METHOD AND APPARATUS FOR RESILIENT END-TO-END MESSAGE PROTECTION FOR LARGE-SCALE CYBER-PHYSICAL SYSTEM COMMUNICATIONS
    1.
    发明申请
    METHOD AND APPARATUS FOR RESILIENT END-TO-END MESSAGE PROTECTION FOR LARGE-SCALE CYBER-PHYSICAL SYSTEM COMMUNICATIONS 有权
    用于大规模CYBER - 物理系统通信的终端消息保护的方法和装置

    公开(公告)号:US20140129838A1

    公开(公告)日:2014-05-08

    申请号:US13837440

    申请日:2013-03-15

    IPC分类号: H04L9/08

    摘要: To address the security requirements for cyber-physical systems, embodiments of the present invention include a resilient end-to-end message protection framework, termed Resilient End-to End Message Protection or REMP, exploiting the notion of the long-term key that is given on per node basis. This long term key is assigned during the node authentication phase and is subsequently used to derive encryption keys from a random number per-message sent. Compared with conventional schemes, REMP improves privacy, message authentication, and key exposure, and without compromising scalability and end-to-end security. The tradeoff is a slight increase in computation time for message decryption and message authentication.

    摘要翻译: 为了解决网络物理系统的安全要求,本发明的实施例包括弹性的端对端消息保护框架,称为弹性端对端消息保护或REMP,利用长期密钥的概念 以每个节点为基础。 这个长期密钥在节点认证阶段被分配,随后用于从发送的每个消息的随机数中导出加密密钥。 与常规方案相比,REMP可以改善隐私,消息身份验证和密钥曝光,并且不会影响可扩展性和端到端的安全性。 权衡是消息解密和消息认证的计算时间略有增加。

    Cross-layer aware communication of a multipath data flow via a communication network

    公开(公告)号:US09742628B2

    公开(公告)日:2017-08-22

    申请号:US14664311

    申请日:2015-03-20

    摘要: A capability for cross-layer aware communication of a multipath data flow via a communication network is presented. The multipath data flow is transported using a set of multiple transmission flows based on a multipath transport protocol. The communication network supports a set of multiple communication paths. A controller is configured to determine a set of mappings between the multiple transmission flows of the multipath data flow and the multiple communication paths based on cross-layer state information, compute a set of path mapping rules for a network element based on the mappings between the multiple transmission flows of the multipath data flow and the multiple communication paths, and provide the path mapping rules to the network element. The network element is configured to apply the path mapping rules for mapping packets of the multipath data flow between the multiple transmission flows of the multipath data flow and the multiple communication paths.

    CROSS-LAYER AWARE COMMUNICATION OF A MULTIPATH DATA FLOW VIA A COMMUNICATION NETWORK
    3.
    发明申请
    CROSS-LAYER AWARE COMMUNICATION OF A MULTIPATH DATA FLOW VIA A COMMUNICATION NETWORK 有权
    通信网络的多路数据流的跨层通信

    公开(公告)号:US20160277247A1

    公开(公告)日:2016-09-22

    申请号:US14664311

    申请日:2015-03-20

    IPC分类号: H04L12/24 H04L12/707

    摘要: A capability for cross-layer aware communication of a multipath data flow via a communication network is presented. The multipath data flow is transported using a set of multiple transmission flows based on a multipath transport protocol. The communication network supports a set of multiple communication paths. A controller is configured to determine a set of mappings between the multiple transmission flows of the multipath data flow and the multiple communication paths based on cross-layer state information, compute a set of path mapping rules for a network element based on the mappings between the multiple transmission flows of the multipath data flow and the multiple communication paths, and provide the path mapping rules to the network element. The network element is configured to apply the path mapping rules for mapping packets of the multipath data flow between the multiple transmission flows of the multipath data flow and the multiple communication paths.

    摘要翻译: 提出了一种通过通信网络进行多路径数据流的跨层感知通信的能力。 基于多径传输协议,使用一组多个传输流来传输多径数据流。 通信网络支持一组多个通信路径。 控制器被配置为基于跨层状态信息来确定多路径数据流的多个传输流和多个通信路径之间的映射集合,基于网络元素的映射来计算网络元件的路径映射规则集合 多路径数据流和多条通信路径的多个传输流,并向网络单元提供路径映射规则。 网元被配置为应用路径映射规则,用于映射多径数据流的多个传输流与多个通信路径之间的多径数据流的分组。

    SYSTEM, METHOD AND APPARATUS PROVIDING ADDRESS INVISIBILITY TO CONTENT PROVIDER/SUBSCRIBER
    4.
    发明申请
    SYSTEM, METHOD AND APPARATUS PROVIDING ADDRESS INVISIBILITY TO CONTENT PROVIDER/SUBSCRIBER 审中-公开
    向内容提供商/订阅者提供地址隐私的系统,方法和设备

    公开(公告)号:US20130173747A1

    公开(公告)日:2013-07-04

    申请号:US13683195

    申请日:2012-11-21

    IPC分类号: H04L29/08

    摘要: A method and apparatus for scalably and securely providing address invisibility to a content provider over a network. In various embodiments, the content provider determines the closest geographic rendezvous point node to store content, such that each of the geographic regions may have associated with it one or more nodes, which provide content to a subscriber without directory service to thereby provide address invisibility to the content provider and also the content consumer.

    摘要翻译: 一种用于通过网络向内容提供商进行可扩展且安全地提供地址不可见性的方法和装置。 在各种实施例中,内容提供商确定最近的地理会合点节点以存储内容,使得每个地理区域可以与其相关联一个或多个节点,其向订户提供内容,而不提供目录服务,从而提供地址不可见性 内容提供商以及内容消费者。

    Cloud-Based Demand Response
    5.
    发明申请
    Cloud-Based Demand Response 审中-公开
    基于云的需求响应

    公开(公告)号:US20120310860A1

    公开(公告)日:2012-12-06

    申请号:US13153741

    申请日:2011-06-06

    IPC分类号: G06Q30/08

    摘要: Methods, systems, and apparatus for implementing cloud-based demand response are provided. Cloud-based demand response may be performed by publishing a demand response request at a communications node, the published demand response request including at least a load reduction request and an incentive price; initiating a load reduction bidding process in response to the published demand response request, the load reduction bidding process being accessible to customer nodes; and determining an updated incentive price based on at least one load reduction bid received from the customer nodes. The updated incentive price may be determined by a bisection function, and the at least one load reduction bid may be autonomously generated based on a customer cost function.

    摘要翻译: 提供了实现基于云的需求响应的方法,系统和设备。 可以通过在通信节点发布请求响应请求来执行基于云的需求响应,所发布的需求响应请求至少包括负载减少请求和激励价格; 根据已发布的需求响应请求启动负载降低出价过程,客户节点可以访问负载降低出价过程; 以及基于从所述客户节点接收到的至少一个减少出价来确定更新的激励价格。 更新的激励价格可以由二等分函数确定,并且可以基于客户成本函数自主地生成至少一个减少出价。

    METHODS AND APPARATUSES FOR ADAPTING BUFFER CAPACITY AT ROUTERS
    6.
    发明申请
    METHODS AND APPARATUSES FOR ADAPTING BUFFER CAPACITY AT ROUTERS 有权
    适应路由器缓存容量的方法和设备

    公开(公告)号:US20130259063A1

    公开(公告)日:2013-10-03

    申请号:US13434080

    申请日:2012-03-29

    IPC分类号: H04L12/56

    CPC分类号: H04L49/9005

    摘要: In a method for dynamic buffer adjustment at a line card of router, a current buffer occupancy at the line card is compared with at least a first buffer occupancy threshold, the first buffer occupancy threshold being calculated based on a buffer occupancy threshold parameter and a capacity of at least a first buffer memory at the line card; and an active buffer capacity is adjusted by at least one of activating and deactivating buffer memory blocks at the line card based on the comparing step, the activating including switching on the buffer memory blocks, and the deactivating including causing the buffer memory blocks to enter a sleep state.

    摘要翻译: 在路由器的线卡处的动态缓冲器调整方法中,将线卡上的当前缓冲器占有率与至少第一缓冲器占用阈值进行比较,基于缓冲器占用阈值参数和容量来计算第一缓冲器占用阈值 至少在线卡上的第一缓冲存储器; 并且基于所述比较步骤,基于所述比较步骤的激活和去激活缓冲存储器块中的至少一个来调整主动缓冲器容量,所述激活包括对所述缓冲存储器块的切换,以及所述停用包括使所述缓冲存储器块进入 睡眠状态

    Methods and apparatuses for adapting buffer capacity at routers
    7.
    发明授权
    Methods and apparatuses for adapting buffer capacity at routers 有权
    适应路由器缓冲容量的方法和装置

    公开(公告)号:US09154452B2

    公开(公告)日:2015-10-06

    申请号:US13434080

    申请日:2012-03-29

    IPC分类号: H04L12/861

    CPC分类号: H04L49/9005

    摘要: In a method for dynamic buffer adjustment at a line card of router, a current buffer occupancy at the line card is compared with at least a first buffer occupancy threshold, the first buffer occupancy threshold being calculated based on a buffer occupancy threshold parameter and a capacity of at least a first buffer memory at the line card; and an active buffer capacity is adjusted by at least one of activating and deactivating buffer memory blocks at the line card based on the comparing step, the activating including switching on the buffer memory blocks, and the deactivating including causing the buffer memory blocks to enter a sleep state.

    摘要翻译: 在路由器的线卡处的动态缓冲器调整方法中,将线卡上的当前缓冲器占有率与至少第一缓冲器占用阈值进行比较,基于缓冲器占用阈值参数和容量来计算第一缓冲器占用阈值 至少在线卡上的第一缓冲存储器; 并且基于所述比较步骤,基于所述比较步骤的激活和去激活缓冲存储器块中的至少一个来调整主动缓冲器容量,所述激活包括对所述缓冲存储器块的切换,以及所述停用包括使所述缓冲存储器块进入 睡眠状态

    End-to-end service quality using source-routed probes
    8.
    发明申请
    End-to-end service quality using source-routed probes 有权
    使用源路由探测器的端到端服务质量

    公开(公告)号:US20070177518A1

    公开(公告)日:2007-08-02

    申请号:US11342372

    申请日:2006-01-27

    申请人: Fei Li Marina Thottan

    发明人: Fei Li Marina Thottan

    IPC分类号: H04J1/16 H04L12/28 H04L12/56

    CPC分类号: H04L43/50

    摘要: The need to monitor real time network services has prompted service providers to use new measurement technologies, such as service-specific probes. A service-specific probe is an active probe that closely mimics the service traffic so that it receives the same treatment from the network as the actual service traffic. Service-specific probes are end-to-end and their deployment depends on solutions that address questions such as minimizing probe traffic, while still obtaining maximum coverage of all the links in the network. A polynomial-time probe-path computation algorithm is provided as well as a 2-approximate solution for merging probe paths when the number of probes exceeds a required bound k. The algorithms are evaluated using ISP topologies generated via Rocketfuel. For most topologies, it is possible to cover more than about 98% of the edges using just about 5% of the nodes as terminals.

    摘要翻译: 监控实时网络服务的需要促使服务提供商使用新的测量技术,如服务特定的探测。 一个特定于服务的探测器是一个活跃的探测器,它密切地模仿服务流量,从而从网络接收与实际服务流量相同的处理。 特定于服务的探测器是端对端的,其部署取决于解决问题的解决方案,例如最小化探测流量,同时仍获得网络中所有链路的最大覆盖。 提供多项式时间探测路径计算算法以及当探头数量超过所需界限k时用于合并探测路径的2近似解。 使用通过Rocketfuel生成的ISP拓扑来评估算法。 对于大多数拓扑结构,可以使用约5%的节点作为终端来覆盖大约98%的边缘。