:2012-03-01

    申请号:US13168277

    申请日:2011-06-24

    IPC分类号: G06F17/30

    CPC分类号: G06Q20/027

    摘要: A network control method for controlling a client-and-server based high-reliability session for secure payment using a multi interface user terminal in the wired or wireless Internet is provided. The network control method establishes an active and standby secure channel between a client equipped to a terminal including a plurality of network interfaces and a server to control each terminal based on a terminal identifier (ID). The method continuously receives terminal state information through the secure channel, and identifies a homogeneous or heterogeneous access network and the secure channel to which a user terminal connects based on the terminal state information, thereby securely authenticating the user terminal requesting payment to a payment gateway (PG) system. Accordingly, the PG system may securely authenticate the user terminal and perform the payment.

    摘要翻译: 提供了一种用于使用有线或无线因特网中的多接口用户终端来控制基于客户机和服务器的高可靠性会话以进行安全支付的网络控制方法。 网络控制方法在配备到包括多个网络接口的终端的客户端和服务器之间建立主动和备用安全通道,以基于终端标识符(ID)来控制每个终端。 该方法通过安全信道连续接收终端状态信息,并且基于终端状态信息来识别用户终端连接的均匀或异构接入网络和安全信道,由此安全地认证向支付网关请求支付的用户终端( PG)系统。 因此,PG系统可以安全地认证用户终端并进行支付。

    Network resource control method and apparatus for guaranteeing admission rate of high-priority service
    8.
    发明授权
    Network resource control method and apparatus for guaranteeing admission rate of high-priority service 失效
    网络资源控制方法和装置,用于保证高优先级服务的准入率

    公开(公告)号:US08189467B2

    公开(公告)日:2012-05-29

    申请号:US12540687

    申请日:2009-08-13

    IPC分类号: H04J3/16

    摘要: Provided are a network resource control method and apparatus for guaranteeing an admission rate of a high-priority service. In the method and apparatus, the admission rate of the high-priority service is increased by differentiating between the high-priority service and a low-priority service by either rejecting the low-priority service or reducing a bandwidth allocated to the low-priority service when the low-priority service has already been accepted.

    摘要翻译: 提供了一种用于保证高优先级服务的准入速率的网络资源控制方法和装置。 在该方法和装置中,通过拒绝低优先级业务或减少分配给低优先级业务的带宽,高优先级业务与低优先级业务之间的差异化来提高高优先级业务的准入速率 当低优先级服务已被接受时。

    APPARATUS AND METHOD FOR INTEGRATED SIGNAL PROCESSING FOR IP-BASED CONVERGENCE NETWORK
    9.
    发明申请
    APPARATUS AND METHOD FOR INTEGRATED SIGNAL PROCESSING FOR IP-BASED CONVERGENCE NETWORK 审中-公开
    用于基于IP的融合网络的集成信号处理的装置和方法

    公开(公告)号:US20110085470A1

    公开(公告)日:2011-04-14

    申请号:US12902108

    申请日:2010-10-11

    IPC分类号: H04L12/28 H04L12/66

    摘要: In an apparatus and method for integrated signal processing for an IP-based wired and wireless convergence network, based on an ID of a second user acquired in response to a service call request from a first user terminal, a unique address corresponding to the ID is acquired. The location address corresponding to the unique address, acquired from the address information of the terminals being stored and managed, i.e., the transport address of the second user terminal, is acquired. An IP connection request is sent to the acquired transport address of the second user terminal and the transport address of the first user terminal, and upon completion of the IP connection, data traffic for the requested service is transferred.

    摘要翻译: 在基于IP的有线和无线汇聚网络的集成信号处理的装置和方法中,基于响应于来自第一用户终端的服务呼叫请求而获取的第二用户的ID,与该ID对应的唯一地址是 获得了 获取与存储和管理的终端的地址信息相对应的唯一地址的位置地址,即第二用户终端的传送地址。 IP连接请求被发送到所获取的第二用户终端的传输地址和第一用户终端的传输地址,并且在完成IP连接时,传送所请求服务的数据业务。

    METHOD AND APPARATUS FOR COLLABORATIVELY PROTECTING AGAINST DISTRIBUTED DENIAL OF SERVICE ATTACK
    10.
    发明申请
    METHOD AND APPARATUS FOR COLLABORATIVELY PROTECTING AGAINST DISTRIBUTED DENIAL OF SERVICE ATTACK 审中-公开
    协调维护对付分配服务攻击的方法和装置

    公开(公告)号:US20110072515A1

    公开(公告)日:2011-03-24

    申请号:US12882557

    申请日:2010-09-15

    IPC分类号: G06F11/00 G06F15/173

    CPC分类号: H04L63/1458

    摘要: A method and apparatus for collaboratively protecting against a Distributed Denial of Service (DDoS) attack are provided. The method performed by a network apparatus includes detecting data suspected as being used in the DDoS attack by monitoring traffic forwarded to a service server, notifying a security apparatus that the detected data is suspected as being used in the DDoS attack, and performing at least one of a first operation and a second operation, the first operation being receiving an analysis result for the detected data from the security apparatus and controlling the traffic based on the analysis result, and the second operation being controlling, prior to the first operation, the traffic based on a rule set in advance.

    摘要翻译: 提供了一种用于协同防御分布式拒绝服务(DDoS)攻击的方法和装置。 由网络装置执行的方法包括通过监视转发到服务服务器的流量来检测疑似被用于DDoS攻击中的数据,通知安全设备所检测到的数据被怀疑在DDoS攻击中被使用,以及执行至少一个 在第一操作和第二操作中,第一操作是从安全装置接收检测到的数据的分析结果,并且基于分析结果来控制流量,第二操作在第一操作之前控制流量 基于事先设定的规则。